Crypto hacks in 2026: less frequent, far more damaging
North Korean hackers were already responsible for the vast majority of all stolen crypto this year. What happened, why exchanges remain a target, and how to protect yourself.
10 June 2026 · Reading time: 6 minutes · By the editorial team of CryptoCode.nl
Last week the DeFi platform Radiant Capital announced it was shutting down for good — it never recovered from the €44 million North Korean hack of 2024. It is a fitting symbol of the hacking year 2026: there are fewer incidents than before, but the blows that land are enormous. And remarkably often, the trail leads to the same culprit.
One country, three-quarters of the loot
According to security researchers, North Korean hacking groups were responsible for about 76 percent of all stolen crypto worldwide in the first four months of 2026 — largely through two mega-heists totaling around €508 million. With more than €528 million in damage, April was the most expensive hacking month since early 2025.
The biggest blow of the year fell on 19 April at Kelp DAO, where attackers stole around €258 million via a vulnerable 'bridge' (a link between two blockchains). The damage did not stop at Kelp: the stolen tokens were used as collateral on lending platform Aave, which was left with nearly €176 million in uncollectible debt. The total value on Aave fell by €5.8 billion in the aftermath. One weak link, and the shock ripples through half of the DeFi ecosystem.
The pattern: targeted strikes on large targets
Security platform Immunefi previously calculated that 191 hacks in 2024 and 2025 together caused €4.1 billion in damage — and that just five major attacks accounted for 62 percent of that amount. Centralized exchanges are a favorite target: twenty exchange hacks together accounted for more than half of all damage. The logic is simple: that is where the most crypto sits in one place.
The report contains another sobering figure: tokens of hacked projects lost an average of 61 percent of their value within six months, and in 84 percent of cases the price never recovered to its old level. A hack is therefore rarely a temporary dip — the market treats it as evidence of structural weakness.
The threat is shifting to your phone
Where the mega-heists target platforms, smaller criminals increasingly aim directly at users. Google researchers discovered an exploit kit ('Coruna') this spring that tries to steal the seed phrases of iPhone users via phishing websites. Microsoft warned in early June about new malware that specifically hunts for crypto wallets and passwords. And AI does not make things better: security researchers report that cybercriminals are increasingly using artificial intelligence to automate attacks and make phishing more convincing.
Five lessons for Dutch crypto holders
The good news: against virtually all of the scenarios above, you can defend yourself as a private individual. The basic rules are not new, but 2026 underlines them painfully.
1. Do not leave large amounts on an exchange. Exchanges remain the favorite target. For amounts you do not actively trade, your own (hardware) wallet is the safest place. Not your keys, not your coins is not dogma but risk management.
2. Your seed phrase never leaves your house. No legitimate party — no wallet, no exchange, no 'support agent' — ever asks for your recovery words. Any website or app that asks for them is by definition an attack. Keep the words offline, on paper or metal, never as a photo or in the cloud.
3. Choose platforms that are regulated and prove their reserves. Exchanges that fall under European supervision (MiCA) and publish a Proof of Reserves give you verifiable certainty instead of promises. Check registrations with the AFM or DNB before sending money anywhere.
4. Be extra careful with DeFi and bridges. The biggest losses of 2026 arose at bridges and interconnected DeFi protocols. Attractive returns there sometimes come with correspondingly larger risks — use only money you can fully afford to lose.
5. A hacked project is rarely a bargain. The figures are clear: in more than eight out of ten cases the price never returns. 'Buy the dip' after a hack is, statistically, a bad plan.
In closing
The crypto sector is demonstrably becoming more professional — fewer incidents, stricter oversight, better audits. But as long as billions sit in one place, state hackers and criminals will keep looking for that one weak link. Make sure it is not you.
Sources: Immunefi report via Newsbit (March 2026); 2026 hacking figures via BeInCrypto and Crypto-Insiders; Radiant Capital, Microsoft and AI warnings via Newsbit (June 2026). Reference date: 10 June 2026.
Note: investing in cryptocurrencies carries significant risks. You can lose your stake. This article is not financial advice; always do your own research.
