Fri, 28 August 2026
Security8 July 2026

Hijacked accounts are now the biggest DeFi threat

For the first time, hijacked accounts are responsible for more than half of all DeFi attacks — surpassing classic smart contract exploits. A recent governance hack at Bonk DAO shows exactly how it works in practice.

Article image for: Hijacked accounts are now the biggest DeFi threat

The nature of DeFi hacks has fundamentally shifted this year. For the first time, hijacked accounts account for more than half of all DeFi attacks by incident count — overtaking classic smart contract exploits as the leading attack vector. In just the first four months of 2026, DeFi protocols lost more than 750 million dollars (roughly €655.9 million) to exploits; adding May and (partial) June, the running total exceeds 840 million dollars (roughly €734.6 million).

In short 🔓 Hijacked accounts now account for >50% of all DeFi attacks — more than smart contract bugs 💸 DeFi protocols have already lost over 840M dollars (roughly €734.6M) to exploits in 2026 🗳️ On July 6, Bonk DAO was hit by a hijacked governance vote, causing roughly 20M dollars (roughly €17.5M) in damage 🎭 The attacker hid a malicious instruction inside a governance proposal and pre-bought voting power on major exchanges 🕵️ Chainalysis links roughly 76% of all crypto hack losses in 2026 to state-linked actors such as the Lazarus Group 🛡️ For users, wallet security and vigilance around governance votes are becoming increasingly important

From smart contract bugs to hijacked accounts

For years, DeFi security focused mainly on finding bugs in smart contract code. That risk hasn't gone away, but 2026 shows a clear shift: more than half of all DeFi attacks this year now go through hijacked or compromised accounts rather than technical bugs in the underlying code. Chainalysis researchers also attribute roughly 76% of global crypto hack losses in 2026 to actors linked to the Lazarus Group, a group tied to the North Korean state.

The Bonk DAO hack as a real-world example

On July 6, 2026, Bonk DAO was hit by exactly this kind of attack. Through a malicious governance proposal — internally labeled BIP #76 — an attacker managed to drain roughly 4.426 trillion tokens (worth about 20 million dollars, roughly €17.5 million) from the community treasury. The attacker concealed a malicious smart-contract execution command within the text of the proposal itself, and bought approximately 88.23 billion BONK tokens on major exchanges such as Binance and Bybit beforehand to secure enough voting power.

This approach bypasses classic code audits: the underlying smart contract can be technically sound while the attack still succeeds because the governance vote itself is manipulated.

What this means for users

For retail investors and active DeFi users, the key takeaway is that security extends beyond simply trusting an audited smart contract. Practical points to keep in mind:

  • Be cautious about approving token access for unfamiliar or new protocols.
  • Scrutinize governance proposals carefully, especially those containing unusual technical instructions.
  • Keep larger amounts in a hardware wallet rather than a hot wallet connected to DeFi platforms.
  • Stay alert to phishing attempts disguised as governance or voting requests.
Key figureValue
DeFi losses in 2026 (through June)>840M dollars (roughly €734.6M)
Share of attacks via hijacked accounts>50% of all incidents
Bonk DAO damage (July 6)roughly 20M dollars (roughly €17.5M)
Attributed to Lazarus-linked actorsroughly 76% of global hack losses

Conclusion

The shift from technical smart contract bugs to hijacked accounts and manipulated governance votes shows that DeFi security has become a broader issue than code audits alone. Users should keep weighing risks carefully, stay critical of governance requests, and keep sensitive amounts offline where possible.

Sources: Chainalysis, Bonk DAO. Last checked: 8 July 2026.

#defi#security#hack#governance