Fact-check findings
What an automated fact-checker found when it re-read Q2 2026 DeFi Record Hack Wave against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
3 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #23[disputed][awaiting moderator]in section: Other Notable Incidents
“Two exploits on abandoned Aztec Connect smart contracts resulted in losses of approximately $2.1 million and $1.3 million respectively; the protocol had been deprecated but its contracts remained active with residual funds.”
reviewerTwo exploits on abandoned Aztec Connect smart contracts resulted in losses of approximately $2.1 million and $1.3 million respectively.No source describes a second Aztec Connect exploit of $1.3 million; independent reporting puts the second drain at roughly $88,000. The $1.3 million figure appears to be duplicated from the separate Raydium exploit described later in the same paragraph.Proposed correction (not yet applied)Two exploits on abandoned Aztec Connect smart contracts resulted in losses of approximately $2.1 million and $88,000 respectively; the protocol had been deprecated but its contracts remained active with residual funds. - #24[disputed][awaiting moderator]in section: Other Notable Incidents
“The quarter also saw concurrent non-crypto cybersecurity incidents, including tens of thousands of Fortinet firewall compromises and 772 ransomware victims recorded in April alone, suggesting broader infrastructure threat environment.”
reviewerThe quarter saw concurrent non-crypto cybersecurity incidents including tens of thousands of Fortinet firewall compromises and 772 ransomware victims, both recorded in April alone.None of the three cited sources for this section discuss Fortinet or ransomware at all. The 772-ransomware-victims figure for April is independently accurate, but the tens-of-thousands Fortinet firewall compromise (the FortiBleed campaign) took place in mid-June 2026, not April, so grouping both under 'recorded in April alone' is inaccurate.Proposed correction (not yet applied)The quarter also saw concurrent non-crypto cybersecurity incidents, including 772 ransomware victims recorded in April alone and a mid-June FortiBleed campaign that compromised tens of thousands of Fortinet firewalls, suggesting broader infrastructure threat environment. - #25[disputed][awaiting moderator]in the timeline
“April 2026 closes as the single month with the highest crypto hack losses ever recorded; losses for the month estimated at $606–$651 million across approximately 30 incidents.”
reviewerApril 2026 closed as the single month with the highest crypto hack losses ever recorded, at $606-651 million across approximately 30 incidents.The cited source directly contradicts the page's superlative framing: it explicitly names the February 2025 Bybit hack ($1.4B) as worse, and other coverage frames April 2026 as merely the highest since 2022 (implying some 2022 months, e.g. the Ronin hack, were also higher).Proposed correction (not yet applied)April 2026 closes as the highest month for crypto hack losses since 2022; losses for the month estimated at $606–$651 million across approximately 30 incidents.
link rot
4 claimsA cited source no longer resolves or no longer says what the page attributes to it.
- #26[link rot][awaiting moderator]in section: Overview and Scale
“https://blockchain.news/news/q2-2026-most-hacked-quarter”
reviewerThe 47%/37%/5.66% attack-vector breakdown and other Q2 2026 statistics are sourced in part to blockchain.news, which is cited across multiple sections.This URL is cited three times in sections and once in sources_used; grouped under one defect_group. Underlying stat (83 incidents/$755.3M) is independently confirmed elsewhere, so this is a citation health issue rather than a factual dispute.Proposed correction (not yet applied)https://www.kucoin.com/news/flash/q2-2026-sees-record-83-crypto-hacks-total-losses-at-755-3m - #27[link rot][awaiting moderator]in section: Attack Vectors and Patterns
“https://blockchain.news/news/q2-2026-most-hacked-quarter”
reviewerSee prior finding — same blockchain.news URL cited as a source for the Attack Vectors and Patterns section.Duplicate occurrence of the same dead/inaccessible source cited for the attack-vector percentage breakdown.Proposed correction (not yet applied)https://www.kucoin.com/news/flash/q2-2026-sees-record-83-crypto-hacks-total-losses-at-755-3m - #28[link rot][awaiting moderator]in section: Other Notable Incidents
“https://blockchain.news/news/q2-2026-most-hacked-quarter”
reviewerSee prior finding — same blockchain.news URL cited as a source for the Other Notable Incidents section.Duplicate occurrence of the same dead/inaccessible source cited for the Other Notable Incidents section.Proposed correction (not yet applied)https://www.kucoin.com/news/flash/q2-2026-sees-record-83-crypto-hacks-total-losses-at-755-3m - #29[link rot][awaiting moderator]in the cited sources
“https://blockchain.news/news/q2-2026-most-hacked-quarter”
reviewerSee prior finding — same blockchain.news URL appears in the page's sources_used list.The page's own archival pipeline had already flagged this source as unarchivable; this finding confirms it is also currently inaccessible to direct fetch.Proposed correction (not yet applied)https://www.kucoin.com/news/flash/q2-2026-sees-record-83-crypto-hacks-total-losses-at-755-3m
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #10[partially supported][awaiting moderator]in section: Drift Protocol Exploit — $285 Million (April 1, 2026)
“By early 2026, the attackers had allegedly convinced multisig signers to pre-sign hidden governance authorizations. On April 1, they pushed a zero-timelock governance migration that removed the protocol's review window, granting them administrative control.”
reviewerAttackers convinced Drift multisig signers to pre-sign hidden governance authorizations, then pushed a zero-timelock governance migration on April 1 that granted them administrative control.The claim is factually accurate but is not actually supported by any of the three sources the section cites for it (The Hacker News, TRM Labs, and an uncited 'Drift's own post-mortem'); the mechanism is only documented in a Chainalysis post that is not in this section's source list. - #20[partially supported][awaiting moderator]in section: DeFi TVL Impact and Market Effects
“The broader crypto market also contracted: total crypto market capitalization fell from roughly $4.21 trillion to approximately $2.15 trillion between peak and trough in 2026, per Yahoo Finance data.”
reviewerTotal crypto market capitalization fell from roughly $4.21 trillion to approximately $2.15 trillion between peak and trough in 2026, per Yahoo Finance data.The figures are directionally accurate and appear verbatim in a different cited source (Crypto Economy), but the page attributes them to Yahoo Finance, whose cited article does not contain this data. This is a source-attribution error, not a factual one.
confirmed
20 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“Q2 2026 became the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses.”
reviewerQ2 2026 was the most-hacked quarter in crypto history by incident count, with 83 confirmed exploits totaling approximately $755 million in losses.Multiple independent trackers (CoinTelegraph, KuCoin, FinanceFeeds, Cryptopolitan) corroborate 83 incidents and ~$755M in Q2 2026 losses. - #2[confirmed][no action needed]in the summary
“The two largest incidents — a $293 million bridge exploit at KelpDAO and a $285 million social-engineering attack on Drift Protocol — were both attributed to North Korean state-sponsored actors, who collectively captured an estimated 76% of all crypto hack losses recorded through April 2026.”
reviewerThe two largest Q2 2026 incidents, KelpDAO ($293M) and Drift Protocol ($285M), were both attributed to North Korean state-sponsored actors who captured 76% of all crypto hack losses through April 2026.Directly confirmed by TRM Labs research, corroborated by The Block and Decrypt coverage of the same report. - #3[confirmed][no action needed]in the summary
“The wave contributed to a 39% year-to-date decline in DeFi total value locked, which fell from roughly $115 billion to approximately $70 billion by late June 2026.”
reviewerThe hack wave contributed to a 39% YTD decline in DeFi TVL, from ~$115B to ~$70B by late June 2026.Exact figures and percentage confirmed verbatim in the cited CoinTelegraph article. - #4[confirmed][no action needed]in section: Overview and Scale
“Year-to-date through late June 2026, the industry recorded 121 hacks with cumulative losses approaching $942 million, according to CoinTribune.”
reviewerYear-to-date through late June 2026, the industry recorded 121 hacks with cumulative losses approaching $942 million, per CoinTribune.Matches cited source verbatim. Note the same CoinTribune piece separately says Q2 alone accounted for '85 crypto incidents' / ~$775M, a minor tracker-to-tracker variance from the 83/$755M figure used elsewhere on the page — expected given differing methodologies between DefiLlama-based counts. - #5[confirmed][no action needed]in section: Overview and Scale
“Total losses reached approximately $755.3 million, making Q2 2026 the most-hacked quarter by frequency, though it trails Q4 2020's $3.56 billion in aggregate dollar terms.”
reviewerQ2 2026's $755.3M in losses trails Q4 2020's $3.56 billion in aggregate dollar terms.Confirmed via independent search summary of the cited CoinTelegraph article. - #6[confirmed][no action needed]in section: KelpDAO Exploit — $292–$293 Million (April 18, 2026)
“The attacker allegedly poisoned two of the bridge's internal RPC nodes — the servers relaying blockchain data to the LayerZero Decentralized Verifier Network (DVN) — while simultaneously conducting a distributed denial-of-service (DDoS) attack that forced the DVN's verifier to fail over to the compromised nodes.”
reviewerThe KelpDAO attack involved poisoning two internal RPC nodes and a simultaneous DDoS to force DVN failover, exploiting a 1-of-1 DVN verification scheme.Mechanism description matches the cited Chainalysis post-mortem closely, including the 1-of-1 DVN single point of failure. - #7[confirmed][no action needed]in section: KelpDAO Exploit — $292–$293 Million (April 18, 2026)
“The attack had cascading effects on Aave: the attacker deposited approximately 89,567 rsETH as collateral and borrowed roughly $190.86 million in wrapped Ether against it.”
reviewerThe KelpDAO attacker deposited ~89,567 rsETH as Aave collateral and borrowed ~$190.86 million in wrapped Ether, extracting an estimated $190 million before Aave froze rsETH markets.Figure is in the same range as independently reported bad-debt estimates ($190-195M); minor variance is consistent with measurement at different points in time. - #8[confirmed][no action needed]in section: KelpDAO Exploit — $292–$293 Million (April 18, 2026)
“TRM Labs attributed the KelpDAO attack to North Korean state-sponsored actors, noting that pre-hack funding wallets traced back to Wu Huihui, a Chinese crypto broker previously indicted in 2023 for laundering Lazarus Group proceeds.”
reviewerTRM Labs attributed the KelpDAO attack to North Korean state-sponsored actors, tracing pre-hack funding wallets to Wu Huihui, a Chinese broker indicted in 2023 for laundering Lazarus Group proceeds.Confirmed verbatim against the cited TRM Labs report. Note LayerZero's own incident report and Chainalysis instead emphasize direct DPRK/TraderTraitor attribution without mentioning Wu Huihui, but this does not contradict the TRM finding — it is a separate, corroborating attribution thread. - #9[confirmed][no action needed]in section: Drift Protocol Exploit — $285 Million (April 1, 2026)
“The alleged operation began in fall 2025, when attackers created accounts on the Drift platform, deposited more than $1 million of their own funds to establish credibility, and cultivated relationships with multiple core contributors through detailed product questions over several months.”
reviewerThe Drift social engineering campaign began in fall 2025 with attackers creating accounts and depositing more than $1 million of their own funds to build credibility.Confirmed verbatim against the cited Hacker News article. - #11[confirmed][no action needed]in section: Drift Protocol Exploit — $285 Million (April 1, 2026)
“The Hacker News, TRM Labs, and Drift's own post-mortem describe the incident as the culmination of a six-month social engineering campaign attributed with medium confidence to UNC4736, a North Korean state-sponsored hacking group also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces — distinct from but related to the broader Lazarus Group umbrella.”
reviewerThe Drift attack is attributed with medium confidence to UNC4736, aka AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces, distinct from the broader Lazarus umbrella.Attribution naming and confidence level match the cited Hacker News reporting. - #12[confirmed][no action needed]in section: Humanity Protocol Exploit — $36 Million (June 8, 2026)
“According to CoinDesk and a Halborn post-mortem, the attack originated from a phishing email impersonating South Korean exchange Bithumb that compromised an employee's laptop. That laptop stored multiple bridge admin private keys — specifically, three of six Ethereum multisig keys and three of five BNB Chain multisig keys — all on a single device.”
reviewerThe Humanity Protocol attack began with a phishing email impersonating Bithumb that compromised an employee laptop storing 3-of-6 Ethereum and 3-of-5 BNB Chain multisig keys.Exact key-threshold figures and phishing vector confirmed against the cited CoinDesk reporting. - #13[confirmed][no action needed]in section: Humanity Protocol Exploit — $36 Million (June 8, 2026)
“Approximately 141 million H tokens were drained from the Ethereum bridge; approximately 200 million additional H tokens were minted at will on BNB Chain. The attacker swapped most stolen tokens for ETH via DEXs, causing H token's market price to collapse by an estimated 80–90% within 12 hours.”
reviewerApproximately 141 million H tokens were drained from Ethereum and 200 million more minted on BNB Chain, causing an 80-90% price collapse within 12 hours.Token drain/mint figures and price-collapse range confirmed by cited and independent sources. - #14[confirmed][no action needed]in section: THORChain Exploit — $10.7 Million (May 15, 2026)
“According to THORChain's official exploit report and coverage by CoinDesk and The Block, the attacker was a newly admitted node operator who had joined the network two days prior.”
reviewerThe THORChain attacker was a node operator who had joined the network two days before exploiting the GG20 TSS scheme, and the solvency checker flagged a >1% imbalance within minutes.Timeline, mechanism, and 1% solvency-checker threshold all confirmed directly against THORChain's own exploit report. - #15[confirmed][no action needed]in section: THORChain Exploit — $10.7 Million (May 15, 2026)
“Trading resumed approximately five weeks after the incident.”
reviewerTHORChain covered the $10.7 million loss from protocol-owned liquidity and trading resumed approximately five weeks after the incident.Confirmed verbatim against the cited Crypto Briefing article. - #16[confirmed][no action needed]in section: Attack Vectors and Patterns
“Compromised administrator accounts and token price manipulation accounted for approximately 37% of losses, while private key theft accounted for a further 5.66%.”
reviewerCross-chain bridge exploits accounted for ~$351 million (47%) of Q2 2026 losses; compromised admin accounts/price manipulation accounted for ~37%; private key theft for ~5.66%.Percentages match, though see separate link_rot finding regarding direct access to this source URL. - #17[confirmed][no action needed]in section: North Korean State-Actor Attribution
“TRM Labs reported that North Korean state-sponsored actors captured approximately $577 million — or 76% of all tracked crypto hack value through April 2026 — via just two attacks: the Drift Protocol exploit on April 1 and the KelpDAO exploit on April 18.”
reviewerTRM Labs reported North Korean actors captured ~$577 million (76%) of all tracked 2026 crypto hack value through April via the Drift and KelpDAO attacks.Confirmed directly against the primary TRM Labs report. - #18[confirmed][no action needed]in section: North Korean State-Actor Attribution
“North Korea's cumulative attributed crypto theft since 2017 was estimated by TRM Labs at more than $6 billion prior to the Q2 2026 incidents.”
reviewerNorth Korea's cumulative attributed crypto theft since 2017 was estimated by TRM Labs at more than $6 billion prior to the Q2 2026 incidents.Confirmed by both The Block's and Decrypt's coverage of the same TRM Labs report. - #19[confirmed][no action needed]in section: DeFi TVL Impact and Market Effects
“Aave alone saw TVL drop from $26.4 billion to $14.3 billion in the immediate aftermath of the KelpDAO exploit, as depositors withdrew funds in response to oracle and collateral concerns.”
reviewerAave's TVL dropped from $26.4 billion to $14.3 billion following the KelpDAO exploit, and total crypto market cap fell from ~$4.21 trillion to ~$2.15 trillion between peak and trough in 2026, per Yahoo Finance data.Confirmed verbatim, though only by the Crypto Economy source, not the Yahoo Finance or CoinTelegraph sources also cited in this section (see separate finding on market-cap attribution). - #21[confirmed][no action needed]in section: Industry and Regulatory Context
“The SEC and CFTC issued a joint interpretation of federal securities laws as applied to crypto assets in March 2026, and signed a memorandum of understanding on regulatory harmonization in the same month.”
reviewerThe SEC and CFTC issued a joint interpretation of federal securities laws for crypto assets and signed a regulatory-harmonization MOU in March 2026.Both regulatory actions and their March 2026 timing confirmed against the cited source. - #22[confirmed][no action needed]in section: Other Notable Incidents
“Raydium, a Solana-based DEX, reported a $1.3 million exploit in June 2026. Taiko, a ZK-rollup bridge, suffered an estimated $1.7 million loss.”
reviewerRaydium reported a $1.3 million exploit in June 2026 and Taiko suffered an estimated $1.7 million loss.Both figures independently confirmed even though the specific incidents are not detailed in the section's own cited sources; Raydium loss is more precisely reported elsewhere as $1.34M, consistent with the page's rounded $1.3M.