The State of Digital Asset Security: The Top 100 Hacks Report - Download Now

Solutions

Company

Resources

Blog

Contact

Login
    • Advisory

      AI Advisory

      Strategic guidance for secure AI adoption

      Blockchain Architecture Assessment

      Reviewing blockchain designs for security and resilience

      Compliance Readiness

      Aligning controls to evolving regulatory mandates

      Custody and Key Management Assessment

      Securing digital asset custody and key systems

      Risk Assessment

      Clarity on your cybersecurity risk posture

      Technical Due Diligence

      Validating security before third-party commitments

      Technical Training

      Building blockchain and security skills enterprise-wide

    • Assurance

      AI Red Teaming

      Adversarial testing against real-world AI threats

      AI Security Assessment

      Identifying vulnerabilities in AI models and pipelines

      Blockchain Layer 1 Assessment

      Protocol-level security review of L1 networks

      Code Security Audit

      Uncovering vulnerabilities in your source code

      Web Application Penetration Testing

      Exposing exploitable flaws in web applications

      Cloud Infrastructure Penetration Testing

      Finding weaknesses across cloud environments

      Red Team Exercise

      Full-scope adversarial simulation of your defenses

      Smart Contract Assessment

      Code security testing for blockchain-powered applications and systems.

    • Who We Are

      The best security engineers in the world

      Careers

      Work with the elite

      Who Trusts Us

      The trusted security advisor for blockchain and financial services industries

      Brand

      Access official logos, fonts, and guidelines

      Service Commitments

      Committed to Protecting Your Data

      Press Releases

      Company news and announcements from Halborn

    • Audits

      In-depth evaluations of smart contracts and blockchain infrastructures

      BVSS

      Blockchain Vulnerability Scoring System

      Disclosures

      All the latest vulnerabilities discovered by Halborn

      Case Studies

      How Halborn’s solutions have empowered clients to overcome security issues

      Reports

      Comprehensive reports and data

  • Blog

  • Contact

Login

STAY CURRENT WITH HALBORN

Subscribe to the monthly Halborn Digest for our top blogs and videos, major company announcements, new whitepapers, webinar and event invites, and one exclusive interview.

ADVISORY SERVICES

AI AdvisoryRisk AssessmentBlockchain Architecture AssessmentCompliance ReadinessCustody and Key Management AssessmentTechnical Due DiligenceTechnical Training

ASSURANCE SERVICES

AI Security AssessmentAI Red TeamingSmart Contract AssessmentBlockchain Layer 1 AssessmentCode Security AuditWeb Application Penetration TestingCloud Infrastructure Penetration TestingRed Team Exercise

COMPANY

Who We AreWho Trusts UsService CommitmentsCareersBrandBlogPress ReleasesContact

RESOURCES

AuditsDisclosuresReportsBVSSCase Studies
Halborn Logo
Privacy PolicyTerms of UseVulnerability Disclosure Policy

© Halborn 2026. All rights reserved.

AI Advisory

Strategic guidance for secure AI adoption

Blockchain Architecture Assessment

Reviewing blockchain designs for security and resilience

Compliance Readiness

Aligning controls to evolving regulatory mandates

Custody and Key Management Assessment

Securing digital asset custody and key systems

Risk Assessment

Clarity on your cybersecurity risk posture

Technical Due Diligence

Validating security before third-party commitments

Technical Training

Building blockchain and security skills enterprise-wide

AI Red Teaming

Adversarial testing against real-world AI threats

AI Security Assessment

Identifying vulnerabilities in AI models and pipelines

Blockchain Layer 1 Assessment

Protocol-level security review of L1 networks

Code Security Audit

Uncovering vulnerabilities in your source code

Web Application Penetration Testing

Exposing exploitable flaws in web applications

Cloud Infrastructure Penetration Testing

Finding weaknesses across cloud environments

Red Team Exercise

Full-scope adversarial simulation of your defenses

Smart Contract Assessment

Code security testing for blockchain-powered applications and systems.

Who We Are

The best security engineers in the world

Careers

Work with the elite

Who Trusts Us

The trusted security advisor for blockchain and financial services industries

Brand

Access official logos, fonts, and guidelines

Service Commitments

Committed to Protecting Your Data

Press Releases

Company news and announcements from Halborn

Audits

In-depth evaluations of smart contracts and blockchain infrastructures

BVSS

Blockchain Vulnerability Scoring System

Disclosures

All the latest vulnerabilities discovered by Halborn

Case Studies

How Halborn’s solutions have empowered clients to overcome security issues

Reports

Comprehensive reports and data

THIS WEBSITE USES COOKIES

We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. You consent to our cookies if you continue to use our website. Learn More.

// Halborn Research

The State of Digital Asset SecurityThe Top 100 Hacks

Analysis of the largest security incidents from 2014 to H1 2026. The controls the industry trusted most have been engineered around, not defeated.

Download the Full Report

$12B+

Total losses, 100 incidents

96%

H1 2026 losses, off-chain

56%

Losses tied to Custody & Signing

23%

Losses from smart-contract bugs

Report Overview

Between January 2014 and June 2026, the 100 largest publicly disclosed digital asset security incidents cost their victims a combined $12 billion. This report breaks down what must change for organizations operating in or adjacent to digital assets.

The attack surface has moved. The industry made measurable progress against smart-contract vulnerabilities. It made almost no progress against compromised keys, signing workflows, social engineering, and vendor infrastructure, where 96% of H1 2026 losses now occur. Multisig and code audits have been engineered around, not defeated.

The State of Digital Asset Security: The Top 100 Hacks report cover

The controls the industry trusted most have been engineered around

Bridges got fixed. The eleven-year-old CEX problem did not.

Bridge exploits cost $2.82B in 2021 through 2023 and have not appeared in the top 100 since. CEX and custodial losses hit an all-time high of $1.77B in 2025, and when that category finally went quiet in H1 2026, the same failure modes resurfaced in restaking, DEX governance, and stablecoin custody instead.

Bridge losses, 2021 to H1 2026.

CEX
DEX
Restaking / LST
Yield aggregator
Other

All off-chain losses excluding bridges by protocol type, 2014 to H1 2026.

Multisig-protected treasuries lost 3x more per breach than hot wallets.

Multisig incidents average $276M in losses versus $98M for hot wallets. All 12 multisig breaches in the dataset were defeated through the human or workflow layer, not the cryptography. Raising the signer count doesn't address where attackers actually operate.

Mean loss
Median loss

Mean and median loss per incident by signature and wallet factor.

Off-chain causes drove 96% of H1 2026 losses.

Compromised keys and signing infrastructure accounted for 96% of H1 2026 losses, up from 36% in 2021. Smart-contract bugs fell in step. Concentrated engineering effort can retire a known vulnerability class.

On-chain
Off-chain
Unknown

Share of losses per year by cause, 2021 to H1 2026.

A single state actor now dominates the tail.

DPRK and Lazarus-linked incidents rose from 0% of annual losses in 2021 to 81.9% by H1 2026. This is APT tradecraft, patient and well-resourced, not smash-and-grab crime: fake-recruiter social engineering, deepfake approval calls, and compromised signing vendors.

Other / unattributed
DPRK-linked (confirmed/attributed)
DPRK-linked (suspected)

DPRK-linked versus all other losses by year, 2018 to H1 2026.

Attacks are increasingly hybrid and multi-stage.

A category that did not exist before 2024, chaining a social or infrastructure step with a technical exploit, is now a recurring pattern. It defeats defenses built for one attack surface at a time: an audit alone catches the exploit but misses the compromise that enabled it, and vice versa. Only layered controls across both surfaces close the gap.

Smart contract
Infrastructure / signing
Hybrid

Losses by cause category: smart contract, infrastructure/signing, and hybrid, 2021 to H1 2026.

Get the full report, prevention matrix, and actionable recommendations.

Download the Report

Key Findings From Twelve Years Of Incident Data

100%

Audited in 2025

Every one of 2025's incidents with known audit status hit audited protocols.

$3.49B in losses, 29% of the total, hit entities that had been audited. Some had eleven audits from top-tier firms. Point-in-time code review does not cover infrastructure, dependencies, or changes made post-audit.

82%

DPRK-linked, H1 2026

DPRK-linked actors now account for the majority of annual losses.

Incidents attributed to DPRK and Lazarus grew from 0% of annual losses in 2021 to 82% in H1 2026. Their proceeds recover at 9%, compared to 32% for every other actor category.

11%

Recovery rate, H1 2026

Recovery rates have collapsed to 11%.

The blended recovery rate fell from 40% in 2021 to 11% in H1 2026. Private key compromise recovers at 7.3%. Signing infrastructure compromise recovers at 6.2%. Smart-contract bugs recover at 52.2%.

73%

Off-chain, top 10 incidents

The biggest incidents skew even more off-chain.

The top 10 incidents are 73% off-chain by value and 47% DPRK-linked. The bottom 70 are 58% off-chain and 9% DPRK-linked. The catastrophic tail is disproportionately a human-and-key problem attributable to a single sophisticated threat actor.

Download the report to uncover all findings

Download the Report

// Takeaway

The industry engineered around the threats it prepared for, and lost $12 billion to the ones that replaced them.

More than a decade of incident data shows the same pattern: the digital asset industry made measurable progress against the threats it explicitly engineered against, and almost no progress against the threats that replaced them. Multisig and code audits remain necessary. Removing them would be a regression. But this dataset shows plainly that neither is sufficient on its own, and the gap between necessary and sufficient is exactly where the losses went.

The organizations that operate safely in this space over the next few years will treat signing-workflow integrity and vendor discipline with the same rigor already applied to core banking infrastructure. Starting now, not after an incident makes the decision for them.

Download The Full Report

The full analysis, with data-backed insights, case studies, and immediate actionables for security leadership.

Coverage

January 2014 to June 2026

Dataset

Top 100 incidents by gross loss at time of theft

Who Is It For

CISOs, CTOs, Compliance and Risk Leads, Head of Digital Assets, Investors and VCs

Get The Report