cryptonist
Fibre optic strands gathered into a bundle, their ends lit

Research

How crypto gets hacked: the incidents, classified

DefiLlama’s hacks record, as committed to this site on 3 October 2026, holds 1,293 incidents and $21.1B in recorded losses. Read as one dataset it shows two things and has one limit: the class of failure that recurs most is not the one that costs most, and 43 incidents of $100M or more hold 69.9% of the value (computed); the limit is that it lists what was recorded, which is not the same as what happened.

The record and its limits

DefiLlama publishes the record on its hacks dashboard. Read on 3 October 2026, the dashboard shows a total value hacked, with separate totals for DeFi and for bridges, a monthly chart, a chart by technique, and a table giving each incident’s name, date, amount lost, chains, classification, technique and language. DefiLlama’s API reference, read the same day, lists the endpoint for paying API users without describing what it returns; the field names appear only in its machine-readable listing, which defines none of them. The site reads the same fields from api.llama.fi/hacks, a keyless address the reference does not list. DefiLlama’s documentation (docs.llama.fi) has no page on the hacks record: hacks come up in its data definitions and FAQ only in passing, in discussions of TVL. Nothing on the dashboard, in the reference or in the documentation read says how an incident is found and added, who assigns its class and technique, which date’s prices an amount uses, or whether an amount is counted before or after any recovery.

Compared on that date, the snapshot’s total, $21,065,227,140, matches the dashboard’s $21.065b, so the snapshot can be taken as the rows behind that dashboard and, with no stated method, as nothing more. It cannot show how many incidents never became a row, and two skews are possible that the snapshot cannot test: if large incidents, or incidents on widely watched chains and protocols, are entered more reliably than others, the tables lean towards them. Where a pattern below could come from recording, the text says so instead of reading a trend into it.

The snapshot holds 1,293 incidents dated from 19 June 2011 to 1 October 2026. Thirty-one of them, worth $931.8M, are dated before 2018, where the site’s yearly pages begin. The rows have gaps of their own:

  • No sources. The source field is empty on all 1,293, so a reader of the snapshot cannot check an incident against the report behind it.
  • Zero amounts. 52 incidents hold zero, which the site’s import writes where DefiLlama’s amount is missing or not positive; they count as incidents and add nothing to value.
  • Unknown techniques. 53 incidents carry the technique Unknown, which is also what the site’s import writes where the field is blank. 52 of them are in the Protocol Logic class, and together they total $21.5M.
  • One label each. Each incident has one class and one technique, so the record cannot show an incident as having more than one cause.

This piece takes each amount as the record gives it, without adjustment and without netting off returned funds. The figures come from the aggregation code behind the hacks data pages, run over the committed snapshot, so they match those pages. Shares and means are computed from the unrounded counts and totals, and medians from the incident amounts; the first such figure in each section is marked as computed.

By class of failure

The record carries one class per incident, and the snapshot uses 13 labels, spelled here as the record spells them. The documentation read does not define them, so each plain-English line below is the ordinary meaning of the label, and the technique labels filed under a class show what the record put there. Classes run by value, largest first, and each label links to its data page.

  • Key Compromise. Someone other than the owner obtained a key that could move the funds. 158 incidents, $8.9B. Private Key Compromised (69 incidents, $1.3B), Hot Wallet Key Compromised (58, $3.1B), Validator Key Compromised (11, $893.3M), and Weak Key Generation, the technique on the record’s largest row, LuBian ($3.5B).
  • Social Engineering. A person was deceived into handing over access or approving an action. 61 incidents, $3.1B. Phishing (29, $1.0B) and Malware (13, $331.1M).
  • Access Control. A function or permission that should have been restricted was open to someone who should not have had it. The largest class by count: 226 incidents, $2.0B. Improper Access Control (141, $1.2B) and Token Approval Abuse (23, $28.9M).
  • Bridge & Cross-Chain. A failure in the contracts or checks that carry assets or messages between chains. 53 incidents, $1.5B. Forged Proof (19, $265.5M) and Bridge Logic Flaw (17, $34.6M).
  • Token & Share Accounting. The arithmetic a contract uses to track who owns what was wrong. 160 incidents, $1.4B. Incorrect Share Accounting (44, $68.4M), Infinite Mint (36, $211.0M) and Arithmetic Error (34, $561.0M).
  • Frontend & Infrastructure. The attack went through the systems around a service (its website, servers, domain, or keys held in that infrastructure) rather than its on-chain code. 95 incidents, $1.0B. Key Leaked via Infrastructure (37, $343.5M) and DNS Hijack (19, $6.9M). That first technique is filed in this class, not under Key Compromise.
  • Oracle Manipulation. A contract relied on a price that was wrong, stale or pushed to a false value by the attacker. 161 incidents, $892.8M. Spot Price Manipulation (133, $833.8M) and Oracle Misconfiguration (18, $26.9M).
  • Input Validation. A contract accepted data it should have rejected. 70 incidents, $755.4M. Missing Input Validation (52, $330.5M) and Signature Verification Flaw (14, $423.6M).
  • Reentrancy. A contract made an external call before it finished updating its own records, and was called back into. 63 incidents, $458.1M, 58 of them labelled Reentrancy ($385.3M).
  • Rugpull. The people behind a project took the funds. 42 incidents, $284.7M. Admin Drain (21, $180.7M) and Liquidity Rug (9, $55.3M).
  • Protocol Logic. A flaw in a contract’s own rules let it be used in a way its authors did not intend. 173 incidents, $252.4M. Of these, 52 have the technique Unknown; the named ones include Swap Logic Flaw (36, $52.3M) and Withdrawal Logic Flaw (30, $58.4M).
  • Governance. A protocol’s voting or proposal process was used to move funds. 20 incidents, $245.2M. Malicious Proposal (16, $63.1M) and Flashloan Governance Attack (4, $182.1M).
  • Market Manipulation. Prices or trading conditions were distorted to take value. 11 incidents, $135.1M. Risk Parameter Abuse (7, $26.1M).

Count versus value

By incidents the top five classes are Access Control (226), Protocol Logic (173), Oracle Manipulation (161), Token & Share Accounting (160) and Key Compromise (158). By value they are the first five in the list above: Key Compromise, Social Engineering, Access Control, Bridge & Cross-Chain and Token & Share Accounting. Three classes are on both lists.

The split is widest at the ends. Key Compromise and Social Engineering together are 219 incidents, 16.9% of the record, and $12.1B, 57.3% of its value (computed against 1,293 incidents and $21.1B). Protocol Logic is 13.4% of incidents and 1.2% of value, and Oracle Manipulation 12.5% and 4.2%. Incident sizes show the same asymmetry.

SizeIncidentsShare of incidentsValueShare of value
Under $1M67552.2%$164.6M0.8%
$1M to under $10M42432.8%$1.6B7.5%
$10M to under $100M15111.7%$4.6B21.8%
$100M and over433.3%$14.7B69.9%

The median incident is $800K and the mean $16.3M. With a mean that far above the median, a few large rows can carry a class’s total, and several do: LuBian is 39.1% of Key Compromise’s value, Bybit 44.9% of Social Engineering’s and Beanstalk 73.8% of Governance’s. LuBian is also 16.6% of the whole record’s value ($3.5B against $21.1B). Without it the record is 1,292 incidents and $17.6B, and the order of the top four classes by value is unchanged, with Key Compromise at $5.4B against Social Engineering’s $3.1B. One row does not produce the ordering; it does account for much of the distance between first and second.

What the asymmetry says is therefore limited. The four most frequent classes concern contracts rather than keys or people, and they, with Input Validation and Reentrancy, have class means (value over count) of $1.5M to $10.8M, against $56.6M for Key Compromise and $51.1M for Social Engineering. With one label per incident, reclassifying a single large row would move these totals: Bybit alone is $1.4B.

By year

YearIncidentsValueLargest incidentShare of year (computed)
201831$1.1BCoincheck, $534.0M47.5%
201926$277.3MUpbit, $49.3M17.8%
202046$4.0BLuBian, $3.5B88.0%
2021127$2.9BPoly Network, $611.0M21.3%
2022184$3.6BRonin Bridge, $624.0M17.2%
2023197$1.6BMixin Network, $200.0M12.3%
2024217$1.7BDMM Bitcoin, $305.0M18.3%
2025148$2.7BBybit, $1.4B51.6%
2026 to 1 Oct286$2.2BBitget, $387.0M17.3%

Years are by UTC date; the last row runs to the snapshot’s latest incident, on 1 October.

Three years lead on value: 2020 ($4.0B), 2022 ($3.6B) and 2021 ($2.9B). The two largest incidents are 88.0% of 2020 (LuBian) and 51.6% of 2025 (Bybit); without LuBian, 2020 is $477.5M and 2022 leads. 2022 holds four of the ten largest incidents (Ronin Bridge, Binance Bridge, FTX and Portal), yet its largest is 17.2% of the year, so no single incident carries it. Each year has its own data page, among them 2020, 2022 and 2025.

The counts do not rise in a line. 2025 is lower than 2023 and 2024, and 2026 is already higher than any full year. Two features of the snapshot show where the rise sits. Incidents of $1M or more were 70 to 99 a year from 2021 to 2025, and 106 in 2026 to 1 October, already more than any earlier year; incidents under $1M rose further: 39 in 2021, 85 in 2022, 110 in 2023, 120 in 2024, 78 in 2025 and 180 in 2026. Their share of each year’s count was 30.7% in 2021, 46.2% in 2022, 55.8% in 2023, 55.3% in 2024, 52.7% in 2025 and 62.9% in 2026, and the yearly median $3.4M, $1.1M, $700K, $521K, $811K and $460K. Both series are uneven: 2024’s share is a little below 2023’s, and 2025 runs the other way on both.

The rise in small incidents is the pattern better recording of them would leave. It is equally the pattern more small attacks would leave, and nothing in the snapshot separates the two. The early years carry the same doubt the other way: 31 incidents in 2018 and 26 in 2019 say what had been entered, and not necessarily what happened.

By chain

The record names 128 chains once spellings are folded together (BSC alone appears under five), the same folding the data pages apply. Ten chains have the 20 or more incidents the data pages require for a chain page; the other 118 share 263 incident entries, counted per chain. Ethereum has 538 incidents and $10.1B, 41.6% of incidents and 47.9% of value (computed), BSC 313 and $3.2B, and Bitcoin 64 and $5.4B. Counting each incident once, 804 of them (62.2%) touch Ethereum or BSC, with $11.7B (55.5%).

Value does not follow count: Bitcoin’s 64 incidents have a mean of $85.0M, against $18.7M for Ethereum and $10.1M for BSC. Two rows, LuBian ($3.5B) and Mt. Gox ($470.0M), are 73.0% of Bitcoin’s value.

Why the counts differ the record cannot say. More code deployed, more value, more scrutiny or weaker code could each produce a table like this, and no field in the record separates them, so this section reports where incidents are recorded and ranks chains by nothing else.

A multi-chain incident counts its full amount on each chain it touched. 136 incidents in the snapshot touch more than one chain, $4.1B between them, so the chain counts sum to 1,533 against 1,293 incidents and the chain values to $30.0B against $21.1B. Poly Network’s $611.0M is listed on Ethereum, BSC and Polygon and counted on each. Another 29 incidents, $624.2M, name no single chain: they are recorded only as Multiple or Multi-Chain, or with no chain.

The ten largest incidents

YearIncidentClassTechniqueAmount
2020LuBianKey CompromiseWeak Key Generation$3.5B
2025BybitSocial EngineeringSigner Phishing$1.4B
2022Ronin BridgeKey CompromiseValidator Key Compromised$624.0M
2021Poly NetworkAccess ControlImproper Access Control$611.0M
2022Binance BridgeBridge & Cross-ChainProof Verifier Bug$570.0M
2018CoincheckKey CompromiseHot Wallet Key Compromised$534.0M
2014Mt. GoxKey CompromisePrivate Key Compromised$470.0M
2022FTXSocial EngineeringPhishing$450.0M
2026BitgetKey CompromiseHot Wallet Key Compromised$387.0M
2022PortalInput ValidationSignature Verification Flaw$326.0M

Together they come to $8.9B, 42.1% of the record’s value from 10 of its 1,293 incidents (computed). Seven of the ten are filed under Key Compromise (five) or Social Engineering (two), and one each under Access Control, Bridge & Cross-Chain and Input Validation. Five carry the target type CEX, four DeFi Protocol and one Other. The four DeFi Protocol rows (Ronin Bridge, Poly Network, Binance Bridge and Portal) are also the four flagged as bridge hacks. Four of the ten fall in 2022, and none in 2023 or 2024.

Ten rows cannot carry a pattern, and the labels are the record’s: this piece reproduces them and has not checked them against other accounts of the incidents.

Returned funds and bridges

25 incidents (1.9% of 1,293, computed) carry a returned-funds figure above zero; the other 1,268 carry none. All 25 are dated 2022 to 2026, a period of 1,032 incidents in which they are 2.4%, and in 16 of them the returned figure is at least the recorded loss. The API reference does not define the field, so this piece reports the count only. It does not total or rank returned amounts, which the data pages also leave out, and it does not read a blank as a recovery that never happened, since the record does not say whether a blank means none or none recorded. What a public ledger shows about where taken funds went, and where tracing stops, is set out in can governments track crypto.

The record has two definitions of a bridge. The class Bridge & Cross-Chain holds 53 incidents (4.1% of the record) and $1.5B (7.3%). Separately, a flag marks 96 incidents (7.4%) and $3.7B (17.5%) as bridge hacks; the API reference does not define the flag either. 43 incidents are in both. The other 53 flagged incidents sit in seven other classes, 16 of them Key Compromise and 13 Access Control, so the bridge share depends on whether the label or the flag is counted. Ronin Bridge is one: filed as Key Compromise, flagged as a bridge hack.

What follows for a user

The record lists incidents at named projects, venues and chains: 942 at a DeFi Protocol, 117 at a CEX, 99 at a Token, 31 at a Chain and 18 at a Wallet, among other target types. It is not a count of individual holders’ losses. It does allow each class to be set against the part of the failure a person can change.

Keys and people. Five of the seven top-ten incidents filed under Key Compromise or Social Engineering carry the target type CEX. On an exchange, as exchange or self-custody puts it, a customer holds a claim on a company, not coins, so the keys at risk are the venue’s. What a holder controls is how much sits on a venue at all. In self-custody the keys are the holder’s, and a seed phrase, in the piece on what each secret controls, is not a password for the keys but the keys themselves. How crypto wallets actually fail lists the routes by which funds leave a self-custodial wallet; weak key generation, LuBian’s technique, is one of them.

What gets signed. 23 incidents ($28.9M) carry Token Approval Abuse, filed under Access Control, and 29 ($1.0B) carry Phishing. The Frontend & Infrastructure class holds DNS Hijack (19) and Frontend Compromise (9). The record does not say who was deceived or what was signed in these incidents, but the labels name routes a holder also meets: a token approval, a request to sign, a site that is not the one it appears to be. What a wallet connection approves sets out the difference between connecting and approving, why an allowance outlasts the visit, and the habit of reading the spender in the request and not the site’s address.

Flaws in code. Nothing a holder does changes whether a contract has an access-control, logic, oracle, accounting, input or reentrancy flaw. What a holder can change is how much a later flaw can reach, which is the same article’s point about approvals left standing.

None of this is a ranking. A venue, chain or class with few rows has not been shown to be safe, and one with many has not been shown to be unsafe; counts can follow what was deployed, watched and reported as much as what fails. The hacks data pages carry the record by year, class, chain and technique, as of 3 October 2026.