BREAKING
Sep 3A Blockchain Just Hit Undo on Two Hours of Everyone's TransactionsSep 3You Did Everything Right and Lost It Anyway: The $116M Coldcard HackSep 3Ledger Is Getting Sued for $500M — and Not a Single Private Key Was HackedJul 8Trump Says Iran Ceasefire Is 'Over' — $450M in Crypto Liquidated in HoursJul 8The SEC Just Surrendered: Startups Can Now Raise $75M in Crypto Without Getting SuedJul 7The U.S. Has $20 Billion in Bitcoin and Nobody's in Charge of ItJul 7Strategy Sold 3,588 Bitcoin at a $15,000-Per-Coin Loss — to Pay Its Own DividendsJul 6A Hacker Borrowed $65 Million, Gave It All Back, and Kept $6 MillionJul 6Someone Spent $4M to Vote $20M Out of BonkDAO's Treasury — And It Was All 'Legal'Jul 5Trump Pocketed $636M. The 988,905 People Who Bought His Meme Coin Lost $3.8 Billion.Sep 3A Blockchain Just Hit Undo on Two Hours of Everyone's TransactionsSep 3You Did Everything Right and Lost It Anyway: The $116M Coldcard HackSep 3Ledger Is Getting Sued for $500M — and Not a Single Private Key Was HackedJul 8Trump Says Iran Ceasefire Is 'Over' — $450M in Crypto Liquidated in HoursJul 8The SEC Just Surrendered: Startups Can Now Raise $75M in Crypto Without Getting SuedJul 7The U.S. Has $20 Billion in Bitcoin and Nobody's in Charge of ItJul 7Strategy Sold 3,588 Bitcoin at a $15,000-Per-Coin Loss — to Pay Its Own DividendsJul 6A Hacker Borrowed $65 Million, Gave It All Back, and Kept $6 MillionJul 6Someone Spent $4M to Vote $20M Out of BonkDAO's Treasury — And It Was All 'Legal'Jul 5Trump Pocketed $636M. The 988,905 People Who Bought His Meme Coin Lost $3.8 Billion.
BTC -- --%
ETH -- --%
Fear & Greed F&G 65 Greed
ESC
Type to search articles
$1.32 Billion Stolen in Six Months and the Contracts Weren't the Problem

$1.32 Billion Stolen in Six Months and the Contracts Weren't the Problem

The Grind Catch-Up: what you missed while we were offline. Part 3 of 8.

Crypto project hacks totalled $1.32 billion in the first half of 2026 across more than 200 exploits, per the Bitcoin Foundation’s H1 summary. By the time the Coldcard drain landed, the year’s running total had pushed past $1.2 billion across 276 incidents. 2026 is tracking to be the costliest year for crypto theft on record.

But the aggregate isn’t the interesting part. The distribution is.

July was a spike, not a trend line

July alone saw $247.4 million stolen — more than triple June’s $75 million and more than four times May’s $60 million, according to Cointelegraph. That made it the second-worst month of the year.

Nearly half of it was one incident: the Coldcard firmware exploit (~$116M). Strip that out and July looks closer to an ordinary bad month. The rest was spread across smaller hits — roughly $9M from Bonzo Lend, $24M from Arbitrum perps exchange AFX, $2.6M from Cardano wallet SecondFi, and about $7.5M elsewhere.

Worth noting: monthly tallies vary meaningfully between trackers depending on what counts as an incident and when funds are marked stolen. crypto.news put July nearer $110M. Treat any single number as an estimate; the direction is what’s solid.

August cooled to around $136 million, though it still set a record for number of incidents.

The pattern nobody wants to say out loud

Run through 2026’s largest losses and count how many were caused by a bug in an audited smart contract.

  • Coldcard, ~$116M — firmware RNG flaw
  • Tectonic, ~$75M — oracle manipulation on a thin token
  • The Sandbox — hijacked LayerZero delegate permissions
  • Harmony ONE — 4 billion unauthorized tokens minted
  • Coinsbuy, ~$8M — exchange compromise
  • Ledger’s $500M class action — a leaked customer list, not a broken key

Almost none of these are “the Solidity had a reentrancy bug.” They are firmware, oracle design, cross-chain permission configuration, minting authority, exchange operations, and a marketing database.

The industry built an audit economy aimed squarely at contract code. Attackers moved to everything surrounding it — because that’s where the review isn’t.

Why This Matters for Crypto Jobs

If you are trying to build a security career in crypto right now, the highest-leverage move is to specialize away from the crowd.

Smart contract auditing remains valuable and well paid, but it is the most saturated security niche in the industry. Meanwhile these are thinly staffed:

  • Cross-chain / bridge permission auditing — who holds delegate rights on your LayerZero config, and who can change them?
  • Key management and signer operations — multisig hygiene, hardware custody, ceremony design
  • Oracle and market risk — the Tectonic class of failure, which is a modelling problem more than a code problem
  • Operational and corporate security — the boring stuff that produced the Ledger and Coinsbuy incidents
  • Detection and incident response — most protocols still find out from Twitter

Demand for security and auditing skills has been climbing all year, with roles like smart-contract auditor, penetration tester and compliance officer reportedly commanding FAANG-level pay. The pay is there. The competition is concentrated in one lane, and the attackers left that lane months ago.

Pick the boring specialism. That’s where the openings are.


Browse open security, audit, and infrastructure roles at cryptogrind.com.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs