News linked to both this project and an event.
: A security report for the first half of 2026 released by on-chain security platform Blockaid shows that the crypto industry suffered losses exceeding $1 billion during the period, with a record number of hacker incidents in six months. Blockaid tracked 212 security incidents, including a single attack on KelpDAO that resulted in a loss of $292 million. Ethereum and Solana were the networks with the largest amounts of stolen funds during the period, with losses of approximately $332 million and $326 million, respectively. Blockaid stated that the number of high-threshold attacks in the first half of 2026 was 3.4 times that of the entire year of 2025. Ethereum incidents were primarily driven by code vulnerabilities, with attack vectors including bridge and smart contract exploits, unauthorized access to privileged accounts, and market manipulation. Solana's losses increased significantly from approximately $127 million in 2025, with over 98% of losses stemming from key leaks, primarily involving incidents related to Drift Protocol and Step Finance.
According to Bitcoin.com, U.S. Senator Cynthia Lummis is pushing hard for the CLARITY Act to complete Senate voting before Congress adjourns. Section 303 of the bill grants the Treasury Department the authority to impose targeted digital asset sanctions on foreign jurisdictions, while Section 305 allows exchanges to freeze suspicious transactions for up to 180 days. On-chain data shows that North Korea's Lazarus Group stole approximately $643 million in the first half of 2026, accounting for two-thirds of the total global crypto theft during the same period ($972 million), including a $285 million attack on Drift Protocol in April and a $292 million attack on the KelpDAO cross-chain bridge. The group's cumulative theft amount has reached $6.75 billion since 2019. Currently, Galaxy Research has lowered the probability of the CLARITY Act passing within 2026 to 30%. The bill still requires 60 votes to advance, meaning at least 7 Democratic senators need to vote across party lines in support.
that, according to Onchain Lens monitoring, after a $285 million attack on Drift Protocol on Solana in April, the attacker has begun moving funds through Tornado Cash following a 3-month dormant period. The attacker is rapidly depositing ETH into the Tornado Cash Router in batches of 100 ETH, with multiple transactions occurring per minute.
Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.
Odaily, Web3 security firm CertiK has released the "Hack3D: First Half of 2026 Report." The report shows that the Web3 ecosystem experienced 344 security incidents in the first half of 2026, with cumulative losses of approximately $1.32 billion. Although this figure represents a 46.8% decrease compared to the same period last year, excluding the impact of the $1.45 billion security incident involving Bybit, the scale of losses in the first half of this year actually increased by approximately 28% year-on-year, indicating that the overall security environment in the industry has not materially improved.The report points out that wallet theft has become the attack type causing the greatest financial loss, accounting for approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks fell by more than 50% year-on-year, the loss amount only decreased by approximately 10.8%, reflecting that attackers are shifting towards high-net-worth individuals and institutional targets, carrying out more targeted high-value attacks.Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running legacy smart contracts that lack re-audits. The report also shows that mega-attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents alone causing approximately $577 million in losses, accounting for 44% of the total losses in the first half of the year. Looking at the number of incidents, the impact of single attacks, and the changing attack patterns, the Web3 industry is facing more complex and continuously escalating security challenges.
according to DefiLlama data, Q2 2026 has become the most active quarter on record for crypto hacks, with 83 separate attack incidents, setting a new all-time high.Despite the increased frequency of attacks, the total losses for the quarter were approximately $755.3 million, still lower than the $3.56 billion lost in Q4 2020. Of this, the $293 million attack on KelpDAO and the $280 million attack on Drift Protocol accounted for more than three-quarters of the quarter's total losses. Cross-chain bridges were the largest source of losses, with related attacks leading to approximately $351 million being stolen. Earlier this month, Humanity Protocol lost $36 million, Aztec Connect experienced two attacks on passive smart contracts, each losing about $2.1 million, and decentralized exchange Raydium suffered a $1.3 million attack in June. (financefeeds)
leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)
According to Drift’s official announcement, the Drift Protocol released its latest recovery update on June 3, 2026. An independent forensic investigation conducted by cybersecurity firm Mandiant has confirmed that the prior attack against Drift was carried out by the North Korean threat group UNC6862, whose tactics closely align with those historically employed by North Korean state-sponsored hacking operations. On the rebuilding front, Drift announced the appointment of Noah Prince—former Engineering Lead of the Helium Protocol—as Protocol Lead, who will spearhead codebase hardening and platform security architecture redesign. Additionally, former members of the Gauntlet team have been brought on board to conduct margin engine reviews, optimize funding rates and market parameters, enhance liquidation mechanisms, and implement continuous risk monitoring. Drift plans to relaunch with “security-first” as its core principle, repositioning itself as Solana’s largest USDT-perpetuals exchange. With support from strategic partners including Tether, Drift will establish a dedicated recovery pool funded by platform revenues to compensate users for losses. Further details regarding the recovery mechanism and timeline will be disclosed progressively.
data from blockchain security firm CertiK shows total losses in the crypto sector from hacks, vulnerabilities, and scams in May 2026 were approximately $68.3 million. This represents a nearly 90% decline from the over $650 million in losses recorded in April, making it the third month this year where losses fell below $100 million. Phishing attacks accounted for about $2.6 million of the losses.In April, industry losses surged due to two major attacks on Drift Protocol and KelpDAO, which together accounted for approximately 95% of the month's losses, making April one of the most devastating months for losses in recent years.The institution reminds that while large-scale protocol-level attacks have decreased, risks such as phishing, deepfakes, and credential leaks are on the rise, with the focus of attacks increasingly shifting towards personnel and identity systems. The decline in losses this time is merely due to the absence of major security incidents; the overall security risks in the industry have not been fundamentally eliminated. Cross-chain bridge vulnerabilities and insider threats remain primary risks. (Financefeeds)
Drift Protocol stated on X platform that after the protocol resumes operation, users who have staked in the Insurance Fund will be able to withdraw their corresponding shares normally. The Insurance Fund is designed to maintain the protocol's solvency during liquidation or bankruptcy scenarios. Since the protocol was paused before losses were realized through normal liquidation or bankruptcy processes, the Insurance Fund was not affected by the relevant vulnerability or attack.Drift Protocol added that the protocol's own Insurance Fund assets will be used to support system restart and user recovery, and it plans to disclose the relevant on-chain addresses to allow the community to track fund usage and subsequent deployment.
in April 2026, two major DeFi attacks on Drift Protocol and Kelp DAO resulted in losses of nearly $600 million, triggering approximately $9 billion in capital outflows from protocols like Aave. TRM Labs investigator Nick Carlsen stated that a hacker group suspected to be linked to North Korea has allegedly used AI to assist in target selection and attack path design. Failsafe CEO Aneirin Flynn said that AI has compressed the time for discovering blockchain vulnerabilities from months to days or even hours. The report noted that Anthropic has not fully opened its AI model Mythos due to cybersecurity risks, claiming the model has the capability to discover large-scale zero-day vulnerabilities. Its research indicates that over half of blockchain attacks in 2025 could theoretically be completed autonomously by AI. (Bloomberg)
According to the official disclosure by Drift Protocol, all affected wallets impacted by the April 1 attack will receive Recovery Tokens—representing their verified losses and proportional claims against the Recovery Pool—where each Recovery Token corresponds to $1 of verified loss. The Recovery Pool’s initial funding is approximately $3.8 million, sourced from converting the protocol’s remaining assets into USDT. It will be further replenished through a portion of quarterly net exchange revenue, partner contributions, and up to $127.5 million in matching deployment from Tether. Once the Recovery Pool exceeds $5 million, users may begin redeeming Recovery Tokens; the redemption price will be calculated as the Recovery Fund’s value divided by the outstanding supply of Recovery Tokens. Drift stated that the Insurance Fund was unaffected by the attack; any release of related funds requires governance proposals and DAO voting. The exchange plans to relaunch in Q2 2026, focusing primarily on perpetual contracts and a select set of markets. Additionally, it will replace its programs and addresses, rotate keys, reconstruct its community multisig, remove durable nonces and the Earn product, and implement operational security upgrades.
According to Odaily, Drift Protocol has released a user recovery plan for the approximately $295 million security vulnerability incident on April 1, which was attributed to a North Korean-backed hacker group. Under the plan, Drift will issue receipt tokens representing users' verified losses, with each token corresponding to $1 in losses, allowing holders to gradually redeem based on the recovery pool's funding size.Currently, the recovery pool has initial funding of approximately $3.8 million. Subsequent funding sources include up to $127.5 million from exchange revenue, Tether-backed funds, and up to $20 million from partner contributions, aiming to cover total losses of approximately $295.4 million. Drift has frozen approximately $3.36 million in USDC and has established a public bounty program offering 10% of recovered assets. It is expected to relaunch the exchange in a "security-first" model during the second quarter. (CoinDesk)
North Korea has denied allegations of its involvement in cryptocurrency theft, calling the claims "absurd slander" and a "political tool." The statement, issued by state-run media, emphasized that necessary measures will be taken to safeguard national interests. However, data from blockchain analytics firm TRM Labs shows that in the first four months of 2026, hacker groups linked to North Korea have stolen approximately $577 million, accounting for about 76% of global crypto theft losses during the same period. This includes two major attacks on KelpDAO (approximately $292 million) and Drift Protocol (approximately $285 million).TRM pointed out that the attacks are primarily associated with the Lazarus Group and its sub-organizations. Since 2017, the cumulative scale of crypto theft linked to North Korea has exceeded $6 billion.U.S. and international agencies widely believe that such funds are used to support military and missile programs. Meanwhile, the U.S. Treasury Department has recently imposed sanctions on relevant individuals and entities, targeting approximately $800 million in illicit fund flows in 2024. (The Block)
North Korean spies spent months conducting multiple in-person meetings with Drift Protocol employees before executing one of the largest social engineering attacks against a crypto protocol, stealing $285 million. According to TRM Labs data, losses attributed to North Korean hackers accounted for 76% of total crypto hack losses in 2026. (CoinDesk)
According to The Block, blockchain intelligence firm TRM Labs released a report stating that North Korean hacker groups stole approximately $577 million in crypto assets during the first four months of 2026—accounting for 76% of global hacking losses over the same period. All these losses stemmed from two major incidents that occurred in April: KelpDAO was attacked by the TraderTraitor group, resulting in $292 million in losses; and Drift Protocol was compromised by another North Korean sub-group, suffering $285 million in losses. Preparations for the latter attack began as early as March 11, and funds were fully extracted within 12 minutes. The two incidents employed distinct money-laundering pathways: stolen funds from Drift remain largely dormant on Ethereum, whereas funds stolen from KelpDAO were rapidly swapped into BTC via THORChain, with subsequent laundering facilitated by Chinese intermediaries. TRM Labs noted that since 2017, North Korea’s cumulative crypto theft has exceeded $6 billion—and its share of global losses has risen steadily, from less than 10% in 2020 to 64% in 2025.
According to Natalie Newson, Senior Blockchain Investigator at CertiK, real-time deepfakes, phishing attacks, supply-chain compromises, and cross-chain vulnerabilities will be the primary drivers of cryptocurrency hacks in 2026. So far this year, the industry has lost over $600 million to hacking incidents—including the $293 million Kelp DAO exploit and the $280 million theft from Drift Protocol in April—both linked to a North Korean hacker group. Newson warns that the accelerated advancement of AI will make attack methods increasingly sophisticated, including more realistic deepfakes, autonomous attack agents, and “agent AIs” capable of automatically scanning smart contracts for vulnerabilities. However, AI can also serve as a defensive tool. CertiK advises investors to verify URL authenticity and store assets in cold wallets to mitigate risk.
According to Cointelegraph, stablecoin issuer Circle faces a class-action lawsuit in the U.S. District Court for the District of Massachusetts for failing to freeze stolen funds during the Drift Protocol hack on April 1. Plaintiffs allege that attackers transferred approximately $230 million worth of USDC from Solana to Ethereum via Circle’s cross-chain transfer protocol (CCTP) within hours—and that Circle failed to intervene. The lawsuit accuses Circle of aiding and abetting conversion and of negligence. Cryptocurrency analytics firm Elliptic previously suspected the attack may be linked to North Korea–backed hackers; the stolen funds were subsequently converted into ETH and laundered through Tornado Cash.
According to CoinDesk, Drift Protocol—the largest decentralized perpetual futures exchange on Solana—announced it has secured up to $147.5 million in funding from Tether and its partners (including $127.5 million from Tether and $20 million from other partners) following a hack that stole over $270 million. The funds will be used to restore user assets and relaunch the protocol. The attack was carried out on April 1 by a North Korea–linked group that had posed as a quantitative trading firm and infiltrated the protocol for approximately six months, causing the DRIFT token’s value to plummet roughly 70%. The funding structure combines revenue-linked credit, ecosystem subsidies, and market-maker loans, aiming to cover approximately $295 million in user losses. Upon relaunch, the protocol will replace USDC with USDT as its core settlement layer; Tether will simultaneously provide fee waivers, user incentives, and liquidity support.
Odaily News Drift announced on its official website that Drift Protocol has received support from Tether and other partners. Tether intends to contribute $127.5 million, while other partners plan to contribute $20 million, collectively supporting user recovery efforts following the April 1st attack. This support package includes a $100 million revenue-linked credit line, ecosystem grants, and loans provided to market makers. Drift will establish a dedicated user recovery pool, aiming to gradually address the $295 million in outstanding user losses as trading revenue grows. Additionally, Drift will issue independent recovery tokens to affected users, which represent a claim on the recovery pool and are transferable. Drift is currently in the process of restarting the protocol, having engaged Ottersec and Asymmetric for audits, and is migrating its settlement layer from USDC to USDT. The previous attack resulted in the theft of assets worth approximately $295 million, while the insurance fund assets remained unaffected.