CertiK’s Hack3D report for the first half of 2026 counts $1,315,676,432 stolen across 344 Web3 incidents. Its category table contains a pairing that most summaries skip. Wallet compromise cost $444.5 million from 33 incidents. Code vulnerabilities cost $151.6 million from 204. By cost, compromised wallets lost nearly three times as much; by count, code bugs were more than six times as common. That supports the argument that security audits cover the cheaper half of the problem, with a caveat the same data supplies: two April incidents account for nearly 44% of everything stolen.

The numbers

  • Total, H1 2026: $1,315,676,432 across 344 incidents. After $115,311,507 of frozen and returned funds, adjusted losses were $1,200,364,925 (CertiK).
  • Wallet compromise: $444,531,691 across 33 incidents, about $13.5 million per incident (CertiK; the per-incident figure is our division).
  • Phishing: $366,312,027 across 63 incidents, about $5.8 million each. CertiK says four social-engineering attacks account for about 85% of phishing losses.
  • Code vulnerability: $151,591,472 across 204 incidents, about $743,000 each, with many of the targeted contracts more than a year old.
  • Together those three categories are about $962 million. The remaining roughly $353 million sits in categories we did not itemise.

The average wallet-compromise incident cost about 18 times the average code-vulnerability incident. CertiK’s Ronghui Gu put the consequence plainly in comments reported by Forbes on 17 July:

““A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.” — Ronghui Gu, CertiK, quoted by Forbes”

The mechanism is what an audit examines. A code audit reviews the contracts for flaws that let an outsider do something the design did not intend. It does not test who holds the keys that the design intentionally empowers: an admin key that can upgrade a contract, a signing quorum that can approve a withdrawal, a session credential that can reach infrastructure. If an attacker obtains those, the contract behaves as designed and the money leaves anyway.

Two incidents carry the ranking

Forbes, reporting CertiK’s data, says Kelp DAO ($291.3 million) and Drift Protocol ($285.3 million) together were about $576.6 million, nearly 44% of H1 losses. Both happened in April. CertiK’s page lists the Kelp DAO incident as an RPC compromise, and crypto.news describes it as a single compromised verifier on its LayerZero bridge that minted 116,500 unbacked rsETH on 18 April; accounts differ on the label. Crypto.news reports Drift lost $285 million on 1 April in 128 seconds, after attackers spent months building trust with contributors and used a durable nonce to obtain pre-signed Security Council authority. Elliptic tied it to Lazarus Group’s TraderTraitor unit with medium-high confidence, according to crypto.news, while CertiK said only that Drift’s breach bears characteristics consistent with DPRK-linked operational patterns.

This sensitivity matters for the headline comparison. The pages we read do not say which category each incident falls in. If Drift sits in wallet compromise, which is plausible but not stated, removing it would leave about $159 million across 32 incidents, roughly level with the $151.6 million attributed to code vulnerabilities. The ranking holds as published; it is also an outcome that one large incident can change.

Post-H1 incidents that the data does not cover

Two summer incidents are outside CertiK’s half-year window and should not be added to its total. Crypto.news reports AFX Trade lost $24.15 million on 22 July when five compromised validator signatures met the two-thirds quorum on its Arbitrum USDC bridge; the bridge’s dispute window was 200 seconds, and the exploit came 49 days after AFX promoted a Zellic audit. It is a clean example of the keys-not-code pattern: the signatures were valid because the signers were compromised.

The Coldcard case complicates the keys-versus-code framing. Galaxy Research, via crypto.news, puts the drain starting on 30 July 2026, with high-confidence losses of 1,596 BTC from about 7,300 addresses by 7 August and candidate-inclusive estimates up to 2,055 BTC. The roughly $130 million figure is crypto.news’s conversion, not Galaxy’s. Crypto.news attributes it to a firmware entropy-generation failure, which would mean the keys were weak because of a software defect. That is both a key-custody failure and a code failure, and a simple two-bucket taxonomy cannot place it. We could not independently confirm the cause.

A claim we could not support

Some coverage, including crypto.news, says compromised keys overtook smart-contract bugs as the leading attack vector for the first time on record. We checked CertiK’s report and the Forbes article and found neither contains that statement. CertiK’s page says it added dedicated first-quarter and second-quarter breakdowns for the first time, which is a different claim. The data show keys and wallets ahead of code in H1 2026 by cost; they do not show this is unprecedented. The same coverage uses DeFi and first eight months loosely, while CertiK’s figures are H1 and its scope includes scams, phishing and wallet compromises, not DeFi protocol exploits alone.

The counter-argument

Code bugs may be undercounted in cost because audits are working: many exploitable flaws are found before launch and never appear as incidents. Wallet compromise is a catch-all label, and CertiK’s page uses it in place of private-key compromise, so the two may not map exactly. A defender would also say frequency matters to protocol builders, since 204 code incidents are a much larger surface than 33 wallet incidents, even at a lower cost each. These are reasonable objections that the dataset cannot settle.

What the evidence does not establish

  • That the shift is new. CertiK’s report does not make a first-on-record claim.
  • That keys beat code in every sample. The H1 ranking depends heavily on two April incidents.
  • That $1.3 billion is the full cost. It reflects publicly attributed incidents, and CertiK reports recoveries separately.
  • Which category holds each large incident. The pages reviewed do not say.