The crypto industry has been hit with a staggering wave of thefts in the first half of 2026, with hackers walking away with nearly a billion dollars. A new report from security research firm ack3 reveals that 135 separate exploits occurred between January and June, resulting in total losses of $939.86 million. That averages out to roughly $6.96 million lost per incident — a sobering reminder of the persistent risks in the digital asset space. Even more alarming, the report indicates that the vast majority of these attacks slipped past security audits, raising serious questions about the effectiveness of current safeguards.
Audits Failing the Industry
Security audits have long been considered a cornerstone of crypto safety, with projects spending significant resources to have their code reviewed by third-party experts. However, ack3's data paints a troubling picture: a staggering 94% of the exploited vulnerabilities were not detected by audits prior to the attacks. This suggests that many audit processes are not keeping pace with the evolving tactics of malicious actors.
While audits remain a valuable tool for identifying common coding errors and known vulnerabilities, they appear to be missing the more sophisticated or novel attack vectors that hackers are now exploiting. The report highlights a critical gap in the industry's defense-in-depth strategy, as projects often rely on a single audit as their primary security measure.
Attack Vectors and Targets
According to ack3's findings, the 135 verified exploits targeted a wide range of platforms, including DeFi protocols, bridges, and centralized exchanges. The report does not single out specific victims, but the sheer volume of attacks indicates that no sector is immune. The average loss of nearly $7 million per event underscores the high value that hackers place on crypto assets.
The report also notes that the pace of attacks shows no signs of slowing down. With the first half of 2026 alone seeing nearly a billion dollars in losses, the annual figure could easily exceed $2 billion if the trend continues. This makes it imperative for projects to adopt more robust and continuous security monitoring rather than relying solely on point-in-time audits.
Why Audits Miss the Mark
Several factors may explain why audits are failing to catch these vulnerabilities. For one, auditors often operate under time constraints and may not have the full context of a project's business logic. Additionally, many exploits stem from complex interactions between smart contracts, which can be difficult to simulate in a test environment. The rapid pace of development in DeFi also means that new code is constantly being deployed, creating a moving target for security reviewers.
What This Means for Investors
For crypto investors, the ack3 report is a stark reminder that due diligence cannot stop at a project's audit badge. The fact that 94% of attacks bypassed audits suggests that relying solely on audit reports is insufficient. Investors should demand more transparency about a project's security practices, including whether it has a bug bounty program, conducts regular penetration testing, and has a clear incident response plan.
Moreover, the report underscores the importance of diversification and risk management. Holding assets across multiple platforms and using cold storage for long-term holdings can mitigate the impact of a single exploit. As the industry matures, the expectation is that security standards will improve, but until then, caution is warranted.
Key Takeaways
- $939.86 million was lost in 135 crypto exploits in H1 2026, averaging $6.96 million per incident.
- A staggering 94% of exploited vulnerabilities were missed by security audits, calling their effectiveness into question.
- Attack vectors are evolving faster than audit methodologies, requiring a more dynamic and layered security approach.
- Investors should not rely solely on audit reports and must implement their own risk mitigation strategies.
As the crypto industry continues to grow, so do the threats it faces. The ack3 report serves as a critical wake-up call for both project developers and investors to prioritize security beyond the surface level. Until audits become more comprehensive and adaptive, the sector remains vulnerable to the next wave of attacks.
Zyra