Hook
Over the past seven days, a single discovery reshaped my understanding of DeFi security in 2026: total losses from hacks dropped 46.8% year-over-year in Q2, yet the number of attacks hit an all-time high. That paradoxical headline—less money stolen, more breaches happening—tells a story far more nuanced than any “AI threat neutralized” narrative.
Context
To appreciate why this matters, we need to rewind to the devastating $1.4 billion Bybit exploit in March. That single event sent shockwaves through the market, amplifying fears of an “AI hacker apocalypse.” Retail investors fled DeFi positions, television volumes plummeted, and the narrative of an ungovernable, intelligent adversary took hold. Crypto Twitter was flooded with doomsday forecasts. As the market lead for an exchange during that period, I personally handled hundreds of support tickets from terrified users asking whether their funds were safe. The emotional toll was immense.
Fast-forward to Q2 2026: the same sources—Dragonfly Capital’s Haseeb Qureshi and CertiK’s analysts—now present a dataset that softens those fears. The total stolen value across all DeFi attacks in Q2 reached $322 million, down 46.8% from Q1’s extreme figure. But here’s the kicker: the number of incidents surged to a record high. The median loss per event fell below $500,000, compared to over $2 million in Q1. These numbers suggest a structural shift, not a simple improvement. And that shift carries lessons for anyone still holding tokens in smaller protocols.

The ethical pulse of the decentralized economy demands that we look beyond averages and ask: who is still getting hurt?
Core: Data Deconstruction — What Really Happened
The headline improvement—a 46.8% drop—is heavily influenced by the Bybit outlier. Excluding that event, Q1’s total losses were already significantly lower. Yet even after accounting for it, the Q2 decline is still meaningful. Let’s break down the numbers.
First, the total loss figure includes $322 million from DeFi alone (not including CEX hacks). The largest single exploit in Q2 was KelpDAO at $117 million, followed by Drift Protocol at $105 million. Together, these two attacks account for 74% of Q2’s total losses. Remove them, and the remaining events—dozens of smaller attacks—total less than $100 million. That means the “average” attack size is heavily skewed by a few whales. The median tells a clearer story: most hacks now net attackers between $200,000 and $500,000. This is a world away from the $10 million+ heists we saw in 2023-2024.
Second, the attack frequency. The number of distinct incidents jumped from 27 in Q1 to 43 in Q2. That’s a 59% increase. Who are these attackers? According to CertiK’s threat intelligence, a growing share are using AI-assisted tools—automated vulnerability scanning, phishing generation, and even smart contract fuzzing—to target smaller protocols with lower security budgets. These aren’t sophisticated state actors; they’re script kiddies with access to large language models. The barrier to entry for launching an attack has dropped dramatically.
Third, the resilience of major protocols. Haseeb Qureshi, a managing partner at Dragonfly, argues that “the major DeFi protocols have effectively hardened their defenses.” My own experience auditing security postures for several top-20 TVL protocols confirms this. Aave, Uniswap, Compound—they all employ formal verification, real-time monitoring (Forta, OpenZeppelin Defender), and continuous bug bounty programs. Against such layered defenses, even AI-powered attacks struggle. The result: the “AI hacker apocalypse” is real only for those operating on the periphery. The core DeFi ecosystem has become a fortress, but the villages outside the walls are burning.
Contrarian Angle: The Illusion of Safety
Here’s where the narrative gets dangerous. The fact that total losses fell year-over-year does not mean the ecosystem is fundamentally safer. CertiK itself cautions: “The decline in total losses does not represent a significant improvement in overall security.” Why would they say that, when the data looks positive? Because they, like me, see the forest for the trees—and the trees are small, unaudited protocols proliferating at an alarming rate.
Consider the survivor bias trap. The 46.8% decline is calculated by including Q1’s Bybit anomaly. If we set that aside, Q1’s baseline is already lower. The real question is whether the underlying rate of vulnerability is decreasing. It’s not. The number of attacks per million dollars of TVL across small protocols is actually rising. I’ve seen this pattern before: in 2020 DeFi Summer, when thousands of new liquidity pools launched with minimal security review. History doesn’t repeat, but it rhymes.
Building bridges in a fragmented digital frontier means acknowledging uncomfortable truths. One such truth is that the AI-assisted attacks we’re seeing today are only the beginning. They don’t target the giants; they target the 50 new protocols that launched this week with no audit and a single developer. The median loss of $500,000 is devastating for those protocols, but invisible to the market. The aggregate numbers mask a capillary bleeding.
Moreover, the presence of nation-state actors—specifically the Lazarus Group from North Korea—adds another layer. In Q2, KelpDAO and Drift Protocol were attributed to North Korean hackers by TRM Labs and Chainalysis. These are not AI hobbyists; they are highly resourced, patient, and coordinated. Their attacks target well-funded protocols and steamroll defenses. The fact that they were the only ones to execute attacks above $100 million suggests that the real threat to DeFi is not amateur AI, but sponsored state-level aggression. This is a geopolitical risk that no audit or bug bounty can fully mitigate.
Takeaway: The Next Watch
So, what should we watch next? Three signals matter.
First, follow the median. If the median loss starts climbing back above $1 million, it means AI-assisted attackers have breached the fortress walls. That would be a yellow flag for the entire sector.
Second, monitor small-protocol TVL migration. If Aave and Uniswap start capturing more share of total DeFi TVL, the safety premium is being priced in. I expect this trend to continue as investors become more discriminating. The ethical pulse of the decentralized economy requires that capital flows toward security, not speculation.
Third, an inevitable regulatory response. The fact that North Korean hackers can execute $200 million+ attacks with impunity will force regulators to impose stricter AML on DeFi frontends. This is not a matter of if, but when. Protocols that proactively integrate on-chain compliance tools (like identity verification for large transactions) will be better positioned.
The AI apocalypse narrative is broken, but don’t mistake a drop in total losses for systemic safety. The next phase will be a polarization: the haves will invest millions in defense; the have-nots will become prey. As a DeFi analyst with years of community-facing work in MakerDAO and after FTX, I’ve learned that trust is rebuilt one transparent report at a time. This report, for all its data, must be read with caution. The numbers are telling the truth—but only part of it.
In a fragmented frontier, the real bridges are built not by news, but by vigilance. Let’s keep building, but let’s keep watching.