TL;DR. 2026 has recorded more crypto exploits than any year on record, over 200 in the first half alone, more than one a day. The dollars stolen are actually lower than 2025, because no single theft matched last year’s $1.5 billion Bybit hack, but the number of attacks has roughly doubled. The driver is AI, which has lowered the cost and skill needed to probe software until attacking a small protocol became economical for the first time. That same technology is now the strongest defense.

What the numbers actually show

The clearest way to see 2026 is to separate two things that usually get merged, how often protocols are attacked and how much is taken when they are.

The picture is a divergence. Total value stolen peaked in 2021 and 2022, dipped through the bear market, and has stayed well below those highs. The number of incidents did the opposite, holding steady for years and then climbing sharply. By CoinGecko’s count, 2026 logged 164 separate incidents through early August, already more than any full prior year, with the next-highest annual figure being 2025’s 97. TRM Labs recorded 207 hacks in just the first half of 2026, more than double the 83 from the same period a year earlier, and Blockaid independently verified 212.

The dollar figures need care, because they are easy to misread as good news. H1 2026 losses came in around $972 million to $1.1 billion, below H1 2025. But as TRM’s Ari Redbord noted, that decline happened almost entirely because North Korea did not repeat an operation on the scale of the $1.5 billion Bybit hack. One outlier event in 2025 flattered the year-over-year comparison. Set it aside and the trend is more attacks, spread across more protocols, each taking less. That is a specific signature, and it points to a specific cause.

The evidence for the AI thesis

There is a straightforward economic reading of that signature. If attacks suddenly get cheaper to run, you would expect many more of them, reaching down to targets that were previously too small to bother with. That is what the data shows, and it lines up with what the security firms are measuring directly. TRM reported in August 2026 that AI adoption across crypto crime rose 40% year on year, and framed the mechanism plainly, AI did not invent new crimes, it removed the constraints on old ones. The skill floor dropped, the scale ceiling lifted, and fake identity went industrial.

The economics were put most directly at the Wyoming Blockchain Symposium, where Global Settlement Network’s Ryan Kirkley observed that it used to be too costly to hack someone worth $20,000, because the time was not worth it, and that an AI agent can now go after everyone at once. Three recent incidents show the range of what that enables.

Small teams overwhelmed by volume

In August 2026, two Bitcoin swap services shut down within weeks of each other citing the same cause. Boltz suspended operations, describing months of steadily rising automated, AI-assisted probing that its team could not patch fast enough. Atomiq followed, taking its swap routes offline because, as a small team, it could not fight the numerous sophisticated AI-assisted attacks on its infrastructure.

Governance nobody was watching

On August 23, Term Labs lost about $8.5 million, and the mechanism is worth understanding because no code was broken. Term’s vaults were governed by a token almost nobody had bothered to hold. The attacker simply acquired the governance tokens, which cost a few dollars in vault shares, then held 100% of the vote on five of the drained vaults. He opened a proposal styled to look like a routine parameter update, waited out the six-day minimum, and executed a bundle of 17 actions that recalled every asset into a strategy contract he controlled.

Scale as the point

On August 22, Blockaid detected an ongoing exploit of The Sandbox’s SAND token on Base, where attackers hijacked LayerZero delegate permissions and minted unbacked SAND across hundreds of transactions. The mechanism was a permissions oversight, and the automation is what made it relentless.

The frontier of this is already visible. Researchers disclosed JadePuffer, described as the first fully agentic ransomware, where an AI agent ran reconnaissance, credential theft, lateral movement, and encryption end to end, and Blockaid flagged a $216,000 exploit of an AI trading agent as the first of its kind, expecting prompt-injection attacks on agents to grow through the year.

Why this is a whole-industry problem, not a crypto flaw

It is worth being precise about what these incidents do and do not say about crypto. Very little of the 2026 record is smart-contract cryptography failing. The two largest H1 losses, Drift at roughly $285 million and KelpDAO at roughly $292 million, both traced to LinkedIn social engineering leading to a compromised multisig signer, the same human-layer attack that hits banks and enterprises. The Bybit hack that defined 2025 was a compromised interface at a wallet infrastructure provider, not a flaw in Ethereum.

And on the pure-code side, the direction is genuinely encouraging. Immunefi’s six-year data shows DeFi protocol losses fell about 80% from the 2022 peak of $2.62 billion to $534 million in 2024, with the median loss per incident dropping from $6 million to $1.5 million even as total value locked grew substantially. The old ecosystem-class attacks, flash-loan oracle manipulations and reentrancy, collapsed from nearly 19% of losses in 2022 to under 1% in 2025. Crypto’s core smart-contract security has been maturing, not decaying. What changed in 2026 is not that the code got worse. It is that AI made probing every layer, especially the human and operational layers, cheap enough to do at scale, and that pressure is arriving everywhere software runs. Crypto simply feels it first, because its infrastructure is open-source, its value is liquid, and its teams are often small.

The defense is the same technology, but access to it is gated

The encouraging half of the story is that the capability driving the attacks is also the strongest available defense. The important qualifier is that this defense is not something a protocol can simply switch on, and that is by design.

Anthropic launched Project Glasswing on April 7, 2026 on a deliberate premise. It had built a frontier model, Claude Mythos, that it assessed could surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Releasing that openly would hand the same capability to attackers, so Anthropic did the opposite and distributed it narrowly, to defenders of software whose compromise would be catastrophic. The launch cohort was around 50 organizations and reads like a list of the world’s most critical infrastructure, Apple, Microsoft, Amazon, Google, NVIDIA, JPMorgan Chase, Cisco, CrowdStrike, and the Linux Foundation among them. Access is invitation-only with no self-serve signup, and every organization has to meet Anthropic’s security requirements before it is granted the model.

The early results were substantial. In roughly a month, Glasswing partners used the model to find more than 10,000 high- or critical-severity vulnerabilities across systemically important software, including a critical flaw in a cryptographic library used by billions of devices, since patched, and one partner bank used it to detect and stop a fraudulent $1.5 million wire transfer. In May the program expanded to roughly 150 organizations across more than 15 countries, still centered on critical infrastructure in power, water, healthcare, and communications, and the US Federal Reserve and Treasury convened bank leaders over its implications. Anthropic has signaled that a broader, application-based access program for security organizations is in development, but it is not open yet.

That gating is why crypto’s entry point matters. In August 2026, Payward, the parent company of Kraken, joined Project Glasswing and adopted Claude Mythos for security, which makes it one of the first crypto firms known to reach this tier of defensive capability. It is a large, regulated exchange, exactly the profile the program targets, and its inclusion is a signal rather than a broadly available option. Most crypto teams cannot join Glasswing today. What they can do is use the widely available Claude and other AI models for defensive review, adopt the third-party security tooling being built on top of them, and prepare for the moment the capability becomes more accessible, which by Anthropic’s own timeline is months, not years, away for both sides.

How this could progress

Reading the current evidence forward, a few things look likely rather than certain.

Incident counts keep rising before they fall

As long as running an attack stays cheap, the frequency stays high, and the targets keep getting smaller. The near-term trend line is more incidents, lower average value, which is the 2026 signature intensifying rather than reversing.

The human and operational layers become the main battleground

The largest losses of 2026 were social engineering and unwatched governance, not broken math. Hardware-enforced signing, out-of-band verification of large transfers, active governance participation, and multisig hygiene are where the most value can be protected, and where AI-driven phishing will keep applying pressure.

Defensive AI adoption widens as access opens up

Today the most powerful defensive models sit behind gated programs like Glasswing, reaching a handful of large, vetted firms such as Kraken’s parent. But Anthropic expects Mythos-class capability to be available from multiple providers within 6 to 12 months, and is building a broader application-based access path. As that gate widens, running these models on your own systems first shifts from a rare advantage to a baseline expectation, and the teams that prepared their processes early will move fastest when it does.

Patch cadence compresses toward machine speed.

When bugs are found in hours, quarter-long patch windows are untenable. The maintainers who keep pace, and the disclosure norms that let them, become as important as the audits themselves.

The honest summary is the one the security firms keep returning to. AI removed the constraints that used to limit attacks, and that will not be undone. But the same technology, in defenders’ hands, finds the same flaws first, and the industries deploying it are moving. Crypto is early to this fight because of how it is built, open, liquid, and lean, and that makes it the clearest place to watch how the balance settles. The goal is not an unhackable system, which has never existed in any industry. It is to close the speed gap, and 2026 is the year that race began in earnest.

Sources

TRM Labs: AI in crypto crime (via The Block) and H1 2026 hacks reportCoinGecko: crypto hacks 2016–2026Immunefi: six years of DeFi loss dataBlockaid H1 2026 coverage: CryptoBriefing, FXStreet, PrimeXBTThe Block: AI agents and future hacksAnthropic: Project Glasswing and initial updateThe Hacker News, TechCrunch, CNBC, CoinDesk on PaywardThe Defiant: Boltz halts swapsIncident disclosures: Term Labs, Atomiq, Blockaid on Sandbox

2026 Crypto’s Most-Hacked Year, and the AI Race to Defend It was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

By

Leave a Reply

Your email address will not be published. Required fields are marked *