
Despite the overall decline in DeFi hack losses, recent developments show three significant exploits occurred within 24 hours, demonstrating that while median hack sizes have fallen, the frequency of attacks remains elevated. According to TenArmor, an attacker exploited a vulnerability in FCOW token on BNB Smart Chain, causing an estimated $61,300 loss. DefiTuna revealed that an attacker took advantage of its lending pools, causing an estimated $580,000 loss and leaving its USDC pool with a similar deficit. Most notably, PeckShield reported that Cascade was exploited, allowing user funds worth approximately 1.34 million USDC to be stolen. The attacker swiftly transferred the stolen assets between several blockchains by bridging funds from Arbitrum to Solana before transferring to Ethereum via Relay Protocol and transforming them into DAI.
According to CertiK blockchain intelligence firm, total cryptocurrency hack losses in H1 2026 decreased 47% to $1.32 billion, marking a significant improvement from the previous year. The median hack size in DeFi has fallen below $500,000 in 2026, representing a dramatic reduction from over $2 million in 2025. As reported by CoinTurk, April 2026 saw crypto losses reach approximately $644 million, making it the highest monthly total in over a year, with the last comparable peak occurring in February 2025 when the Bybit incident caused monthly losses to spike to $1.46 billion. Despite the relative decline in headline losses, experts stressed that DeFi platforms remain exposed to risks, particularly from sophisticated attackers using automated or artificial intelligence tools. However, Dragonfly's Haseeb Qureshi has provided additional context, noting that annualized hack losses in 2026 are running below 2025 levels and remain within historical ranges, directly challenging months of dire warnings about large language models being used to scan contract code at scale.
As reported by AMBCrypto, 75% of the nearly $1 billion stolen in 2026 was linked to operational failures, but this trend is showing signs of decline. Dragonfly's Haseeb Qureshi noted that operational security failures related to admin keys or signing infrastructure are dropping, with admin key/multisig hacks also declining in dollar terms. However, OpenZeppelin's Manuel Aráoz has expressed deep skepticism about DeFi's safety due to advancements in AI code analysis, warning that smart contracts remain highly vulnerable to exploitation by automated tools. The analysis suggests that hacks are moving toward smaller protocols, with malicious actors using AI seeming to increasingly target minor projects and neglected platforms rather than established protocols that have improved their defenses. Qureshi's observations directly challenge the narrative that AI would supercharge DeFi exploits, instead showing that crypto-native security investments—formal verification, bug bounties, and upgrade delays—are absorbing the blow. The decline in losses from admin-key and multisig compromises suggests that the most glaring operational weaknesses are being patched, especially at protocols with meaningful treasury exposure.
According to AMBCrypto reports, capital outflows from DeFi vaults have hit over $50 billion amid broader market downturn and security concerns. The value locked in DeFi vaults dropped from $113 billion to $61 billion before slightly recovering to $65 billion as of writing. This decline occurred despite vaults offering 2.7%-3.8% average yield, making DeFi relatively riskier and less lucrative than U.S. Treasury bills. The bank run on leading DeFi lending platform Aave after the KelpDAO hack underscored how major players were also fragile. For users, the practical implication is that capital concentrated in top-tier lending markets, decentralized exchanges, and liquid staking protocols now faces meaningfully lower hack risk than it did in 2022 and 2023. The rise in raw incident count paired with falling median losses tells a specific story where attackers are probing forgotten forks, unaudited yield aggregators, and projects that launched during past market exuberance but now sit with minimal total value locked, generating more headlines but less financial damage.
As reported by AMBCrypto, S&P Global Ratings views DeFi vaults as equivalent to managed funds, with the rating firm projecting that vaults could become 'core infrastructure' for tokenized real-world assets and institutional capital. However, whether the ongoing DeFi security fears will derail this major adoption unlock remains uncertain, as institutional investors continue to evaluate the risk-reward profile of DeFi investments. The broader trend worth watching is how on-chain capital is concentrating into a shrinking number of battle-tested applications, with recent tokenization milestones and institutional settlements underlining that serious money is flowing toward infrastructure that has demonstrably survived adverse events. Security track records are becoming an asset class differentiator, not just a technical metric, as the gap between AI threat narratives and actual loss data reveals more about media cycles than attacker capabilities. The resilience of established DeFi codebases is not happening in a vacuum, with regulatory scrutiny from agencies in multiple jurisdictions pushing major teams to tighten admin controls, implement timelocks, and submit smart contracts to multiple independent audits.