Crypto hacks hit $764M in Q2 as bridge exploits climb
The second quarter was one of the most expensive on record for crypto security. Nearly $764 million was stolen across 67 incidents, and the pattern behind the losses should change how you think about where you keep your coins.
- Hackers stole about $764 million across 67 incidents in the second quarter of 2026, pushing first-half losses to roughly $1.3 billion.
- The attacks are getting more surgical: fewer incidents, bigger hauls, and a focus on the keys and bridges that move assets between chains.
- In one late-July example, attackers drained 24 million USDC from a bridge on Arbitrum after compromising the keys of five validators.
Crypto security had a bad quarter. According to industry trackers, thieves made off with roughly $763.9 million across 67 separate incidents in the second quarter of 2026, and the single biggest point of failure was not clever code. It was access. First-half losses now sit near $1.3 billion.
The more important shift is in how the money is being taken. One analysis described 2026's attacks as fewer but far more surgical, meaning the number of hacks is down while the average theft is up. Attackers are spending less time spraying at small targets and more time going after the places where large amounts of value concentrate.
Bridges are the weak point
Nothing illustrates that better than the late-July attack on a cross-chain bridge. On July 22, attackers withdrew 24.15 million USDC from a custodial bridge on Arbitrum. They did not break the math of the blockchain. They obtained the private keys of five validators, which was enough to reach the quorum needed to approve the transfer, and then simply signed it. On the same day, two cross-chain bridges were hit for a combined $31.5 million.
Bridges are attractive to attackers for a simple reason: they hold large pools of assets and rely on a small set of signers to approve movements. Compromise enough of those signers and the funds follow.
The threat has moved offline too
Not every attack happens on a keyboard. So-called wrench attacks, where someone is physically coerced into handing over access, exposed about $124 million in the first half of the year according to one security firm. It is an uncomfortable reminder that in crypto, the person is sometimes the easiest thing to break.
What this means for you
You do not run a bridge, but the lesson still applies. The safest place for coins you are not actively using is self-custody in a hardware wallet, where the keys never touch the internet. Be cautious about parking large balances in bridges or leaving them on platforms longer than you need to, and keep your holdings to yourself. If you want a starting point, our hardware wallet guide covers the ones we actually trust.
Our read
The following is ScalpStreet analysis, not reporting. The headline number matters less than the trend. When the weakest link is access rather than code, the fix is not waiting for better smart contracts. It is boring, personal security: a hardware wallet, restraint with bridges, and discretion about what you hold. Those three habits remove most of the risk that made this quarter so costly.
- Coinpedia, "Crypto Hacks Surged to $763M in Q2 2026 as Operational Failures Spike." coinpedia.org
- Forbes, "'Fewer But Far More Surgical' - Crypto Hacks Hit $1.3 Billion In 2026," July 17, 2026. forbes.com
- The Crypto Times, "Crypto Wrench Attacks Exposed $124M in H1 2026: CertiK Report," July 23, 2026. cryptotimes.io
Keep reading
Europe's MiCA deadline has passed, and most firms did not make it
As of July 1, the European Union's crypto rulebook is fully in force. Of more than 1,200 firms that once held national registrations, only about 210 hold full authorization.
Polkadot and XRP Ledger lead a rare green day for altcoins
On a day the broader market slipped, a handful of altcoins pushed higher. Polkadot and tokens tied to the XRP Ledger led the gainers, but with Bitcoin dominance near 56%, this looks like selective strength rather than the start of an altcoin season.