CertiK ' s latest report shows that security losses in the encryption industry fell to $1.32 billion in the first half of 2026, a decrease of 46.8 per cent compared to the same period last year. However, this change is more a reflection of the fact that there have been no more excess events similar to the Bybit level during the statistical period, as opposed to a marked reduction in non-industry risk.

Attack to high-value target.

CertiK states that the amount of the total loss alone is susceptible to error. The attackers are reducing their actions on a large scale, randomly, and instead targeting higher-value targets, with greater financial losses resulting from single incidents.

Over the quarter, fishing attacks continued to be the main source of theft, resulting in losses of approximately $508.2 million. By the second quarter, the break-in of the wallet had replaced the fishing attack as the largest form of attack, involving losses of approximately $807.5 million.

  • First quarter fishing attack loss: $508.2 million
  • 2nd quarter Wallet Breaking Loss: $807.5 million
  • Total losses for the first half of the year: $132 billion

TRM Labs points to the same trend

CertiK stated that, if the unusually large theft of Bybit in 2025 were to be eliminated, the intensity of the attacks faced by the industry this year had not decreased structurally, and that the attackers preferred to conduct high-destructive operations against high-priority targets rather than relying on opportunity-type loopholes.

TRM Labs in the first half of the year made a similar determination. According to the Agency, the fall in the total amount of theft should not be interpreted as a reduction in the ability of the attackers, the greater reason being the absence of a record-breaking single theft during the reporting period.

Private key management remains the focus

In terms of protection recommendations, CertiK lists private key management and multi-signature wallet control as the most needed link. It recommended that agreements and institutions holding large chain assets should reinforce key management aspects, including hardware security, multi-signature governance and geographical decentralization of signatories.

TRM Labs claims that, since 2017, more than $6 billion in encrypted assets have been stolen by hackers associated with North Korea. Recent attacks related to KelpDAO and Drift Protocol have also facilitated talks between United States, Japanese and Korean officials at the end of last month to discuss ways to curb North Korean cyberoperation and its illegal revenues from encryption theft.

Ledger also continues to remind users that assistive words should be kept offline and not disclosed to anyone to reduce the risk of fishing attacks and unauthorized visits. Multiple cyber-security personnel have also warned that artificial intelligence is being used to increase the scale, speed and covertness of cyberattacks.