April 2026 produced $621 million in decentralized finance hacks, the sector's worst month since March 2022, with 66% of the damage traced to compromised access controls rather than smart-contract flaws, according to Binance Research.
The losses were not caused by code that failed. They were caused by permissions that ended up in the wrong hands.
A Record Number of Incidents, and Almost None of the Damage
Contracts have got harder to break, and that is the point. Years of audits and hardened engineering pushed the attack outward, onto the keys and credentials and the infrastructure a team logs into every morning.
Most months bury that shift inside a single headline number. April did the opposite: its internal composition points the other way from its total. DL News counted 29 separate incidents across the month, the highest count it has recorded, and 24 of those came from ordinary code bugs.
Those two dozen contract bugs produced about $42 million between them, which DL News put at roughly 6.6% of the month's total on its own count. When the most frequent attack and the most expensive attack stop being the same attack, defending against one buys very little protection from the other.
Days of Setup, Seconds of Withdrawal
The two incidents that produced almost all of April's damage read as operations rather than exploits.
Global Ledger's reconstruction of the Drift Protocol breach describes an attacker who spent roughly nine days on setup creating durable nonce accounts to hold pre-signed transactions, obtaining multisig approvals and running a small test withdrawal. He then took about 10 seconds to drain more than fifteen asset types inside a total execution window of roughly 11 minutes.
Kelp DAO ran on a similar clock. The first unauthorized transaction landed one minute and 48 seconds after the attack began, and consolidation into the attacker's wallet finished in just under two hours. Those two incidents, together with Grinex at $19.38 million, accounted for more than 93% of the $641.67 million Global Ledger tracked across all crypto hacks that month, a wider scope than Binance Research's DeFi-only figure.
Nine days of quiet groundwork and ten seconds of withdrawal is not what a contract exploit looks like. It is what an operation against people and process looks like, and none of it happens anywhere a code review would be looking.
"Code is no longer necessarily the weakest link in Web3," says Jimmy Su, Chief Security Officer at Binance. "As smart contract security improves, attackers are shifting their attention to the people, credentials and governance systems surrounding protocols. We saw this firsthand when Binance Security helped prevent a $1.2 million governance attack on BrainTrust. Protecting a protocol today means securing not just its code, but also who can control it, how that control is exercised, and the infrastructure and people behind it."
The Containment Layer Failed as Well
The failures did not stop at the protocols. Two of the layers meant to contain the damage did not hold either.
Kelp's cross-chain messaging ran a single-verifier configuration, and responsibility for that choice is publicly disputed. LayerZero has said Kelp selected the setup against its recommendations. Kelp has said the configuration was LayerZero's own documented default. Both positions are on the record and neither has been resolved.
At the asset layer, roughly $232 million in USDC moved from Solana to Ethereum over about six hours after the Drift breach without being frozen. Circle's chief executive has said publicly that the company blocks funds only pursuant to court orders or law enforcement requests.
A proposed class action filed in the Southern District of New York in April 2026, McCollum v. Circle Internet Group, disputes that account and alleges the issuer had both the authority and the technical means to intervene. The allegations are untested.
When containment depends on a default setting and a discretionary freeze, the recovery window gets set by decisions nobody at the exploited protocol made.
July Looked Nothing Like April
April was an outlier in both directions. Halborn's monthly figures put January at about $86 million, February at $23.5 million and March at more than $27 million, a first quarter of roughly $136 million against an April four and a half times larger on its own.
The knock-on was systemic rather than contained. DeFi total value locked fell to $82.4 billion—a one-year low and about 25% below the roughly $110 billion recorded at the start of 2026. One session took 5.6% off the sector, approaching the 98th percentile of daily declines since 2024, and lending protocols came off worst at about 13%.
Building a threat model on one bad month is how you get the next one wrong. QuillAudits' reading of July 2026 puts total losses above $242 million but attributes 45% of it to weak key generation in a single hardware-wallet incident and only 16% to private key and credential compromise. Three months after access control accounted for two thirds of the damage, it accounted for a sixth. April's composition would have mis-predicted July almost entirely.
A Decomposition, Not a Forecast
April holds up as an autopsy rather than as a forecast. What it decomposed was a set of operational and human failures no amount of contract review would have reached, and that distinction is more useful to a protocol planning its next security spend than the headline number ever was.
The Hacker News https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQyjwPYjJP0wddSEB8Dlpr3dlnQUs52-WmlrZfqJoBPeOvv2Zoqlq-FhEAz_Xeprj_mtrI1MGCW1JS840JUjVEK6VoNe6zCNNTw_7YmyvNmf3E5pprZ3zqP8lszq74Wt97SvbJo5yeuyep0U6-nGs0vdarg4_WUrc5r6L0ML0xE-BsPipJd2-1PMHTvO1/s76-e365/thn.jpg


