CertiK Mid-Year Report: The frequency of hacker attacks has not decreased but increased, and private key management has become the biggest shortcoming in security

sourceCOINTELEGRAPH·谢伟伦·10:46 编辑
CertiK Mid-Year Report: The frequency of hacker attacks has not decreased but increased, and private key management has become the biggest shortcoming in security

Source: COINTELEGRAPH

author:Brayden Lindreareporters

Original title: CertiK: Crypto hacking incidents decreased by 47% in the first half of the year, but ecosystem security did not improve


According to the CertiK report, cryptocurrency utilization incidents rose 59% month-on-month in the second quarter, reaching US$807.5 million. This was mainly due to attacks on KelpDAO and Drift Protocol, and North Korean hackers were behind it.

Cryptocurrency losses fell 46.8% year over year to $1.32 billion in the first half of 2026, but cryptocurrency security firm CertiK said the decline was misleading and warned that attackers were becoming more complex and disruptive.

CertiK reports that losses in the first quarter were mainly driven by phishing attacks, totaling US$508.2 million. In the second quarter, the wallet was breached as the main attack route, causing a loss of 807.5 million US dollars.

More than 70% of losses in the second quarter stemmed from the hacking of KelpDAO and Drift Protocol, which are believed to have been carried out by North Korean state-sponsored hackers.

CertiK told CointeleGraph: “The appearance of 'loss reduced by nearly 50% 'makes people think the ecosystem is safer, but the data does not support this conclusion.” CertiK explained that data for the same period last year was seriously boosted by the $1.4 billion Bybit hack (the biggest cryptocurrency attack in history).

According to data, North Korean hackers are still one of the biggest threats to the crypto industry. TRM Labs estimated in April this year that since 2017, these hackers have stolen more than 6 billion US dollars in cryptocurrencies.

The amount of cryptocurrency attacks and the number of incidents changed monthly in the first half of the year. Source: CertiK

North Korean State Actors Accused of Launching Cryptocurrency Attacks

The KelpDAO and Drift Protocol incidents even prompted officials from the US, Japan, and South Korea to meet at the end of last month to discuss how to deal with North Korea's malicious cyber activities and illegal revenue collection methods.

Officials also acknowledged that North Korean IT practitioners are increasingly using AI to enhance their attack plans — some cybersecurity experts believe this has greatly increased the scale, speed, and complexity of the agreement's attacks.

CertiK warned that “the industry is currently experiencing a higher frequency of structural attacks than last year” and that — if the Bybit incident is not taken into account — attacks are becoming “more targeted and more financially disruptive in a single run.”

TRM Labs stated in its 2026 H1 report that “the decline in the total amount of stolen funds should not be mistaken for a safer environment.”

“A lower total amount simply means no record breaking theft, not a reduction in attackers' capabilities.”

TRM's analysis showed that the number of incidents during the H1 period soared from 83 to 207, setting a record for the largest TRM six-month period.

TRM also added that smart contracts were used to account for 125 of all H1 events, accounting for 60%.

Private key protection

According to CertiK, private key and multi-signature wallet management are still the “most critical security aspects” exploited by attackers.

CertiK urges cryptographic protocols and institutions with large on-chain assets to strengthen private key management at every level — including hardware security, multi-signature governance, and even geographically dispersed signers.

According to CertiK, this is “an area where safety investments achieve asymmetric returns.”

Cryptographic hardware wallet vendors such as Ledger have also long reminded users to store mnemonic words offline and never leak them to prevent phishing attacks.


Twitter:https://twitter.com/BitpushNewsCN

Compare the TG exchange group:https://t.me/BitPushCommunity

Compare TG subscriptions:https://t.me/bitpush

Original Link
#CertiK报告#加密安全#朝鲜黑客#私钥管理
说明: All Bitpush articles reflect the author's views only and do not constitute investment advice.

Related

Loading...