Cryptocurrencies,  Security

$483 Million Lost to Hackers and Scammers in Q1

That’s up $84 million over Q4 2025

Bar chart of crypto losses by quarter

Scammers and hackers stole $482.6 million in crypto during the first quarter of 2026, according to security firm Hacken. That was a 21% increase over Q4 2025’s $399 million.

In its Q1 2026 Security and Compliance Report, Hacken noted that phishing and social engineering scams dominated losses, accounting for $306 million — more than 63% of the total — with a single $282 million hardware wallet scam in January accounting for more than half the quarter’s losses. There were 44 incidents recorded.

Smart contract vulnerabilities saw the biggest gain, reaching $86.2 million over 28 exploits. That’s up 213% compared to Q1 2025. Access control failures, including compromised keys and cloud services, were responsible for another $71.9 million in losses.

Still, Q1 2025 had far higher total losses thanks to the $1.4 billion Bybit hack — an access control failure.

Reviews are not enough

One finding that emerged is that while protocol audits are necessary, the security reviews are not enough.

“Traditional audits review code at a point in time; they do not monitor live systems, detect operational compromises, or enforce runtime invariants,” Hacken said. “The industry needs a shift from audit-and-ship to continuous security monitoring as a baseline expectation.”

Hacken pointed to the three smart contract incidents, noting that the Venus Protocol worked with five audit firms, Solv Protocol had three firms and Resolv Labs underwent 18 audits.

It pointed out that real-time anomaly detection on minting and collateral ratios, and protocol-level circuit breakers can flag attacks minutes into execution rather than hours after completion.

“The findings are consistent across every contributor: failures are emerging across code, infrastructure, operations, and human processes simultaneously,” said Yev Broshevan CEO & Co-Founder of Hacken. “No single audit, certification, or tool addresses that. Continuous, layered protection is the only posture that works.”

The industry needs to move away from audit-and-ship to continuous security monitoring as a baseline expectation, Hacken added.

 You May Also Like

Leo Jakobson, Modern Consensus editor-in-chief, is a New York-based journalist who has traveled the world writing about incentive travel. He has also covered consumer and employee engagement, small business, the East Coast side of the Internet boom and bust, and New York City crime, nightlife, and politics.