|
THE KILLCHAIN // No. 060 // U.S. DEBT $39.52T // 07.18.2026
The KillChain
Criminals build the trap. Institutions hold the key. We name both.
THREATS · FLOWS · POSITIONS
|

CertiK's half-year scoreboard says the attack surface moved from the contract to the custodian, and retail is still guarding the wrong door.
| GM, WELCOME BACK TO THE KILLCHAIN. |
CertiK's Hack3D report for the first half of 2026 landed this week carrying a number that looks like good news; but looks can be deceiving. $1.315 billion stolen across 344 on-chain incidents, down 46.8% from a year ago. Strip out the single event that inflated 2025, the $1.45 billion Bybit theft, and last year's comparable figure falls to about $1.03 billion. That puts 2026 roughly 28% higher, on more incidents, in a market trading lower. On paper it looks like an ecosystem getting safer. The detail underneath refuses to cooperate.
The seam has moved, and it is worth naming exactly where. For years the crypto hack meant a bug in a contract, a clever exploit of code that an audit should have caught. That is not where the money went this year. Nearly 44% of every dollar lost in six months came from two April heists, Kelp DAO and Drift Protocol, and neither one touched a line of audited code. The attackers stopped breaking the software and started breaking the people and the keys behind it.
Wallet compromise was the single costliest category of the half at more than $444 million, averaging over $13 million per event, the highest of any attack type CertiK tracks. Code exploits were still the most common by an extraordinary margin, 204 separate incidents, but they cost only $151.6 million combined, and a growing share of them hit contracts more than a year old that were audited once and never revisited. The math is blunt: the cheap, frequent attacks go after software, and the expensive, rare ones go after custody.
The two heists that defined the half show the method. Kelp DAO lost $291.3 million when attackers compromised the RPC infrastructure feeding its cross-chain bridge and pushed forged withdrawal messages through a single verifier that trusted them. Drift lost $285.3 million to a mix of social engineering against multisig signers, governance manipulation, and a fake asset priced up and posted as collateral. In both cases the contracts did what they were written to do. The failure sat in the operational layer around them, the keys, the signers, the infrastructure, the humans. So, yes, your protocol can pass an in-depth code audit and still lose millions because of a compromised admin key.
Phishing tells the same story in a quieter register. The number of social-engineering attacks fell by more than half, from 132 to 63, and the losses barely moved. Four operations produced $310 million, about 85% of all phishing losses for the half, including a single January strike that took $284,785,689 from one holder. This is not the spray-and-pray scam clogging your inbox. This is target selection, patience, and a surgical hit on someone who holds a large balance. CertiK stopped short of naming the shop, noting only that Drift bore characteristics consistent with DPRK-linked operational patterns. The on-chain investigators were less careful, tying both April heists to the Lazarus cluster. The most disciplined key thieves in the world answer to a state (North Korea).
The pattern is heading somewhere specific, and it is worth getting ahead of. The danger window on a contract no longer closes at launch, because audited code a year old is now a target rather than a safe harbor. And the next privileged keyholder is not a person at all. As AI agents start moving money on their own, each one becomes a new kind of signer whose judgment can be steered by whatever inputs it is fed, in ways a careful human might catch and a poorly guarded machine will not. The banks already block agents from touching customer money for exactly this reason (for now). The industry racing to hand AI agents wallets is building next year's $444 million category in real time.
|
An audit tells you the lock was built right. It says nothing about who is holding the key.
THE FRAUDFATHER
|
| ◆ |
| 01 | The Old Threat Model For years a crypto hack meant a flaw in a contract, the kind of bug an audit exists to catch. Code exploits were the whole story, and a clean audit read like an all-clear. That model is now a year out of date. |
| 02 | The Number That Flatters CertiK counts $1.315 billion stolen across 344 incidents in H1, down 46.8% from a year ago. Almost all of 2025's higher total was one event, the $1.45 billion Bybit theft. Strip it out and 2026 runs about 28% hotter, on more incidents, not fewer. |
| 03 | The Cost Moved to Custody Wallet compromise became the costliest category at more than $444 million, averaging above $13 million per event. Code bugs were still the most common at 204 incidents, but cost only $151.6 million between them. The frequent attacks stay cheap while the expensive ones go straight for the keys. |
| 04 | The Surgical Turn Phishing attacks fell by more than half, from 132 to 63, while losses held. Four operations produced $310 million, roughly 85% of the phishing total, including one January strike that took $284,785,689 from a single holder. CertiK flagged DPRK-consistent patterns on Drift, and investigators tied both April heists to Lazarus. |
| 05 | The Next Keyholder The danger window no longer closes at launch, since audited code more than a year old is now getting hit. And the newest privileged keyholder is not human. As AI agents begin moving money on their own, each becomes a signer whose judgment can be steered by its inputs, which is precisely why banks still keep them away from customer funds. |
The first way to trade directly inside Claude and ChatGPT
For decades, the most powerful intelligence lived behind the closed doors of quant firms — billion-dollar funds whose algorithms quietly out-traded everyone else.
That era just ended.
Co-Invest by Liquid is the first way to trade directly inside Claude and ChatGPT. Ask your AI to analyze a market, stress-test an idea, or build a position sized to your comfort level, then execute, right there in the conversation. No jargon. No twelve-screen terminal. No guesswork.
It's built for people who want to invest smarter, not gamble harder. You set the risk tolerance. The AI does the heavy lifting. You approve every trade.
The institutions made the game, Co-Invest gives you a way to beat them.
|
◆ THE LEDGER NOTE
For a year the industry sold the audit as the finish line. Get the code reviewed, publish the checkmark, and the money is safe behind math that does not lie. The first half of 2026 is the receipt on that promise. $1.315 billion gone, and the biggest holes were not in the code at all. They were in the people and the keys standing behind it. The audit secures the vault. It says nothing about who walks in holding the key. Every system eventually trusts a human, and the human is the one part nobody remembers to audit. So do the unglamorous work. Revoke the approvals you forgot you granted. Treat a contract that passed its audit two years ago as live terrain, not settled ground. Ask who holds the keys to anything you touch, how many of them there are, and what happens the day one of them gets phished. And before you let an agent hold a wallet, decide whether you would hand that same key to a stranger who never sleeps and never doubts. The lock was never the weak point. YOU ARE. |
|
|||||||||||||||
Bitcoin spent the week doing very little, and that is the point. It chopped in a tight band under $64,000 while renewed US-Iran headlines and fresh inflation fears pulled risk assets lower, and it still has not lost $62,000. The spot ETFs turned net positive again, with iShares alone taking in $86.8 million on Friday, thin demand but demand. The CLARITY market-structure bill is still stalled in the Senate, odds down near 43% with no floor vote scheduled, so treat it as an unresolved tailwind, not a catalyst you can time. Keep accumulating in tranches. The trade confirms on a daily close above $66,000 and breaks on a daily close below $62,000.
|
We said a daily close over $1,800 earns the upgrade and not a minute before. ETH closed over $1,800 this week, so the desk does what it said it would do. This is the smallest upgrade we can make, and it comes on a short leash. Most stablecoin settlement, USD1 and USDC alike, rides chains Ethereum anchors, so any clean market-structure outcome is a quiet tailwind underneath it. Accumulate in small size while it holds $1,800. Lose that level on a daily close and it goes straight back to hodl, no argument.
|
The $66 line we defended for three weeks broke, and we stood down on the close exactly as written, no hoping and no averaging down. Down 10% on the week, with $59 the level it is now trying to hold. There is no trade here until it proves something. A daily close back above $64 puts it on the radar again. Until then this is a chart to watch, not a position to hold, and the discipline that kept us out of the drop is the entire reason the rule exists.
|
|
◆ SIGNAL WATCH
The next nine-figure theft will more likely look like Kelp DAO and Drift than like a smart-contract bug. CertiK's own numbers carry the call: wallet compromise now averages more than $13 million per event and rising, while code exploits stay frequent and cheap. Watch two tells into the fall. The first major loss that names a compromised automation or AI agent key as the entry point, and any repeat hit on a protocol whose last audit is more than a year stale. The classic code exploit has become the background noise; the compromise of keys and infrastructure is the signal underneath it, and that is the trail worth tracing wallet by wallet.
MONITORING WINDOW: 90 DAYS
|
|
◆ CHAIN OF CUSTODY
The lesson in six words: The lock held. The key walked. |
|
◆ SPREAD THE SIGNAL
The Person You Know With the Biggest Bag Is Guarding the Wrong Door.Someone in your circle still believes a security audit means their money is safe. It does not. The costliest attacks this year skipped the code entirely and went for keys, signers, and the human holding them, and the biggest single victim lost $284 million in one hit. Forward this to the person whose balance would make them a target, while the lesson is still cheaper than the tuition. SHARE THE KILLCHAINTHE AUDIT SECURED THE LOCK.
MAKE SURE YOUR PEOPLE COUNT THE KEYS. |

Not financial advice. The KillChain is research and commentary, not personalized investment guidance. You're in command of every position. Read accordingly.
|
SOURCES
CertiK, Hack3D H1 2026 Security Report. ·
Forbes, "Fewer But Far More Surgical," Crypto Hacks Hit $1.3 Billion in 2026, July 17, 2026. ·
CCN, Biggest DeFi Hacks and Exploits of 2026. ·
The Motley Fool / Yahoo Finance, Crypto Market Today, July 13, 2026. ·
crypto.news, CLARITY Act Senate showdown, July 2026. ·
Alternative.me Crypto Fear & Greed Index. ·
CoinGecko spot prices. ·
U.S. Treasury, total public debt outstanding, July 16, 2026.
|


