This website uses cookies

Read our Privacy policy and Terms of use for more information.

Sponsored by

THE KILLCHAIN  //  No. 060  //  U.S. DEBT $39.52T  //  07.18.2026
 
The KillChain
Criminals build the trap. Institutions hold the key. We name both.
 
THREATS  ·  FLOWS  ·  POSITIONS

CertiK's half-year scoreboard says the attack surface moved from the contract to the custodian, and retail is still guarding the wrong door.

GM, WELCOME BACK TO THE KILLCHAIN.
The Audit Passed. The Money Left Anyway.
CertiK's half-year scoreboard says the attack surface moved from the contract to the custodian, and retail is still guarding the wrong door.

CertiK's Hack3D report for the first half of 2026 landed this week carrying a number that looks like good news; but looks can be deceiving. $1.315 billion stolen across 344 on-chain incidents, down 46.8% from a year ago. Strip out the single event that inflated 2025, the $1.45 billion Bybit theft, and last year's comparable figure falls to about $1.03 billion. That puts 2026 roughly 28% higher, on more incidents, in a market trading lower. On paper it looks like an ecosystem getting safer. The detail underneath refuses to cooperate.

The seam has moved, and it is worth naming exactly where. For years the crypto hack meant a bug in a contract, a clever exploit of code that an audit should have caught. That is not where the money went this year. Nearly 44% of every dollar lost in six months came from two April heists, Kelp DAO and Drift Protocol, and neither one touched a line of audited code. The attackers stopped breaking the software and started breaking the people and the keys behind it.

THE STORY

Wallet compromise was the single costliest category of the half at more than $444 million, averaging over $13 million per event, the highest of any attack type CertiK tracks. Code exploits were still the most common by an extraordinary margin, 204 separate incidents, but they cost only $151.6 million combined, and a growing share of them hit contracts more than a year old that were audited once and never revisited. The math is blunt: the cheap, frequent attacks go after software, and the expensive, rare ones go after custody.

The two heists that defined the half show the method. Kelp DAO lost $291.3 million when attackers compromised the RPC infrastructure feeding its cross-chain bridge and pushed forged withdrawal messages through a single verifier that trusted them. Drift lost $285.3 million to a mix of social engineering against multisig signers, governance manipulation, and a fake asset priced up and posted as collateral. In both cases the contracts did what they were written to do. The failure sat in the operational layer around them, the keys, the signers, the infrastructure, the humans. So, yes, your protocol can pass an in-depth code audit and still lose millions because of a compromised admin key.

Phishing tells the same story in a quieter register. The number of social-engineering attacks fell by more than half, from 132 to 63, and the losses barely moved. Four operations produced $310 million, about 85% of all phishing losses for the half, including a single January strike that took $284,785,689 from one holder. This is not the spray-and-pray scam clogging your inbox. This is target selection, patience, and a surgical hit on someone who holds a large balance. CertiK stopped short of naming the shop, noting only that Drift bore characteristics consistent with DPRK-linked operational patterns. The on-chain investigators were less careful, tying both April heists to the Lazarus cluster. The most disciplined key thieves in the world answer to a state (North Korea).

The pattern is heading somewhere specific, and it is worth getting ahead of. The danger window on a contract no longer closes at launch, because audited code a year old is now a target rather than a safe harbor. And the next privileged keyholder is not a person at all. As AI agents start moving money on their own, each one becomes a new kind of signer whose judgment can be steered by whatever inputs it is fed, in ways a careful human might catch and a poorly guarded machine will not. The banks already block agents from touching customer money for exactly this reason (for now). The industry racing to hand AI agents wallets is building next year's $444 million category in real time.

An audit tells you the lock was built right. It says nothing about who is holding the key.
THE FRAUDFATHER
   
◆ CHAIN REACTION
How the crypto hack stopped being a code problem and became a key problem, in five moves.
01 The Old Threat Model For years a crypto hack meant a flaw in a contract, the kind of bug an audit exists to catch. Code exploits were the whole story, and a clean audit read like an all-clear. That model is now a year out of date.
02 The Number That Flatters CertiK counts $1.315 billion stolen across 344 incidents in H1, down 46.8% from a year ago. Almost all of 2025's higher total was one event, the $1.45 billion Bybit theft. Strip it out and 2026 runs about 28% hotter, on more incidents, not fewer.
03 The Cost Moved to Custody Wallet compromise became the costliest category at more than $444 million, averaging above $13 million per event. Code bugs were still the most common at 204 incidents, but cost only $151.6 million between them. The frequent attacks stay cheap while the expensive ones go straight for the keys.
04 The Surgical Turn Phishing attacks fell by more than half, from 132 to 63, while losses held. Four operations produced $310 million, roughly 85% of the phishing total, including one January strike that took $284,785,689 from a single holder. CertiK flagged DPRK-consistent patterns on Drift, and investigators tied both April heists to Lazarus.
05 The Next Keyholder The danger window no longer closes at launch, since audited code more than a year old is now getting hit. And the newest privileged keyholder is not human. As AI agents begin moving money on their own, each becomes a signer whose judgment can be steered by its inputs, which is precisely why banks still keep them away from customer funds.

The first way to trade directly inside Claude and ChatGPT

For decades, the most powerful intelligence lived behind the closed doors of quant firms — billion-dollar funds whose algorithms quietly out-traded everyone else.

That era just ended.

Co-Invest by Liquid is the first way to trade directly inside Claude and ChatGPT. Ask your AI to analyze a market, stress-test an idea, or build a position sized to your comfort level, then execute, right there in the conversation. No jargon. No twelve-screen terminal. No guesswork.

It's built for people who want to invest smarter, not gamble harder. You set the risk tolerance. The AI does the heavy lifting. You approve every trade.

The institutions made the game, Co-Invest gives you a way to beat them.

◆ THE LEDGER NOTE

For a year the industry sold the audit as the finish line. Get the code reviewed, publish the checkmark, and the money is safe behind math that does not lie. The first half of 2026 is the receipt on that promise. $1.315 billion gone, and the biggest holes were not in the code at all. They were in the people and the keys standing behind it.

The audit secures the vault. It says nothing about who walks in holding the key.

Every system eventually trusts a human, and the human is the one part nobody remembers to audit.

So do the unglamorous work. Revoke the approvals you forgot you granted. Treat a contract that passed its audit two years ago as live terrain, not settled ground. Ask who holds the keys to anything you touch, how many of them there are, and what happens the day one of them gets phished. And before you let an agent hold a wallet, decide whether you would hand that same key to a stranger who never sleeps and never doubts. The lock was never the weak point. YOU ARE.

 
BLOCK HEAT 27 / 100
  27 ▲  
     
FEAR NEUTRAL GREED
+1 PT  ·  7-DAY CHANGE FROM 26 (FEAR)
27. Up a single point on the week and still parked in fear, barely off the extreme-fear line it has hugged for a month. The tape spent the week under pressure as renewed US-Iran headlines lifted oil and revived inflation worry, the kind of macro that pulls risk assets down first. Bitcoin holding $62,000 to $64,000 through that, plus a $1.3 billion hack report and a stalled CLARITY bill, is the tell worth watching. Fear that stops falling on bad news is usually fear that is close to spent. Watch $62,000 as the floor and $66,000 as the line that says the bounce has legs.
◆ THE POSITION DESK
One green, two red against the No. 059 prints. ETH did the one thing we asked and closed above $1,800, so it earns the upgrade. BTC chopped sideways and still holds its floor. HYPE lost the $66 line on the close and we stood down, exactly as the rule has read three weeks running. The desk lets the level, not the Frauddfather's feelings, make the call.
BTC $63,907 −0.3%
 

Bitcoin spent the week doing very little, and that is the point. It chopped in a tight band under $64,000 while renewed US-Iran headlines and fresh inflation fears pulled risk assets lower, and it still has not lost $62,000. The spot ETFs turned net positive again, with iShares alone taking in $86.8 million on Friday, thin demand but demand. The CLARITY market-structure bill is still stalled in the Senate, odds down near 43% with no floor vote scheduled, so treat it as an unresolved tailwind, not a catalyst you can time. Keep accumulating in tranches. The trade confirms on a daily close above $66,000 and breaks on a daily close below $62,000.

ACCUMULATE TRIGGER: DAILY CLOSE ABOVE $66,000
ETH $1,841 +2.6%
 

We said a daily close over $1,800 earns the upgrade and not a minute before. ETH closed over $1,800 this week, so the desk does what it said it would do. This is the smallest upgrade we can make, and it comes on a short leash. Most stablecoin settlement, USD1 and USDC alike, rides chains Ethereum anchors, so any clean market-structure outcome is a quiet tailwind underneath it. Accumulate in small size while it holds $1,800. Lose that level on a daily close and it goes straight back to hodl, no argument.

ACCUMULATE TRIGGER: HOLD $1,800 ON CLOSES
HYPE $59.68 −10.3%
 

The $66 line we defended for three weeks broke, and we stood down on the close exactly as written, no hoping and no averaging down. Down 10% on the week, with $59 the level it is now trying to hold. There is no trade here until it proves something. A daily close back above $64 puts it on the radar again. Until then this is a chart to watch, not a position to hold, and the discipline that kept us out of the drop is the entire reason the rule exists.

WATCH TRIGGER: RECLAIM $64 OR STAND ASIDE
◆ SIGNAL WATCH
The next nine-figure theft will more likely look like Kelp DAO and Drift than like a smart-contract bug. CertiK's own numbers carry the call: wallet compromise now averages more than $13 million per event and rising, while code exploits stay frequent and cheap. Watch two tells into the fall. The first major loss that names a compromised automation or AI agent key as the entry point, and any repeat hit on a protocol whose last audit is more than a year stale. The classic code exploit has become the background noise; the compromise of keys and infrastructure is the signal underneath it, and that is the trail worth tracing wallet by wallet.
MONITORING WINDOW: 90 DAYS
◆ CHAIN OF CUSTODY

The lesson in six words: The lock held. The key walked.

They sold you the audit as the finish line, the green checkmark that means the code is safe and so is your money. Six months of receipts say that checkmark was never the thing protecting you. $1.315 billion left this year, and nearly half of it walked out through two heists that never touched audited code. The costliest attacks now go after wallets, signers, and infrastructure, because that is where the money actually sits and that is the part no audit signs off on. Kelp DAO and Drift did not lose to bad code. They lost to compromised keys and manipulated humans, and the on-chain trail on both roads runs toward the same state that has turned key theft into a national industry. The audit was real. It secured the lock. Then the money left through the door, because someone else was holding the key and nobody thought to ask who. Stop admiring the lock. Start auditing the keys.

◆ SPREAD THE SIGNAL

The Person You Know With the Biggest Bag Is Guarding the Wrong Door.

Someone in your circle still believes a security audit means their money is safe. It does not. The costliest attacks this year skipped the code entirely and went for keys, signers, and the human holding them, and the biggest single victim lost $284 million in one hit. Forward this to the person whose balance would make them a target, while the lesson is still cheaper than the tuition.

SHARE THE KILLCHAIN
THE AUDIT SECURED THE LOCK.
MAKE SURE YOUR PEOPLE COUNT THE KEYS.

Not financial advice. The KillChain is research and commentary, not personalized investment guidance. You're in command of every position. Read accordingly.

SOURCES
CertiK, Hack3D H1 2026 Security Report.  ·  Forbes, "Fewer But Far More Surgical," Crypto Hacks Hit $1.3 Billion in 2026, July 17, 2026.  ·  CCN, Biggest DeFi Hacks and Exploits of 2026.  ·  The Motley Fool / Yahoo Finance, Crypto Market Today, July 13, 2026.  ·  crypto.news, CLARITY Act Senate showdown, July 2026.  ·  Alternative.me Crypto Fear & Greed Index.  ·  CoinGecko spot prices.  ·  U.S. Treasury, total public debt outstanding, July 16, 2026.

The KillChain