This Week’s Verdict
Markets spent 2026 pricing the upside: more ETFs, a friendlier SEC, a White House that does not want to tax your coffee-money bitcoin. The other half of the board, where North Korea drains the better part of a billion dollars a year, is not in any chart. This week handed us both at once, plus a rare reminder that the good ending exists. It is just the exception.
The Breaches
June’s largest single loss was Humanity Protocol, over $30 million. The contracts held. The private keys did not: they had been backed up to a developer machine already carrying malware. Quantstamp flags tooling consistent with North Korean crews, the proceeds moved across Bitcoin, Solana, Hyperliquid, and BNB Chain, and researchers see possible overlap with the Kelp attacker. Your custody is only as strong as the laptop your backups touched.
The month around it, per PeckShield: $75.87 million across 40 incidents, down 7.13% from May’s $81.7 million. The rest of the ledger read like every month before it. Syscoin Bridge for roughly $10 million, a JaredFromSubway MEV bot for $7.5 million, Secret Network for $4.67 million. Bridges, contracts, and stolen keys, in that order, forever.
Vulnerabilities Worth Your Attention
- Aptos Move VM, stale-cache type confusion — Researchers at Hexens showed how the bug let an attacker treat one on-chain resource as another and seize protocol permissions. Direct exposure was low single-digit billions; systemic blast radius across bridges, USDC administration, and exchanges was put near $70 billion. Reproduced with a $3,000 server simulating a third of the validator set at roughly 90% success. Reported through the bug bounty on February 25, patched to mainnet within hours, no funds lost. This is what the good ending looks like.
- The evergreen you can fix today — none of the month’s key-theft losses needed a zero-day. Malware-infected developer boxes and live token approvals did the work. Revoke stale allowances, keep backups off connected machines.
Threat Actors & Campaigns
Chainalysis attributes roughly 76% of 2026 hack losses to state-backed actors, most tracing to Lazarus. Two April jobs set the year’s tone. Kelp DAO lost about $290 million through a LayerZero-based bridge. Drift, Solana’s largest perpetual-futures venue, lost about $285 million in twelve minutes, after a six-month, in-person social-engineering campaign bought the crew admin access. Bridges and people keep breaking faster than cryptography does.
The Bigger Picture
The SEC is signaling a “neutral” posture on crypto ETFs, its investment-management leadership publicly conceding it handled them poorly and lost industry trust. Filings are up to roughly 1,800 this year, about 50% more than last. The President has come out against capital-gains tax on bitcoin used as payment. The access story is being priced in aggressively. The security story is not being priced at all. By the time a breach is news, the discount has already arrived. The keys get priced first.
Resources
- Aptos Move VM flaw: CoinDesk
- June totals (PeckShield): Yahoo Finance
- 2026 state-actor attribution: Chainalysis
- Kelp DAO ~$290M: Bloomberg · Drift ~$285M: Forbes
- SEC ETF posture: The Block
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked