< Go Back

April 2026 was DeFi's worst month ever. We did this to ourselves.

$635M lost in 30 days. SVRN COO David Schwed on the security culture failures behind April 2026's record-breaking DeFi exploit wave.

Blog

28 exploits. 30 days. $635 million gone. This is a bill coming due for years of treating security as an afterthought.

April 2026 is over. And I want to be direct about what just happened, because I'm watching a lot of smart people in this industry reach for comfortable explanations that let everyone off the hook.

The AI narrative. The North Korea narrative. The "crypto is under attack by sophisticated nation-state actors" narrative. These aren't wrong, exactly, but they're incomplete in a way that's dangerous. They frame this as something being done to us. The harder truth is that most of what happened in April was done by us, to ourselves, through years of compounded decisions to treat security as a problem for later.

Let's start with the ledger.

Figure 01—DeFi exploits, April 2026Source: SVRN Research · Verified 04/30
$635MTotal lost in April 2026
28Exploits in 30 days
~1/dayAverage incident cadence
DateProtocolLoss (USD)
01Apr 1Drift$285,000,000
02Apr 3Silo v2$392,000
03Apr 4TMM$1,670,000
04Apr 5Denaria Finance$165,000
05Apr 9Aethir$423,000
06Apr 12HyperBridge$2,500,000
07Apr 12SubQuery$60,000
08Apr 13Dango$410,000
09Apr 13Mona$61,000
10Apr 14Zerion$100,000
11Apr 16Rhea Finance$18,400,000
12Apr 16Grinex$15,000,000
13Apr 18Kelp DAO$293,000,000
14Apr 20Juicebox v3$52,000
15Apr 20Thetanuts Finance$50,000
16Apr 21Volo Protocol$3,500,000
17Apr 22Kipseli$80,000
18Apr 23Giddy Finance$1,300,000
19Apr 25Purrlend$1,500,000
20Apr 26Scallop$150,000
21Apr 27Singularity Finance$413,000
22Apr 27ZetaChain$300,000
23Apr 28JuDAO$228,000
24Apr 28Quant$138,000
25Apr 29Aftermath Perps$1,140,000
26Apr 29Sweat Foundation$3,500,000
27Apr 29Syndicate$330,000
28Apr 30Wasabi Protocol$5,000,000+
Bars normalised to $293M (Kelp DAO).Major (≥ $10M)Standard

Two incidents—Drift ($285M) and Kelp DAO ($293M)—account for nearly 90% of those losses. The other 26 incidents, smaller in dollar terms, are the ones that should actually worry you the most. Because those are the protocols nobody expected to be in the same sentence as "exploit." The frequency tells the real story.

DeFi's April 2026 exploits: the real attack vectors

I've had journalists ask me all month whether AI is driving this surge. Whether this is a uniquely sophisticated campaign. Whether DeFi is structurally impossible to secure. My answer to all three is the same: no. What's happening is simpler and more uncomfortable than that. "You build something incredibly insecure. Attackers find it faster now. That's the story."

Drift was a social engineering attack. Hackers spent months cultivating relationships with team members: meeting them in person at conferences, posing as legitimate trading partners. They then tricked multisig signers into approving transactions they didn't understand. The privileged key got compromised, and the protocol was drained in minutes. The code wasn't the problem. The people and process around the code were the problem.

Kelp DAO exploited a single-verifier configuration in its cross-chain messaging architecture. One checker. Not a zero-day. Not some novel cryptographic break. A configuration choice that created a single point of failure, and attackers fed bad data into that point until the system approved transactions that never actually occurred. A signed lie is still a lie. Signatures verify authorship. They say nothing about truth.

And Wasabi Protocol—the last major incident of the month, April 30th—had its deployer admin key compromised with no timelock, no multisig protection on the key itself. The attacker granted themselves admin privileges and drained multiple vault pools across two chains. A playbook we've seen again and again.

None of these were unimaginable attack vectors. All of them were preventable in a mature security program.

AI didn't cause the DeFi hacking surge. Poor architecture did.

There's a narrative circulating that hackers now have AI-powered tools capable of finding obscure vulnerabilities that even experienced auditors miss, and that this is the root cause of DeFi's current crisis.

I'm skeptical, and I want to explain why.

Yes, AI tooling helps attackers move faster. Yes, it lowers the floor for what a moderately skilled attacker can accomplish. But look at the actual entry points from April. Compromised privileged keys. Single verifiers. Social engineering. Misconfigured access controls. These are not minute, obscure vulnerabilities that require superhuman pattern recognition to find. These are the things a competent security review would flag in week one.

AI doesn't find bad architecture faster. It helps attackers enumerate known weaknesses more efficiently. There's a difference. And if your architecture is fundamentally sound (if you've got multisig with timelocks, if you've got multiple independent verifiers, if you've got people who understand what they're signing, etc.), AI gives attackers relatively little to work with. The protocols that got hit in April weren't victims of some new technological arms race. They were victims of corners being cut. That's the honest diagnosis.

Why DeFi protocols keep getting hacked: a security budget problem

I understand why corners get cut. I'm not naive about the pressures early-stage crypto projects face. Investors want traction and clear growth metrics. Security is expensive. A real CISO, a team underneath them, proper tooling: that's meaningful budget that reduces runway. So teams make the call: get to market first, harden later. The other thing that happens is that "later" never comes. Once you have users and liquidity, the pressure to ship doesn't decrease, it accelerates. And the security debt compounds. You end up with a multibillion-dollar protocol whose security posture was designed for a $10M protocol, because that's when the decisions were made.

I've seen it across the DeFi industry. Projects that hold hundreds of millions in user funds, run by teams of five people, with no dedicated security function. They'll bring in someone whose LinkedIn shows them as an individual contributor engineer six months prior. They have no experience running a security program, no framework for threat modeling at scale, no leverage to push back on engineering decisions from a security standpoint. You cannot build a mature security posture without the people who know how to build one. As I explained to Decrypt earlier in April, "The protocol is decentralized. But the governance of it is centralized against five people." That centralization is where attackers go, every time. The code is often fine. It's the humans that are the attack surface.

Lazarus Group and DeFi: why nation-state hackers keep winning

Lazarus Group's involvement in Drift and Kelp is well-documented by on-chain analysts. I've been asked whether this changes the calculus, whether a nation-state adversary makes adequate defense impossible for DeFi protocols. It doesn't, and here's why: Lazarus isn't using capabilities that exceed what a well-defended organization can handle. They're patient. They're disciplined. They're persistent. The entry points Lazarus exploited in April were social engineering, misconfigured architecture, and compromised keys. These are exactly what a mature security program is designed to prevent.

What makes North Korea effective against crypto isn't sophistication beyond what defenders can counter. It's that they're operating against targets that aren't trying very hard to defend themselves. Irreversible transactions, minimal governance, and an industry that treats security as a "we'll get to it once we have traction" problem. A nation-state with nothing to lose will exploit that gap again and again, until the gap closes. Sadly, the gap hasn't closed. For more on the playbook, see why North Korea keeps stealing billions in crypto.

5 DeFi security fixes that would have prevented April's $635M in losses

First: privileged key management needs to be treated as the most critical security control in the protocol. Multisig is table stakes. Timelocks on critical operations are table stakes. A compromised single key should not be capable of draining a protocol in minutes. If yours can be, fix it today. Not during the next sprint. (See: how crypto can avoid private key compromises.)

Second: the humans who hold signing authority need to understand what they're signing. This sounds obvious, but it is clearly not being done. "Sign this transaction" is not an adequate explanation of what a transaction does. Every signer needs education on what they're approving, and there need to be checks that make bulk approval of misunderstood transactions structurally difficult.

Third: for cross-chain and restaking infrastructure—the plumbing layer—single points of verification need to be treated as single points of failure. Because that's what they are. Multiple independent verifiers is the architectural minimum for anything holding real user value.

Fourth: security needs to be in the room when architecture decisions are made, not called in afterward to audit the result. A security review that finds a critical flaw after a system is already in production means your users were the beta testers for your threat model.

Fifth, and arguably the hardest: investors and founders need to reframe how they think about security spending. Security is a core operating cost, as fundamental as engineering or infrastructure. If you're running a financial protocol, budget accordingly.

The DeFi security crisis isn't over

April is closed, and the losses are permanent. For most of the affected protocols, there is no recovery mechanism, and that same property is what makes the system an attractive target. I don't think May will be dramatically better unless the industry takes the structural lessons seriously rather than waiting for the news cycle to move on. The attack cadence this month was not a spike but a signal: attackers are organized, they're learning, and they're sharing methodologies, while the ecosystem continues to treat security as an individual protocol problem rather than a collective infrastructure challenge. That gap between attacker coordination and defender coordination is where the next $635 million is going to come from.

The tools and knowledge to close this gap have existed for years. The industry just keeps choosing not to use them until after the disaster forces the issue.

■ overview

□ reading time

10min

May 1, 2026

$635M lost in 30 days. SVRN COO David Schwed on the security culture failures behind April 2026's record-breaking DeFi exploit wave.

Crypto Voices logo

key points

  • April 2026 set a record for DeFi losses: $635M across 28 exploits in 30 days, with two incidents (Drift and Kelp DAO) accounting for nearly 90% of the total—but the entry points were not novel.
  • The dominant attack vectors were compromised privileged keys, single-verifier configurations, and social engineering—preventable failures of architecture and process, not AI-powered zero-days.
  • The fix is the security basics done seriously: multisig with timelocks, multiple independent verifiers, signer education, security at the architecture-decision table, and security treated as a core operating cost—not deferred until after the disaster.