Cybercriminals who target crypto are not operating on a fixed schedule. They move when the money moves.
“Vulnerabilities can be exploited in any market environment,” Percoco said, warning that security in crypto has to be treated as an ongoing effort, not a seasonal one.

Still, the losses in early 2026 were far from small. The biggest hit came in January, when portfolio management platform Step Finance lost $40 million after attackers compromised its private keys.
Days later, on Jan. 8, decentralized protocol Truebit was drained of $26.4 million worth of ether through a smart contract manipulation. A third major incident struck stablecoin issuer Resolv Labs in late March, also through a private key compromise — the same method used in the Step Finance attack.
North Korea-Linked Groups Remain A Persistent ConcernData shows that 34 separate DeFi protocols were hit across the quarter. The attacks were spread across the period, with January bearing the heaviest losses.
Percoco described the threat pool as a mix of highly coordinated groups, organized criminal networks, and opportunistic individuals scanning for weak points in smart contracts and user-facing systems.
North Korea-linked actors have been flagged repeatedly in connection with major crypto thefts. Suspected affiliates of that network were linked to an attack on decentralized exchange Drift Protocol, which lost an estimated $285 million to a private key leak.
Featured image from Unsplash, chart from TradingView



















