Crypto theft dipped to $76M in June, with Humanity Protocol's $31M–$36M hack the largest single loss
Blockchain security firm PeckShield tallied about $76 million stolen across 40 crypto incidents in June, a 7% dip from May, led by Humanity Protocol's private-key breach.
A private-key breach at Humanity Protocol drove the month's losses, as blockchain security firm PeckShield tallied 40 incidents totaling roughly $76 million — down about 7% from May.
Crypto thefts came to around $75.9 million across 40 incidents in June, a 7.1% decline from May's $81.7 million, according to blockchain security firm PeckShield's monthly tally, reported by The Block.
The single largest loss was the Humanity Protocol exploit. PeckShield put it at $31 million; onchain analyst Specter first flagged that project-linked wallets had been drained of over $31 million on June 9, and Humanity Protocol's own subsequent investigation put the total closer to $36 million — so the figure sits in a $31M–$36M range depending on whose count you take. Founder Terence Kwok attributed the breach to a compromised private key. PeckShield says the attacker has since laundered funds across Bitcoin, Solana, Hyperliquid, and BNB Chain, and that some proceeds were commingled with funds tied to the separate Kelp DAO exploiter — a pattern PeckShield says raises the possibility, not confirms, that one actor is behind both.
Other notable June incidents, per PeckShield: Syscoin Bridge lost $10 million to a validation flaw that let an attacker mint billions of unbacked SYS without a matching burn; a MEV sandwich-attack bot tied to JaredFromSubway.eth was itself drained of $7.5 million; and Secret Network, Polymarket users, SecondFi and TESSERA lost between $2.4M and $4.67M. Aztec's deprecated, immutable contracts — which the Aztec Foundation says it can no longer control or pause — were hit twice, for a combined ~$4 million.
Key facts
- ~$75.9M stolen across 40 incidents in June, down 7.1% from May's $81.7M — PeckShield, via The Block.
- Humanity Protocol: $31M (PeckShield tally) / ~$36M (project's own investigation); private-key compromise, per founder Terence Kwok. First flagged June 9 by analyst Specter.
- Syscoin Bridge: $10M via a mint-without-burn validation flaw — PeckShield.
- JaredFromSubway.eth MEV bot: $7.5M — PeckShield.
- Aztec Bridge ($2.16M) + Aztec Connect ($2.1M), ~$4M combined on immutable contracts — PeckShield, via The Block.
- 2026 year-to-date losses exceed $750M, driven mostly by two April North Korea-linked attacks: Drift Protocol ($285M, April 1) and Kelp DAO's LayerZero bridge ($292M, April 18) — TRM Labs.
The real-world read The 7% month-on-month "improvement" is noise, not a trend: at ~$76M, June is roughly a tenth of the two April attacks alone, and monthly totals swing on whether one big hack lands. Note the numbers here come from interested-adjacent parties — PeckShield and TRM Labs sell security services, so a busy threat month is also a marketing backdrop; treat the tallies as estimates, not audited figures. The Humanity Protocol discrepancy ($31M vs. the project's own $36M) is worth watching: a hacked project revising its own loss upward is more credible than one revising down. And the recurring theme is unglamorous — private keys, a broken bridge check, unmaintained immutable contracts nobody can pause. These are operational failures, not exotic math.
This is news reporting, not financial advice.
Sources
- The Block (Naga Avan-Nomayo, 2026-07-01) — the reporting and all June figures; relays PeckShield's tally, Specter's onchain flag, Humanity Protocol's own investigation, and TRM Labs' YTD data. The Block discloses Foresight Ventures as majority investor; not sponsored content. PeckShield and TRM Labs are commercial security firms whose data doubles as marketing — figures cited as their estimates.