Latest crypto hacks: WEMIX lost $6.25 million after an admin key compromise, Garden Finance was drained for $450,000 through a solver breach, and Drift Protocol’s $285 million exploit, 2026’s largest, was linked to North Korean state hackers behind the Radiant Capital attack. Together, they highlight over $1 billion lost this year to bridge exploits and compromised access controls.
Crypto security news never really slows down. But this stretch has been brutal. A major gaming blockchain lost millions. A cross-chain bridge suffered its second breach in under a year. And investigators just linked one of 2026’s biggest DeFi hacks to a state-sponsored hacking group. Let’s break down the latest crypto hacks: WEMIX, Garden Finance, and Drift Protocol. Here’s what each incident reveals about crypto security right now.
WEMIX: A $6.25 Million Stablecoin Exploit Forces a Network Shutdown
Attackers hit WEMIX again on July 26, 2026. WEMIX is the blockchain gaming ecosystem run by South Korean developer Wemade. The team shut down the entire network in response.
Here’s how it happened. The exploit began at 18:17 KST. An unidentified attacker gained administrator privileges over a smart contract tied to the WEMIX$ stablecoin. Using those privileges, the attacker minted roughly 5.2 million WEMIX$ tokens out of thin air, worth about $5.22 million. The attacker then routed the fresh tokens through a decentralized exchange and swapped them into WEMIX tokens and bridged USDC. Total losses reached around $6.25 million.
WEMIX Foundation responded fast. It suspended all bridges connecting to and from the WEMIX3.0 mainnet, including its Chainlink CCIP integration and the PLAY Bridge. The foundation says it has identified the attacker’s wallets. It’s now working with global exchanges and stablecoin issuers to trace and potentially freeze the stolen funds.
This isn’t WEMIX’s first breach, unfortunately. It’s the platform’s second major security incident in eighteen months. A 2025 bridge exploit drained roughly $6.1 million in WEMIX tokens before this one. Wemade CEO Kim Seok-hwan now faces renewed scrutiny over the team’s security practices.
Garden Finance: A $450,000 HTLC Drain Across Four Blockchains
Security firm Blockaid raised the alarm a day earlier, on July 26, 2026. It flagged an active exploit targeting Garden Finance’s hash time-locked contracts, or HTLCs. Garden uses these time-bound escrow contracts to facilitate atomic swaps between Bitcoin and assets on other networks. They let users trade across chains without a trusted middleman.
The attacker drained roughly $450,000 in USDT. The drain hit four separate blockchains at once: Ethereum, Base, Arbitrum, and BNB Smart Chain. That multi-chain pattern initially led on-chain observers to suspect a contract-level bug in Garden’s core code.
Garden Finance later clarified the real cause. Its protocol and HTLC smart contracts were never compromised. Instead, the breach traced back to one independent solver’s off-chain database. Solvers are the entities that execute swap orders on the platform, and this one operated outside Garden’s core code entirely. The team paused its app as a precaution while it investigated.
Here’s the part that should worry anyone using cross-chain protocols: this is Garden’s second breach in under a year. In late October 2025, an attacker compromised a different Garden solver’s operating environment and stole roughly $11.4 million. The team again said that incident didn’t touch protocol contracts or put user funds at direct risk. Two breaches through the same category of vulnerability points to a systemic weak point, not just bad luck.
Drift Protocol: The Year’s Biggest Hack Gets Attributed to North Korea
WEMIX and Garden made this week’s headlines. But the Drift Protocol exploit still holds the title of 2026’s largest crypto hack. New attribution findings make it worth revisiting in full.
Attackers drained roughly $285-286 million from Drift Protocol on April 1, 2026. Drift is the largest decentralized perpetuals exchange on Solana, and the hack wiped out more than half of its total value locked. According to blockchain intelligence firm TRM Labs, this wasn’t a spontaneous smart contract bug. On-chain staging began nearly three weeks earlier, on March 11. Attacker infrastructure, fake token manufacturing, and social engineering all ran in careful, coordinated parallel.
The mechanics were genuinely sophisticated. The attacker manufactured an entirely fictitious asset and seeded it with a few thousand dollars in wash-traded liquidity. Drift’s price oracles then treated the fake asset as legitimate collateral worth hundreds of millions of dollars. The attacker also socially engineered multisig signers into pre-signing hidden authorizations. A zero-timelock Security Council migration eliminated the protocol’s last line of defense. Once launched, the entire drain took only about 12 minutes.
Blockchain intelligence firm Elliptic and Drift’s own investigation later assessed the attribution with medium-high confidence, supported by the SEAL 911 security response team. The same threat actors behind the October 2024 Radiant Capital hack carried out this attack too. Mandiant had publicly attributed that earlier hack to a North Korean state-affiliated group tracked as UNC4736, AppleJeus, or Citrine Sleet.
The attacker moved fast after the drain. Stolen funds were quickly consolidated into USDC and SOL, then partially bridged to Ethereum using Circle’s Cross-Chain Transfer Protocol. On-chain investigator ZachXBT publicly criticized Circle over this. He pointed out that large amounts of stolen USDC moved across chains during US business hours without a freeze. He called the enforcement inconsistent compared to other incidents.
The Bigger Pattern: 2026 Is a Brutal Year for Crypto Security
These three incidents don’t stand alone. Crypto losses across the sector topped $47 million the same week WEMIX got hit. Attackers also targeted platforms including AFX Trade, Wanchain, and Verus. The Verus Ethereum Bridge alone lost roughly $7.54 million on July 23. That was the second time attackers abused the exact same import path in just over two months, a clear sign some vulnerabilities get patched too slowly.
Zoom out further, and the numbers get worse. Cross-chain bridges have lost more than $1.31 billion across 344 separate incidents in just the first half of 2026. Industry-wide, total losses this year already top $1 billion across bridge exploits, oracle manipulation, and compromised administrative keys. That positions 2026 as one of the worst years on record for DeFi security.
What These Hacks Have in Common
Looking across WEMIX, Garden, and Drift, a few shared themes stand out:
1. Privileged Access Remains the Biggest Attack Surface
WEMIX’s exploit stemmed from compromised administrator privileges. Drift’s attacker socially engineered multisig signers. Neither attack relied on clever code. Both came down to who could access and authorize critical functions, and how well those permissions were protected.
2. Third-Party Infrastructure Is Often the Weakest Link
Garden Finance’s protocol contracts held up fine, twice. The real failure point sat in a third-party solver’s off-chain infrastructure. Even audited smart contracts are only as secure as every dependency built around them.
3. Sophisticated Attackers Are Playing a Long Game
Drift’s attacker spent nearly three weeks staging infrastructure and manufacturing a convincing fake asset before executing a 12-minute drain. This kind of patience is a hallmark of state-sponsored operations, not opportunistic hackers. It also makes these attacks much harder to detect in advance.
4. Fund Recovery Remains Genuinely Difficult
Attackers moved stolen funds fast in all three incidents. They ran the money through decentralized exchanges, cross-chain bridges, and asset swaps within hours, deliberately complicating recovery. Once funds get laundered across multiple chains, the odds of meaningful recovery drop sharply with each passing hour.
What This Means for Everyday Crypto Users
- Understand what “audited” actually covers. Drift had passed audits from reputable firms. But the exploited vulnerabilities involved governance changes and a new asset market that prior reviews never fully covered. An audit reflects a snapshot in time, not an ongoing guarantee.
- Third-party integrations carry real risk. A protocol’s core contracts can be secure and still fail. Dependencies like solvers, oracles, and bridges can introduce vulnerabilities entirely outside a project’s direct control.
- Repeat incidents are a red flag. Both WEMIX and Garden Finance suffered their second major breach within roughly a year. Weigh that pattern carefully before allocating significant funds to a platform with a recent security history.
- Diversify custody and exposure. Avoid concentrating large amounts of funds on any single platform. Cross-chain bridging and gaming-token ecosystems have both been frequent targets in 2026.
Final Thoughts
This latest wave of crypto hacks paints a sobering picture. WEMIX’s stablecoin exploit, Garden Finance’s solver breach, and the now state-attributed Drift Protocol mega-hack all point to the same weak spots: administrative access controls and third-party infrastructure. Add increasingly patient, well-resourced attackers, and you get one of the most damaging years for crypto security on record. The practical takeaway hasn’t changed: diversify exposure, check a platform’s security history, and treat “audited” as a starting point, not a guarantee.
We’ll keep tracking these incidents and any fund recovery efforts as they develop.
Frequently Asked Questions
What happened in the WEMIX hack?
An attacker gained administrator privileges over a WEMIX$ stablecoin contract on July 26, 2026. They minted roughly $5.22 million in tokens out of thin air and swapped them into other assets, bringing total losses to about $6.25 million. WEMIX suspended its entire network in response.
Was Garden Finance’s smart contract hacked?
No. Garden Finance confirmed its HTLC smart contracts stayed secure. The $450,000 drain across four blockchains traced back to a breach of an independent solver’s off-chain database, not a flaw in the protocol’s core code.
Who was behind the Drift Protocol hack?
Blockchain intelligence firms TRM Labs and Elliptic assessed with medium-high confidence that a North Korean state-affiliated hacking group carried out the $285-286 million Drift Protocol exploit. The same group, tracked as UNC4736, AppleJeus, or Citrine Sleet, also hit Radiant Capital in October 2024.
How much has been lost to crypto hacks in 2026?
Crypto hacks have already cost the industry more than $1 billion in 2026 across bridge exploits, oracle manipulation, and compromised administrative keys. Cross-chain bridges alone account for over $1.31 billion across 344 incidents in the first half of the year.
