Last updated: July 2026. This is a living tracker — we update it monthly as new cross-chain bridge exploits are confirmed. Bookmark this page rather than a snapshot of it.
Key Takeaways
- Cross-chain bridges have lost roughly $328.6 million across at least eight major incidents in the first half of 2026 alone.
- The Kelp DAO exploit ($292M, April) accounts for the vast majority of that total and remains the year’s defining bridge hack.
- Most 2026 incidents, large and small, trace back to the same root cause: a forged or under-verified cross-chain message, not a broken smart contract or a stolen validator key in the classic sense.
- Smaller exploits (Verus, CrossCurve, Syscoin) show the pattern isn’t limited to large, high-profile protocols — it’s a structural weak point across the message-passing bridge category as a whole.
- This tracker is updated monthly; see our complete guide to bridge risk in 2026 for the underlying vulnerability categories and how to evaluate any bridge before using it.
Article Summary: The biggest blockchain bridge hacks of 2026 total roughly $328.6 million across at least eight confirmed incidents so far, led by the $292 million Kelp DAO exploit in April, with most losses traced to forged or under-verified cross-chain messages rather than traditional smart contract bugs or stolen keys.
2026 Bridge Hack Ledger
Sorted newest first. Figures reflect amounts reported at the time of each incident and may be revised as investigations continue.
| Date | Bridge / Protocol | Amount | Root Cause |
|---|---|---|---|
| June 2026 | Syscoin Bridge | ~$10M | Proof-parsing flaw allowed a fake burn proof, minting 5B unbacked SYS |
| May 2026 | Verus-Ethereum Bridge | ~$11.6M | Missing amount-validation check on an otherwise valid proof |
| May 2026 | THORChain | ~$10.8M | Compromised component; swaps temporarily halted |
| April 2026 | Kelp DAO | ~$292M | Forged LayerZero message via single-verifier (“1-of-1”) configuration |
| February 2026 | CrossCurve | ~$3M | Spoofed cross-chain message via Axelar-linked receiver contract access-control gap |
Read the full breakdown of the year’s largest incident in our Kelp DAO hack deep-dive, including exactly how the forged-message attack worked and what it means for anyone holding bridged or restaked assets.
What the 2026 Pattern Actually Shows
Four of the five incidents on this list share the same underlying failure mode: a bridge accepted a cross-chain message it shouldn’t have, either because too few independent parties were required to verify it (Kelp DAO, CrossCurve) or because a validation check that should have caught the discrepancy simply wasn’t there (Verus, Syscoin). Only THORChain’s incident falls outside that pattern, tied instead to a compromised component rather than a messaging-layer gap.
This is a meaningful shift from the bridge hacks that dominated headlines in 2022, like Ronin and Wormhole, which were mostly stories about stolen validator keys or a single verification bug in otherwise sound code. 2026’s pattern is more about configuration choices — how many parties a project requires to trust before moving funds — than about code quality alone. For a full explanation of how message forgery compares to smart contract bugs, validator compromise, oracle manipulation, and centralization risk, see our bridge risk 2026 guide.
How to Use This Tracker
This page exists to answer one question quickly: what’s happened recently, and how bad was it? If you’re trying to decide whether to trust a specific bridge, this ledger tells you whether it (or a similar bridge using the same underlying protocol) has been exploited recently. For a deeper explanation of why these exploits keep happening and how to evaluate a bridge’s security before you use it, the pillar guide linked above is the better starting point. Major incidents that warrant a full explainer, the way Kelp DAO did, will get their own dedicated article linked directly from this table.
Bridge Hack Tracker FAQs
What is the biggest blockchain bridge hack of 2026?
The biggest blockchain bridge hack of 2026 so far is the Kelp DAO exploit in April, which resulted in the theft of roughly $292 million through a forged cross-chain message.
How much has been lost to bridge hacks in 2026?
Cross-chain bridges have lost approximately $328.6 million across at least eight major confirmed incidents in the first half of 2026, with the Kelp DAO exploit accounting for the large majority of that total.
How often is this tracker updated?
This tracker is updated monthly with newly confirmed bridge hack incidents. Major exploits that warrant deeper coverage receive their own dedicated article, linked directly from the ledger above.
Bridge Hack Tracker Citations
- CryptoTimes, “Crypto Bridge Hacks Top $328M in 2026 as Cross-Chain Exploits Accelerate” – cryptotimes.io
- Mintlayer, “Anatomy of 2026’s Bridge Exploits” – mintlayer.com
- Halborn, “Explained: The Syscoin Bridge Hack (June 2026)” – halborn.com
- KuCoin, “Top Crypto Hacks of 2026: Bridge Exploits and Sophisticated Operations Drive Over $750 Million in Losses” – kucoin.com
