Buy now

The largest crypto hacks of 2026 have taken more than 1.2 billion USD across 276 separate incidents, according to TRM Labs. That total gets quoted a lot. What rarely gets quoted alongside it is the more useful question for anyone deciding how to hold their coins: at the moment each theft happened, who was holding the keys?

Sorted that way, the year tells a clearer story than the headline number does.

The three that defined the year

Liquid Network, 320 million USD, September. Roughly 4,000 of the 4,200 BTC held in a wallet used by Bitcoin's Liquid sidechain moved out on 6 September 2026. Blockstream attributed it to a software bug in Elements rather than stolen keys, and CoinDesk reported that the attackers described themselves as white hats and offered terms. Most of it came back: Gizmodo covered the return of 3,400 BTC, leaving about 47 million USD outstanding. The coins were held by a federation of functionaries on behalf of users.

Coldcard, 116 million USD, July and August. A build configuration error in firmware 4.0.1 from March 2021 pushed some devices onto a weak software random number generator instead of the hardware entropy source, cutting effective key strength from 128 bits to as little as 40. Beginning 30 July 2026, attackers drained about 1,816 BTC from more than 5,200 addresses across four waves, the first taking roughly 594 BTC in 25 minutes. These owners held their own keys, on dedicated offline hardware, and lost anyway.

The long tail. The remaining 274 incidents cover exchange breaches, bridge exploits, approval phishing, and drainer campaigns. Individually most are small. Together they are the bulk of the 1.2 billion USD, and they fall overwhelmingly on coins held by a third party or exposed through a signature someone was tricked into giving.

What the sorting reveals

Two patterns come out of the year, and they point in different directions.

The first is that custody concentration produces the biggest single numbers. Liquid's 320 million USD moved in one transaction because one arrangement controlled it. Exchange and bridge failures work the same way: an attacker who solves one problem reaches everyone's coins at once, which is why the largest figures of any year cluster around pooled funds.

The second pattern is the uncomfortable one for our side of the argument. Coldcard shows that self-custody is not a place where bad outcomes stop happening. It relocates the risk onto a device and a backup procedure, and when the device has a defect its owners cannot inspect, the relocation offers no protection at all. We'd rather say that plainly than pretend the year went differently.

What separates the two categories is not how likely failure is. It's how failure resolves. A firmware defect is dated, technical, and published, usually within days, and once it's known you can check whether you were exposed and move. When a custodian fails, resolution runs through a bankruptcy court over a period measured in years, and your recovery is decided by documents you never saw. FTX left roughly 8 billion USD of customer funds missing in 2022 and turned account holders into unsecured creditors.

Liquid was the rare case where the money came back, because the attackers chose to return it. That was a courtesy, not a right.

The lesson people took, and the one available

After Coldcard, some holders moved coins onto exchanges, and Binance's reserves climbed to roughly 693,000 BTC by September 2026, a two-year high. That reaction is understandable and it answers the wrong question. It treats the problem as "self-custody is dangerous" when the specific failure was "one device generated weak keys and nobody could see it."

The available lesson is narrower and more useful. Judge a wallet on what you can verify about it: whether the firmware has been independently audited with the report published in full rather than summarized, whether keys are generated inside a certified secure element and stay there, whether the screen shows you what you're signing in readable form, and whether losing one object ends your access.

That last item is where most setups quietly fail, and it has nothing to do with hackers at all.

Where the unglamorous losses happen

Not one coin in the 2026 total was lost the way most people lose crypto. The ordinary path is a house move, a fire, a drawer cleared out by someone who didn't recognise what a card with twelve words was for. Nobody attacks you. No incident report gets written. The money is just gone, and the amount lost this way over Bitcoin's history dwarfs any single year of thefts.

The standard advice runs from paper to a stamped steel plate, and steel is a clear upgrade because it survives water and fire. Your access still depends on one object continuing to exist, which is a thin thread for something that cannot be reissued.

What TapSafe does about the backup problem

We built TapSafe Recovery so that no single item carries your access. The split is 50% on a Recovery Tag, which is NFC and IP69K rated, built to survive water jets, dust, and temperature extremes, and 50% on your paired phone, stored encrypted in your iCloud or Google Drive rather than on the handset, so a lost or stolen phone doesn't take the share with it. Tag and phone together restore the wallet. Optional Recovery Contacts hold 25% each and can see nothing about your holdings, with setup done in person over NFC.

It runs on a custom implementation of Shamir's Secret Sharing, and your seed phrase stays reachable on the device as a last resort on the BIP-39 standard, so leaving our hardware is always an option.

On the part Coldcard got wrong, the Ryder One generates keys inside an EAL6+ certified Infineon SLC38 secure element and they never leave it, with the firmware independently audited by Halborn and the full report public. Every transaction appears on the 1.6-inch AMOLED touchscreen in detail you can read before approving, so what shows on the device is what gets signed.

Reading the 2027 number

When the 2027 totals arrive, the figure to look for is not the headline. Split it by custody: how much came from pooled funds held by somebody else, and how much from individuals holding their own keys. In most years the first category dwarfs the second, and 2026 followed that pattern despite producing the largest hardware wallet exploit on record.

Holding your own keys moves you out of the category that generates nine-figure single-transaction losses. It puts the remaining work on you, which is a fair trade once your backup no longer rests on one object in one drawer.

Ready to make that trade on better terms? Get your Ryder One for 149 USD.


Meta description: The largest crypto hacks of 2026 total 1.2 billion USD across 276 incidents. Sorted by who held the keys, Liquid, Coldcard and the long tail tell one story.

Target keyword: largest crypto hacks 2026

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More