Step Finance, Truebit and Resolv account for almost 60% of the total losses for the period. Gemini has said Only two protocols achieved partial recoveries of USD 9 million. Exploits to decentralized finance (DeFi) protocols have accumulated losses of approximately USD 137.7 million so far in 2026, according to a report published this March 22 by Cipher Research, an on-chain research and analysis platform. The stolen figure comes from a total of 15 registered attacks and, according to the firm, only USD 9 million could be recoveredless than 7% of the stolen amount. The attacks were distributed across multiple networks: Ethereum accounts for the largest number of incidents, but the report also includes protocols on Solana, BNB Chain, Base, Arbitrum, Stellar and multi-chain architectures. This dispersion indicates that risk exposure is not exclusive to an ecosystem, but transversal to the DeFi sector.

Step Finance, from Solana, tops the ranking with USD 27.3 million stolen via a compromised private key, with no recorded recovery. This case, along with the hacks of sites like Resolv and Truebit, accounts for about 57% of the total losses for the period indicated by Cipher.
This is how some exploits occurred so far in 2026
Resolv, a stablecoin platform on Ethereum, accumulated losses of more than USD 25 million in the most recent incident in the report, which occurred on March 22. The attack on Resolv leveraged a private key with admin permissions on the USR stablecoin minting contract. With access to that key, the attacker issued 80 million USR without real backing (the contract had no upper mintage limit) and exchanged them for real assets on decentralized exchanges. The losses exceed 25 million dollars and USR lost 74% of its parity with the dollar. Truebit, a computational verification protocol on Ethereum, lost $26.2 million, also without recovery. On January 8, attackers exploited a flaw in a five-year-old smart contract at Truebit. As BitcoinDynamic explained, the function that calculated the purchase price of its native TRU token had a logical error that allowed billions of tokens to be minted at almost zero cost and exchange them for real ETH. The protocol lost $26 million and the TRU token crashed 99.9%. The Moonwell platform, for its part, lost $1.7 million on February 15 after registering the price of the cbETH asset at $1.12 when its real value exceeded $2,200. The error was in a contract whose code was generated with artificial intelligence assistance and passed all human reviews without being detected. For several specialists, it is the first documented exploit linked directly to code generated by AI.
The data of 2025: billions of dollars hacked
The context of the Cipher Research report is not isolated. According to a report by the on-chain analysis firm PeckShield published in January 2026, the year 2025 closed with total losses due to theft and scams with crypto assets exceeding $4.04 billion, an increase of 34% compared to 2024. The most serious episode was the hack of the Bybit exchange in February, with more than $1.5 billion stolen in a single attack, the largest in the history of the sector to date. The figure recorded by Cipher Research today represents close to 4% of the total losses recorded in 2026. An alarming fact revealed by the analysis firm is the recovery rate, which represented only the 6.5% of the total stolen. This figure shows the need to strengthen security systems, carry out more rigorous smart contract audits and optimize the tracking of stolen funds.