
June 2026: Two Outliers, One Story
- Crypto Security
- Threat Intelligence
- DeFi
- Rug Pulls
- Phishing
- Supply Chain Attacks
- On-Chain Forensics
- Monthly Report
6 views
June 2026 reads, on paper, as crypto's worst month of the year by dollar volume. That reading is misleading too — just in the opposite direction from May's. The total didn't rise because the exploit landscape got worse. It rose because two exceptional events — a whale-controlled rug pull and a DPRK-attributed phishing campaign — landed in the same 30-day window and together outweighed the other 33 incidents combined.
The headline — and why it's misleading
Crypto lost roughly $142.2 million across 35 incidents in June, a 73.4% increase from May's $82M. But strip out SIREN Token's $64.8M whale dump and Humanity Protocol's $36M phishing operation — together 71% of the month's total — and the remaining 33 incidents come to just $41.4M. Lower than May. The core exploit landscape didn't escalate. Two outliers made it look that way.

Incident count actually fell, from 40+ in May to 35 in June. Whatever happened this month, it wasn't a broader wave of attacks. It was concentration risk: a small number of events doing an outsized amount of damage.
Where the money went

This chart tells a very different story from May's. Rug pulls and whale dumps — a single incident, SIREN — account for 45.6% of losses. Key and credential compromise, driven by Humanity Protocol and SecondFi, is 27%. Bridge exploits are 10.5%. Classic smart-contract logic bugs, June's most common failure mode by incident count, are only 9.1% of the dollars. May's story was operational security overtaking code bugs; June's story is that a handful of large, structurally unrelated events can outweigh an entire category of smaller, more numerous incidents.
Six things worth knowing
Two outliers carried the month. SIREN ($64.8M) and Humanity Protocol ($36M) combined exceed the other 33 incidents put together — the most top-heavy loss distribution tracked so far this year.
The frontend is the new perimeter. Four separate incidents — Polymarket, Gitcoin, Yield Yak and IronWorm — compromised the layer outside the smart contract: vendor dependencies, drainer kits, npm packages. Gitcoin and Yield Yak used the identical "Eleven Drainer" kit and shared C2 infrastructure, three days apart.
Deprecated code is still live risk. Five incidents — Aztec Connect, its sibling Aztec Private Rollup Bridge, Thetanuts' legacy vault, Raydium's inactive-since-2021 AMM V3, and Royal's old royalties contract — hit code teams considered dormant. No admin key also means no pause button.
"Protocol absorbs the loss" is becoming standard, not exceptional. Gnosis Pay, Polymarket and Haedal all pledged full treasury-backed reimbursement independent of whether the attacker's funds are ever recovered — three incidents in one month.
Self-detection overtook external monitors. Seven June incidents were first caught by the affected project's own systems, more than any single external security firm.
AI security tooling cut both ways. A researcher used Claude to find a four-year-old Zcash Orchard counterfeiting bug. The same week, an npm supply-chain worm forged git commits under a fake "claude" author identity to hide its own timeline.
The biggest incidents

SIREN Token — $64.8M. A cluster of 146 wallets controlling 92–94% of supply liquidated ~670M tokens in 48 hours, crashing the price 96%. Not a hack — a rug pull. First flagged by Lookonchain.
Humanity Protocol — $36M. Phishing led to a compromised BSC-side ProxyAdmin and an unauthorized H-token mint, plus a parallel Ethereum-side drain. 71,713 tainted addresses documented on the team's own transparency portal. Attributed to the Lazarus Group / DPRK by Quantstamp.
Syscoin Bridge — $8.6M. A malformed SPV proof authorized an unbacked mint of 5B SYS (568% supply inflation). Bridge paused within hours; the attacker accepted a private bounty and returned all funds. The cleanest full recovery of the month.
JaredFromSubway MEV Bot — $7.5M. 66 fake token contracts baited an MEV bot's automated strategy into granting approvals, then swept it via transferFrom. Used an EIP-7702-delegated EOA. Confirmed clean of any protocol bug by Blockaid's CTO.
Axelar-Secret Network — $4.7M. An infinite-mint bug in a modified CW20-ICS20 bridge contract. Contained same-day; attacker identity is structurally unrecoverable on Secret Network's privacy layer.
Polymarket — $2.94M. A compromised third-party frontend dependency targeted PUSD holders. Core contracts unaffected. Full treasury reimbursement pledged.
SecondFi — $2.4M. A deterministic nonce-derivation flaw in proprietary wallet software let attackers reconstruct private keys after any signed transaction. ~129.4M ADA intercepted mid-sweep before reaching the attacker.
Unlike May's Kelp DAO exclusion, both of June's outliers are counted in full — their on-chain events and disclosures both fall inside the June 1–30 window.
The geography of the losses

BNB Chain shows the highest chain-level loss at $66.7M — almost entirely SIREN. The "multi-chain" bucket at $36M is Humanity Protocol alone. Remove both mega-incidents and Ethereum leads at $14.3M across 10 incidents, a mix of deprecated-contract exploits and the JaredFromSubway MEV bot drain. Bridges and cross-chain infrastructure (Syscoin, Axelar-Secret, Taiko) add another $15.0M on top — a distinct, application-layer-independent category of risk.
Three trends that define the month
The frontend is the new perimeter. Four incidents this month never touched contract logic at all — they compromised vendor dependencies, drainer kits, or package registries instead. Auditing your contract is no longer sufficient; the dependency graph and the frontend build pipeline are now part of the attack surface.
Deprecated contracts are not a security state. Five separate June incidents hit code that teams believed was sunset or dormant. Immutability without an upgrade path means there's no recovery mechanism either, once someone finds the bug.
Treasury-backed reimbursement is maturing into policy. Gnosis Pay, Polymarket and Haedal all executed this under pressure, reactively. Protocols that define the policy and funding mechanism in advance will move faster the next time it happens — and there will be a next time.
"Rest assured, Gnosis will cover all user losses." — Martin Köppelmann, Gnosis co-founder, in the hours after the Gnosis Pay exploit was detected, urging users to withdraw EURe and GNO from affected Safes while the team traced the Zodiac module flaw.
Who caught it — and who got their money back

A shift from May: self-detection by the affected project was the single largest category this month — seven incidents were first caught by the protocol's own monitoring rather than an outside firm. Blockaid and independent or community researchers each carry five detection credits; PeckShieldAlert and f12sec three apiece. Seven incidents' first-alert source could not be firmly attributed from public sources — a reminder that detection credit itself is often undocumented for anything below the mega-incident tier.

Recovery stayed bimodal, with a new middle path. 65.7% of June incidents saw zero fund recovery — funds hit Tornado Cash within minutes, or the exploited contract was immutable with no admin authority to even attempt a freeze. But a genuine third category has emerged: treasury-backed reimbursement (Gnosis Pay, Polymarket, Haedal), where the protocol makes users whole regardless of whether the attacker's funds are ever recovered on-chain — distinct from Syscoin's, Thetanuts' and Flooring's direct whitehat-negotiated returns.
What to do about it
If you run a protocol: audit your frontend dependency and vendor surface with the same rigor as your contracts. Four June incidents never touched contract logic at all.
If you maintain legacy or "sunset" contracts: inventory every deprecated deployment that still holds funds. If there's no upgrade authority, there's no recovery path either — patch or migrate the funds out properly.
If you use enclave- or HSM-backed signing: treat key material as production infrastructure. Taiko's SGX signing key was leaked via a public GitHub commit. Secrets scanning on CI/CD is not optional.
If you're building an incident-response plan: define a treasury-backed reimbursement policy before you need it. Three protocols improvised this under pressure this month.
If you're evaluating a token: track holder concentration alongside code audits. SIREN needed no exploit — just enough supply in few enough hands.
If you write low-level or delegate calls: verify the call itself succeeded, not just the returned value. Gnosis Pay's ERC-1271 flaw and Ambient Finance's manipulation both trace back to this same class of gap.
A few caveats
31 of 35 incidents carry a confirmed USD figure; IronWorm, RetoSwap/Haveno, Gitcoin and Yield Yak involve credential theft or drainer campaigns with no publicly quantified loss and are excluded from dollar totals.
Zcash Orchard is a zero-loss vulnerability disclosure — no funds were ever at risk — and is included for its significance to the security landscape, not its dollar impact.
Gnosis Pay's figures reflect the official July 3, 2026 post-mortem, which superseded an earlier June 5 estimate; included here because the incident and its initial disclosure both fall inside the June window.
Namada Shielded Pools was identified through independent manual research, not the standard multi-model pipeline, and is corroborated by an independent DeFiLlama TVL data point.
No incident besides Humanity Protocol carries a high-confidence nation-state attribution at time of writing.
All on-chain claims are independently verifiable on the respective block explorers. This report is informational and not financial, legal, or security advice.
0xposed Lab — Track. Document. Fight Back.