Crypto Hacks H1 2026: Record 207 Attacks and Where Dirty USDT Comes From
H1 2026 saw 207 crypto attacks worth $972M (TRM Labs), the largest being Kelp DAO at $292M (Lazarus/TraderTraitor). We explain how stolen funds reach ordinary P2P traders and why even honest people get their USDT frozen.
The most common question put to an AML checker: "I didn't break any law, why was my address blocked?" The answer is in hack statistics. Per TRM Labs, the first half of 2026 saw a record 207 crypto attacks totaling $972 million. Stolen coins and tokens don't vanish — they pass through hundreds of wallets, and sooner or later an honest P2P trader receives "dirty" USDT. Here's how it works.
H1 2026 statistics
The paradox: the number of attacks is rising while losses fall. That means AML systems and exchanges are getting faster at tracking and freezing stolen funds. For P2P traders it's bad news: more addresses end up in AML databases than before, and the chance of receiving "dirty" USDT that an exchange will freeze is higher.
How stolen funds reach an honest trader
The chain from hack to your account freeze looks like this:
- The hacker breaches a protocol (DeFi bridge, exchange, wallet). The hacker's address enters TRM/Chainalysis/OFAC databases (if linked to Lazarus or a sanctioned group).
- Splitting and mixing. The hacker runs funds through Tornado Cash or a chain of intermediate wallets to obscure the trail.
- Exit via P2P. At some point the hacker (or a later holder) sells USDT via P2P — and the buyer is you.
- The exchange flags your address. When you deposit USDT to an exchange, its compliance traces history — if it sees a link to the hack address, your account is frozen.
You didn't know, you weren't involved — and the exchange doesn't care. AML compliance runs on "address with history = risk." Proving legitimacy is on you, and the process can take months.
Largest hacks of H1 2026
Kelp DAO — $292M (April 2026)
The largest DeFi hack of 2026. A vulnerability in the LayerZero bridge let an attacker drain about $292M from Kelp DAO. The attack was attributed to the North Korean group TraderTraitor (a Lazarus sub-unit, per the FBI). The hacker addresses entered the OFAC SDN list and AML-vendor databases.
Drift Protocol — $285M (April 2026, Solana)
The largest hack on Solana: $285M drained from Drift Protocol. Attribution was ongoing as of publication. Addresses entered the Forta database (used by VerifAML) and GraphSense.
The broader picture
| Metric | H1 2025 | H1 2026 | Trend |
|---|---|---|---|
| Attacks | ~175 | 207 | ↑ 18% |
| Damage | ~$1.3B | $972M | ↓ 25% |
| Avg per attack | ~$7.4M | ~$4.7M | ↓ lower |
| DeFi share | ~60% | ~65% | ↑ |
Trend: more attacks but lower average damage — DeFi defenses are improving, but the number of hacker addresses entering databases keeps rising. This raises risk for P2P traders.
Why even honest people get USDT frozen
Three reasons:
- Tether and USDC cooperate with OFAC and exchanges. If your address is in the transaction chain from a sanctioned address (e.g., TraderTraitor/Kelp DAO), the issuer may freeze USDT on your wallet.
- Exchanges use AML scoring. Binance/Bybit/OKX integrate Chainalysis/TRM. They see incoming-funds history several hops back. A link to a hack = freeze.
- Russia's 2026 crypto law tightens bank oversight: banks must block transfers tied to unlicensed crypto venues. A double filter.
How to protect yourself
Practical checklist
- Screen your counterparty's address before any P2P trade. VerifAML checks 9 databases for free: OFAC, EU, GoPlus, eth-labels, Forta, MEW, BitOK, GraphSense, Ransomwhere. 30 seconds of checking saves months of disputes.
- For large amounts use the Standard tier. It adds reputation databases (GoPlus, eth-labels, Forta) that catch hacker addresses not yet on sanctions lists.
- Screen right before the trade, not in advance. An address may have been clean yesterday but received "dirty" USDT today.
- Keep the AML report. A screenshot of the report is a document for the exchange/bank proving your due diligence.
- Avoid dealing with addresses tied to Garantex/Grinex/HTX — after the EU's 21st package they're under heightened scrutiny.
What to do if your account is frozen
- Ask the exchange for the freeze reason (usually a specific transaction or address).
- Gather evidence of legitimacy: trade history, AML reports on counterparties, correspondence.
- Contact the exchange's compliance department in writing. The process is slow (weeks-months), but inaction = an admission of guilt.
- Pull your USDT history from a block explorer (tronscan.org, etherscan.io) to see where the funds came from.
FAQ
If an address is on OFAC but I received USDT from it unknowingly — will I get the money back? Practically no. Tether/exchanges freeze on the "address with risk" principle. Recovery requires legal proceedings. Prevention (screening before the trade) is the only reliable method.
How often are AML databases updated? OFAC/EU — with each new sanctions package (usually monthly to bimonthly). Reputation databases (GoPlus, eth-labels, Forta) — more often, from daily to weekly. VerifAML refreshes its cache via cron; the last update date is visible in each report.
Do mixers (Tornado Cash) "clean" USDT? No. Tornado Cash obscures the trail in Ethereum, but addresses linked to hacks and Lazarus remain in AML databases. What's more, the mere fact of receiving funds from a mixer is a red flag for exchanges. After Tornado Cash's delisting (March 2025, appellate court) the myth of the "best mixer" persists, but for a P2P trader it's a guaranteed compliance risk.
Related articles
- Tether froze $131M USDT: how stablecoin freezes work
- How to check USDT on Tron before a P2P trade
- What is risk score 0–100 and how to read the report
Sources: TRM Labs (H1 2026 report), Sanctions.io, Phemex, Nardello & Co, FBI attribution. VerifAML is an informational service.