Cryptocurrency projects lost approximately $1.1 billion in 212 verified exploit incidents during the first half of 2026, according to a report published by security firm Blockaid. This marked
Cryptocurrency projects lost approximately $1.1 billion in 212 verified exploit incidents during the first half of 2026, according to a report published by security firm Blockaid. This marked the highest half-year incident count on record, with a 3.4-fold increase in breaches compared to the entirety of 2025.
Largest incidents and total losses
The overall dollar value of stolen assets was lower than in the previous year, largely due to the absence of one-off mega breaches such as the $1.5 billion loss Bybit suffered in February 2025. In 2026, the four largest individual incidents—impacting KelpDAO, Drift Protocol, Resolv, and CowSwap—contributed nearly $707 million combined, representing 64% of losses during the period.
ProjectLoss ($ million)MonthAttributed ToKelpDAO292AprilDPRK-linked groupDrift Protocol285AprilDPRK-linked groupResolv?2026UnknownCowSwap?2026Unknown
Excluding these major cases, the remaining exploits exceeded 200 incidents and resulted in about $358 million in losses, highlighting an ongoing trend of frequent but smaller attacks in the crypto ecosystem.
Attack methods and security risks
Blockaid identified operational security breaches—such as compromised private keys, signer infrastructure, bridge protocols, and backend systems—as the leading cause of losses. These operational attacks accounted for around $789 million, or 74% of total funds stolen, even though smart contract vulnerabilities made up most of the incidents numerically.
For institutions exploring tokenized assets and onchain settlement, due diligence now centers not only on contract audits but also on key management and transaction authorization processes.
The report noted this shift in the nature of threats, as attackers increasingly exploit human and infrastructure weaknesses rather than just code flaws.
Role of North Korea-linked actors
Approximately 55% of first-half losses were linked to actors tied to North Korea. Blockaid attributed attacks on KelpDAO and Drift Protocol—valued at $292 million and $285 million respectively, and occurring 17 days apart—to groups associated with the Democratic People’s Republic of Korea (DPRK). The same cluster was connected to a $32 million breach at Humanity Protocol.
The firm highlighted LinkedIn-based social engineering campaigns ending in multisig signer compromises as a common entry point for these breaches, a tactic it expects will persist in upcoming incidents.
LayerZero, a cross-chain messaging protocol developer, specifically identified the KelpDAO bridge attack as the work of North Korea’s Lazarus Group. In that exploit, attackers manipulated a single-verifier configuration to forge a cross-chain message. Drift Protocol’s post-mortem reported a sophisticated intelligence operation spanning six months, which included in-person meetings with project contributors.
Mini dictionary: Lazarus Group – A notorious hacking collective believed to be operated by the North Korean government, implicated in numerous high-profile cyberattacks targeting financial and cryptocurrency platforms worldwide.
Network breakdown and new attack vectors
Ethereum-based projects incurred nearly $332 million in exploit-related losses, primarily from code vulnerabilities, while Solana-based projects lost about $326 million, with more than 98% of the latter traced to stolen keys and compromised signing setups.
NetworkTotal Loss ($ million)Main Vector
Ethereum332Code vulnerabilities
Solana326Compromised keys/signers
Blockaid observed a rise in novel attack methods, including the first-known exploitation of an artificial intelligence agent manipulated into approving an unauthorized transaction. This resulted in a $216,000 loss at Bankr. The report also noted abuse of EIP-7702 wallet delegation, and during the Stellar Blend attack, Blockaid’s tracing efforts helped quarantine about $7.3 million after the incident.
LinkedIn-based social engineering led to multisig signer compromise in two of the year’s four largest cases, and similar schemes are expected to continue targeting key infrastructure.
The post Crypto suffered $1.1 billion in 212 exploit incidents in first half of 2026, Blockaid reports appeared first on COINTURK NEWS.