TLDR
Crypto projects lost over $1 billion to hacks in the first half of 2026, making it the most heavily hacked six month period on record.
- Security firm Blockaid verified 212 incidents in H1 2026, with losses around 1.01.1 billion dollars and major exploits hitting Ethereum (ETH) and Solana (SOL).
- Most stolen funds came from compromised keys and infrastructure, not smart contract bugs, with a North Korea linked cluster responsible for more than half of total losses.
- The report flags rising risk from AI driven exploits and stresses better operational security, key management, and monitoring as critical for users and protocols.
Deep Dive
1. Scale Of H1 2026 Losses
Blockaid calls H1 2026 the most hacked half year on record, counting 212 verified onchain security incidents and over 1 billion dollars lost across projects globally, including DeFi, bridges, and apps. Its figures, summarized by outlets like The Block, put total losses above 1 billion dollars, while a deeper breakdown in a later Blockaid dataset cited about 1.1 billion dollars across these incidents, and other firms such as Immunefi and Quill Audits report slightly lower totals but still agree on a record incident count.
By chain, Ethereum (ETH) related projects lost roughly 332 million dollars and Solana (SOL) around 326 million dollars, according to Blockaids H1 security report compiled by Cointelegraph, with the largest single exploit being the KelpDAO incident at about 292 million dollars.
The headline number is large, but the more important signal is the sustained volume and breadth of attacks, not just one off black swan hacks.
2. Where And How Attacks Hit
Blockaids analysis, highlighted in a detailed write up by Crypto.news, finds about 74 percent of stolen value came from operational security failures: compromised devices, private keys, signing systems, and off chain infrastructure, rather than pure smart contract code bugs. On Ethereum, attackers focused on high value protocols and bridges with complex code paths, while Solana losses were overwhelmingly tied to signer and key infrastructure, with more than 98 percent of its losses coming from compromised keys.
A single cluster that investigators link to the Democratic Peoples Republic of Korea accounted for roughly 55 percent of total losses, including the Drift exploit (around 285 million dollars) and the KelpDAO bridge attack, as described in Blockaids incident breakdown. This underscores that nation state level actors are now central players in large crypto thefts.
The biggest weak points are privileged keys and infrastructure, so users and teams should treat signer compromise as the primary risk, not just smart contract audits.
3. Implications And What To Watch
Blockaid expects continued activity from North Korea linked groups and warns that AI related exploits are likely to grow, citing early cases where autonomous agents and prompt injection attacks led to unauthorized signing and fund movement. The report also notes a sharp increase in high threshold exploits compared with all of 2025, meaning more incidents crossing larger loss thresholds.
For everyday crypto users, the trend points toward higher systemic risk around bridges, restaking platforms, high leverage protocols, and ecosystems where keys sign frequently on hot infrastructure. For builders, it suggests that isolating signing devices, segregating keys, enforcing strong transaction intent checks, and monitoring for anomalous behavior are now core parts of crypto security, not optional extras.
The practical edge is to pay more attention to where and how your assets are custodied and bridged; key hygiene and venue choice matter as much as which tokens you hold.
Conclusion
The record 1 billion plus dollars in crypto hack losses in early 2026 reflect a shift toward frequent, infrastructure focused attacks driven by sophisticated, sometimes state backed actors. Ethereum and Solana bear the largest headline figures, but the underlying pattern is cross ecosystem: operational security around keys and bridges is the main fault line. For crypto participants, the takeaway is to treat security architecture and custody decisions as central to any strategy, since future waves of exploits will likely target those same pressure points rather than just isolated protocol bugs.
