Need help? Support
BITCOIN
Tether Dominance USDT.D

Crypto hacks hit record 212 in H1

Published 638 words 3 min read

TLDR

Crypto projects suffered a record 212 hacks in the first half of 2026, with more than 1 billion dollars stolen across on chain exploits.

  1. Blockaid and other security firms report 212 verified incidents in H1 2026, the highest half year hack count on record, with losses around 1.0 to 1.1 billion dollars.
  2. Around three quarters of stolen funds came from operational security failures like compromised keys and signers, with North Korea linked groups and large bridge and DeFi exploits dominating the damage.
  3. The trend shifts risk toward infrastructure and governance, so users and builders need to watch bridges, key management, and emerging AI driven attack vectors more than just smart contract bugs.

Deep Dive

1. Scale Of The H1 Attack Wave

Blockaids H1 2026 Onchain Security Report finds attackers stole over 1.1 billion dollars across 212 verified exploits, calling it the most hacked half year on record by incident count. That is more exploits than Blockaid recorded in all of 2025 and higher than the previous half year record of 187 incidents in late 2025, according to a CoinsKid Community summary.

Dollar losses are lower than H1 2025, when a single Bybit theft of about 1.5 billion dollars distorted totals, but the spread of many medium sized incidents shows attacks are multiplying. Immunefi and other firms report similar magnitudes, around 972 million dollars across 200 plus hacks, with differences explained by coverage and definitions rather than direction of the trend.

What this means

Risk now comes from a broad baseline of exploits, not just rare mega hacks, so it is harder to avoid a few bad platforms and call it safe.

2. How Attackers Are Breaching Crypto

Blockaid estimates about 74 percent of value stolen in H1 2026 came from operational security failures, meaning compromised devices, credentials, private keys, signing systems, and off chain infrastructure rather than pure smart contract bugs. One attacker cluster linked to North Korea accounted for roughly 55 percent of losses, including the 292 million dollar KelpDAO bridge exploit and the 285 million dollar Drift Protocol incident.

Ethereum projects lost roughly 332 million dollars, mostly to large code exploits targeting restaking, stablecoins, and DEX aggregators, while Solana projects lost about 326 million dollars, primarily from signer and key compromises rather than protocol logic. Cross chain bridges continued to be a weak point, featuring in several of the largest single incidents despite fewer total events.

What this means

The main failure modes are governance, access control, and critical infrastructure, so due diligence needs to cover how keys, multisigs, and bridges are operated, not just whether contracts were audited.

3. What To Watch Next

Security firms expect continued activity from DPRK linked groups and warn that AI powered exploits are likely to grow as automated agents gain more control over signing and operations. Blockaid already flags an early AI related exploit and anticipates multiple agent incidents in the second half of 2026.

For everyday users, risk concentrates in three places: custodial platforms with opaque security, protocols that rely on a small number of privileged keys, and bridges or restaking systems that move large value across chains. Builders are being pushed toward stronger transaction intent checks, hardware backed key segregation, and continuous monitoring, while bug bounties and audits remain necessary but clearly insufficient on their own.

What this means

A practical lens is to prioritize platforms that disclose key management and incident response, treat bridges as high risk infrastructure, and assume that social engineering and AI enhanced scams will keep rising.

Conclusion

The headline number, 212 hacks in six months, signals a structural shift in crypto security where more incidents stem from how systems are run rather than how code is written. Losses are spread across bridges, DeFi, and signer infrastructure on major chains like Ethereum and Solana, with state linked actors and increasingly sophisticated tools driving the biggest cases. For crypto users and builders, the advantage now lies in understanding and monitoring operational security and governance, because those controls are where both the largest risks and the fastest improvements will show up.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top