Need help? Support
BITCOIN
Tether Dominance USDT.D

Crypto security losses top $1B in H1

Published 614 words 3 min read

TLDR

Crypto security incidents in the first half of 2026 caused more than $1 billion in losses, driven by a record number of exploits and a shift toward human and operational weaknesses.

  1. Blockaid reports 212 verified onchain exploits stealing about $1.1 billion in H1 2026, the highest half-year incident count so far.
  2. Around three quarters of losses came from compromised keys, governance and infrastructure, with North Korea-linked groups behind over half of stolen funds.
  3. The main risk for users is operational security, not just buggy code, and future attacks could increasingly target wallets, AI agents and bridges.

Deep Dive

1. Scale Of H1 Losses

Security firm Blockaids H1 2026 Onchain Security Report finds attackers stole roughly $1.1 billion across 212 exploits in the first six months of 2026, a record for incident volume in any half-year period. The report notes June alone saw 57 incidents, and four major exploits accounted for $707 million, or around 64 percent of all stolen funds, according to Blockaids H1 2026 analysis.

Dollar losses are slightly below H1 2025, when a single $1.5 billion Bybit theft dominated statistics, but the key message is that attacks are multiplying and becoming more sophisticated. Other analytics firms such as TRM Labs put H1 hack losses nearer $972 million, largely because they use different thresholds and incident definitions, but all agree the environment is unusually hostile.

Ethereum and Solana ecosystems are highlighted as the most impacted, with losses around $332 million and $326 million respectively in one breakdown of the data.

2. Where The Money Was Lost

Blockaid attributes about 74 percent of H1 losses to operational security failures: compromised keys, signing infrastructure and privileged governance access, rather than pure smart contract bugs. The two largest incidents, the $292 million KelpDAO exploit and the $285 million drain of Solana perpetual DEX Drift Protocol, were both tied to North Koreas Trader Traitor cluster, together responsible for roughly $609 million of losses.

In Drifts case, weeks of targeted social engineering gave attackers control of an administrative multisig, letting them steal $285 million in under 12 minutes. In the KelpDAO incident, a LayerZero developer was tricked into changes that poisoned bridge infrastructure, enabling forged cross-chain attestations and a $292 million theft, as detailed in Blockaids report.

Separate research from Immunefi, summarized by CoinDesk, shows a similar pattern over 20212025: a minority of operational failures accounted for most value lost, while continuous audits and bug bounties have started to harden contract code.

3. User Risks And What To Watch

For everyday crypto users, these findings mean the biggest risk is often poor key management or trusting platforms with weak governance and infrastructure, not just unaudited smart contracts. Emerging attack vectors include EIP-7702 wallet delegation misuse, AI prompt-injection attacks on trading agents, and off-chain bridge infrastructure, all flagged as growing threats in the Blockaid report.

At the retail level, malware such as SparkKitty is already stealing phone photos to harvest screenshots of seed phrases, underscoring the danger of storing wallet secrets in device galleries or cloud backups. On the defensive side, security-focused tools like Safes Safenet, an onchain network that pre-checks transactions before value leaves a smart account, are starting to appear, with Safenet processing hundreds of thousands of checks in Q2 2026 according to Safes latest update.

What this means

Treat keys, governance, bridges and AI agents as live attack surfaces; using hardened custody setups, avoiding seed-phrase images, and scrutinizing protocols operational controls can matter as much as reading their code.

Conclusion

Crypto security losses topping $1 billion in H1 reflect a shift from rare mega-heists to many targeted, often human-driven attacks that concentrate on keys and infrastructure. While contract auditing and bug bounties are reducing some code risk, the main vulnerability now lies in operational security across wallets, bridges and governance systems, so the most impactful improvements for users and protocols will come from tightening those layers and watching new attack patterns closely.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top