NewsCryptoCrypto Hacks Drain $1.1 Billion in First Half of 2026 Across 212 Security Incidents, Blockaid Reports

Crypto Hacks Drain $1.1 Billion in First Half of 2026 Across 212 Security Incidents, Blockaid Reports

Author: CryptoNewsNet·

Key Takeaways

  • Approximately $1.1 billion was stolen across 212 cryptocurrency security incidents in the first half of 2026, making it the costliest half-year on record for crypto breaches.
  • North Korea-linked attackers, identified as the TraderTraitor subgroup within the Lazarus Group, were responsible for roughly 55% of all stolen funds, totaling approximately $609 million.
  • Privileged key misuse was the costliest attack vector, accounting for about $790 million in losses, while code-level hacks represented nearly four out of five individual incidents by count.
  • Attackers exploited emerging surfaces including AI agents, with a prompt injection attack tricking Bankr's AI agent into approving a $216,000 unauthorized transaction, and cross-chain bridges through forged proofs and attestations.
  • Recovery prospects varied significantly by attack type, as code-related incidents sometimes allowed fund freezing or negotiated returns, while stolen privileged keys typically led to laundering through mixers with little chance of recovery.
Crypto Hacks Drain $1.1 Billion in First Half of 2026 Across 212 Security Incidents, Blockaid Reports

Crypto Hacks Drain $1.1 Billion in First Half of 2026 Across 212 Security Incidents

The first six months of 2026 marked the most active period on record for cryptocurrency exploits, according to a new report from blockchain security firm Blockaid. Hackers stole approximately $1.1 billion across 212 separate incidents, making H1 2026 the costliest half-year for crypto security breaches to date. The figure continues a multi-year trend of escalating losses that has persisted despite maturing security practices across the industry.

Four Incidents Drive the Majority of Losses

Blockaid's report identified four major incidents — involving KelpDAO, Drift Protocol, Resolv, and CoW Swap — as responsible for roughly $707 million of the total losses.

KelpDAO sustained the single largest loss. Attackers fabricated a cross-chain message that enabled them to drain $292 million worth of cryptocurrency from the protocol's Ethereum reserves. Drift Protocol, a perpetuals exchange built on Solana, was exploited for $285 million in a breach that took only 12 minutes to execute.

Blockaid attributed both the KelpDAO and Drift Protocol exploits to TraderTraitor, a state-sponsored North Korean subgroup operating within the broader Lazarus Group framework. A third incident — the $32 million loss at Humanity Protocol — was linked to the same attacker cluster. Combined, DPRK-linked losses reached $609 million, accounting for approximately 55% of all funds stolen during the period. North Korea's involvement in cryptocurrency theft has been extensively documented by the United Nations, the FBI, and other government agencies, which have linked stolen digital assets to the funding of state weapons programs.

The frequency of attacks accelerated steadily throughout the half-year. Monthly incidents rose from 18 in January to 57 in June. April was the most devastating month: the KelpDAO and Drift Protocol breaches alone erased $577 million, driving total monthly losses to $635 million.

Privileged Key Misuse the Costliest Attack Vector

Privileged key misuse ranked as the most expensive attack category in H1 2026, generating approximately $790 million in losses — close to three-quarters of all funds stolen during the period, according to Blockaid. The finding underscores long-standing industry concerns about operational key management, an area where hardware security modules, multisignature wallets, and threshold signing schemes have been widely recommended but unevenly adopted. Unbacked mint exploits followed in value, led by the $80 million Resolv breach.

However, code-level hacks produced the highest number of individual incidents, accounting for nearly four out of five attacks by count.

Emerging Threats Target AI Agents and Cross-Chain Bridges

The report highlighted AI agents as a newly emerging attack surface. In May, hackers deployed a prompt injection attack that deceived Bankr's AI agent into approving an unauthorized transaction valued at approximately $216,000. The incident points to a new category of risk as autonomous and semi-autonomous agents increasingly handle on-chain transactions in DeFi protocols.

Cross-chain bridges also faced significant pressure. Attackers compromised the verification systems of both KelpDAO and Taiko by submitting forged proofs and attestations that destination chains accepted as valid. Bridges have been among the most consistently exploited components in decentralized finance since major breaches in prior years resulted in hundreds of millions of dollars in losses.

Security teams also encountered novel attack techniques in 2026. Blockaid documented four incidents involving EIP-7702 wallet delegation attacks, a mechanism introduced in Ethereum's Pectra upgrade that allows a wallet to hand control over to a smart contract. Legacy smart contract vulnerabilities remained a persistent problem as well, with approximately five cases recorded in May and June alone — including two involving Aztec Connect and one targeting Raydium's AMM V3.

Post-Report Incidents Signal Continued Pressure

Attacks documented outside the report's coverage period suggest the threat level has not abated. On July 23, AFX Trade, BSquaredNetwork, and Verus were each hit in separate incidents on the same day, collectively causing more than $35 million in losses. Verus had previously suffered an exploit roughly two months earlier; Blockaid linked both Verus incidents to the same bridge contract and bug class.

Recovery outcomes depended heavily on the nature of the attack. Code-related incidents occasionally allowed security teams to freeze funds or negotiate partial returns. In contrast, attacks involving stolen privileged keys typically resulted in funds being laundered through mixers or moved across multiple chains, significantly reducing the likelihood of recovery.

Source: CryptoNews.net