Crypto Losses Hit $1.1B in First Half of 2026 as DPRK Actors and New Attack Vectors Drive Record Incident Surge
Key Takeaways
- •Blockaid verified 212 blockchain security incidents in the first half of 2026, producing $1.1 billion in losses.
- •KelpDAO, Drift Protocol, Resolv, and CowSwap accounted for roughly 64% of the period’s total losses.
- •DPRK-linked actors were responsible for about $609 million in losses, or 55% of the total, including attacks attributed to TraderTraitor.
- •Compromised private keys caused nearly $789 million in damage, making them the largest source of losses by far.
- •New attack patterns included EIP-7702 wallet delegation, the first reported AI prompt injection exploit, and attacks on off-chain bridge prover infrastructure.

The first half of 2026 was the most exploited period in blockchain history, according to onchain security firm Blockaid, which verified 212 incidents totaling $1.1 billion in losses. That figure was 3.4 times the number of high-threshold exploits recorded across all of 2025.
Although total dollar losses did not surpass 2025’s figures — largely because no single event matched the $1.5 billion Bybit breach — the volume and sophistication of attacks pointed to a broader escalation in the threat environment. For protocol teams and infrastructure providers, the report also shows that a single control failure can dominate half-year totals, while lower-dollar incidents still accumulate quickly when attack methods scale across multiple targets.
Losses were heavily concentrated. The four largest incidents — KelpDAO at $292 million, Drift Protocol at $285 million, Resolv at $80 million, and CowSwap at $50.4 million — accounted for roughly 64% of all first-half losses. KelpDAO and Drift were directly attributed to TraderTraitor, a sub-group of North Korea’s Lazarus Group. Including the separately attributed Humanity Protocol breach of $32 million, DPRK-linked actors were responsible for about $609 million, or 55% of the total for the period.
Compromised private keys were the dominant cause of losses by a wide margin. Blockaid said they were responsible for nearly $789 million, or about 74% of first-half damage, across roughly ten incidents. The two largest attacks did not begin with a contract flaw, but with social engineering. DPRK operators targeted employees at Drift and KelpDAO through LinkedIn-style manipulation, ultimately gaining control of multisig signers and bridge verifier infrastructure. In the KelpDAO case, attackers exploited a single-DVN configuration in the LayerZero bridge to forge a cross-chain attestation and drain $292 million from an Ethereum escrow.
Legacy Blind Spots and Novel Vectors Expand the Attack Surface
Code exploits were far less costly in aggregate, at $203 million, but they accounted for the majority of incidents by count, representing nearly 80% of all cases. The largest code exploit was Resolv’s $80 million unbacked mint.
A smaller but recurring pattern involved legacy or deprecated contracts that teams had already migrated away from but had not fully decommissioned. Five incidents in May and June — including two separate attacks on the Aztec Connect rollup and a validation exploit on Raydium’s deprecated AMM V3 — totaled approximately $5.7 million. The incidents underscored that migration timelines are not the same as sunsetting a system.
Three new attack vectors appeared for the first time in the first half of the year. EIP-7702 wallet delegation, introduced by a new Ethereum standard, was abused in four incidents. An AI prompt injection attack on the Bankr agent in May — the first reported case of its kind — led to a loss of $216,000 after tricking an autonomous system into authorizing an unauthorized transaction. Off-chain bridge prover infrastructure was also targeted for the first time, with KelpDAO and Taiko both breached through forged proofs accepted by destination chains.
Recovery outcomes varied sharply. Code exploits sometimes allowed partial fund recovery through emergency pause functions or onchain coordination. By contrast, key compromises produced almost no recovery, with stolen assets typically moved through mixers within hours. The strongest containment of the period occurred on Stellar, where real-time wallet clustering by Blockaid enabled validators to quarantine $7.3 million — 73% of a $10.2 million oracle manipulation drain — within minutes of the attack. That contrast highlights how quickly detection and response can affect the final loss figure, especially when mitigation is built into network operations rather than added after the fact.
The post Crypto Losses Hit $1.1B In First Half Of 2026 As DPRK Actors And New Attack Vectors Drive Record Incident Surge appeared first on Metaverse Post.