NewsCryptoCrypto Hacks Exceed $1 Billion in Record-Breaking H1 2026, Reports Blockaid

Crypto Hacks Exceed $1 Billion in Record-Breaking H1 2026, Reports Blockaid

Author: Cryptofrontnews·

Key Takeaways

  • Cryptocurrency security breaches exceeded $1 billion across 212 verified incidents during the first half of 2026, marking the highest six-month total ever recorded according to Blockaid.
  • Ethereum-related losses of approximately $332 million stemmed mainly from code vulnerabilities, whereas Solana's $326 million in losses were driven overwhelmingly by compromised keys and signing infrastructure rather than smart contract flaws.
  • The KelpDAO bridge contract exploit resulted in roughly $292 million in losses, representing the most significant single incident during the reporting period.
  • Operational security failures caused 74% of all stolen value, and a North Korea-linked attack group was responsible for 55% of total recorded losses.
  • Several affected projects are pursuing recovery efforts, with KelpDAO completing its recovery operations on May 25 and Drift Protocol proposing a recovery pool backed by exchange revenue, Tether, and strategic partners.
Crypto Hacks Exceed $1 Billion in Record-Breaking H1 2026, Reports Blockaid

Cryptocurrency security breaches surpassed $1 billion during the first half of 2026, following a series of attacks on projects across multiple blockchains, according to on-chain security firm Blockaid. The firm recorded 212 verified security incidents through June, marking the highest six-month total on record. The figure continues a pattern of major losses that has persisted across the crypto industry despite maturing security practices, with cross-chain bridges and DeFi protocols remaining frequent targets. Projects built on Ethereum and Solana reported the largest financial losses, with decentralized finance protocol KelpDAO recording the most significant single exploit.

Ethereum and Solana Face Different Attack Vectors

According to Blockaid's H1 2026 Onchain Security Report, Ethereum-related projects lost approximately $332 million during the period. The majority of these losses resulted from code vulnerabilities. KelpDAO alone accounted for roughly $292 million of the total after attackers successfully exploited a bridge contract. Bridge protocols have been a recurring target for attackers in previous years as well, with several of the largest exploits in crypto history involving cross-chain infrastructure.

Meanwhile, Solana-related projects experienced approximately $326 million in losses. However, Blockaid noted that more than 98% of the funds stolen on Solana resulted from compromised keys and compromised signing infrastructure rather than smart contract flaws. The report identified Drift Protocol and Step Finance as the largest contributors to Solana's overall losses. Smaller code-related incidents also affected Raydium and Volo during the same timeframe.

Operational Security Drives Majority of Losses

Blockaid detailed that operational security failures were responsible for 74% of the total value stolen across all incidents. Furthermore, an attack cluster linked to North Korea accounted for 55% of all recorded losses during the first half of the year. DPRK-linked actors have been attributed to a string of major cryptocurrency thefts by U.S. government agencies and private security firms in recent years, making state-associated threat groups a persistent concern for the industry.

The report indicated that attackers are increasingly targeting physical devices, private keys, privileged credentials, and signing systems. Because compromised infrastructure produces transactions that are approved by authorized credentials, they appear entirely legitimate to the network. The firm explained that traditional smart contract audits cannot prevent authorized administrators from approving malicious transactions once their personal systems have been compromised.

Recovery Efforts and Future Security Measures

Several projects affected by the breaches have continued their recovery operations. KelpDAO completed the operational phase of its recovery plan on May 25, which involved transferring the final tranche of rsETH into its bridge adapter.

Drift proposed creating a recovery pool backed by exchange revenue, Tether, and other strategic partners. The protocol also introduced new security measures to be implemented before restarting operations, including dedicated signing devices, timelocks, redesigned multisig controls, and additional comprehensive audits.

As investigations into several major incidents remain ongoing, Blockaid expects infrastructure teams to widely adopt strengthened transaction monitoring, isolated signing devices, strict key segregation, and enhanced bridge security.