NewsCryptoEthereum Leads $332M in First-Half 2026 Hack Losses Amid Rising Operational Security Threats

Ethereum Leads $332M in First-Half 2026 Hack Losses Amid Rising Operational Security Threats

Author: Coinotag·

Key Takeaways

  • Ethereum recorded the highest chain-level losses in the first half of 2026, with $332 million stolen from protocols on its network.
  • North Korea-linked actors were responsible for approximately $600 million in losses through LinkedIn-based social engineering that compromised multi-signature wallet signers.
  • DeFi losses have decreased 74% from their 2022 peak, although the overall number of security incidents continues to rise.
  • The first known AI-agent-related security incident was a $216,000 drain from Bankr, with researchers warning of further attacks as blockchain AI deployment expands roughly tenfold annually.
  • The security threat landscape is shifting from smart-contract code exploits toward operational-security failures involving signer management, access control, and human approval workflows.
Ethereum Leads $332M in First-Half 2026 Hack Losses Amid Rising Operational Security Threats

Ethereum (ETH) suffered the largest chain-level losses in the first half of 2026, with $332 million stolen from protocols on its network, according to blockchain-security research published July 28. The figure contributed to a broader crypto-wide toll exceeding $1 billion over the six-month period, making it one of the most active halves on record for verified attacks and pushing incident counts toward an all-time high.

The total remained lower than the same period a year earlier, when a single $1.5 billion Bybit outflow had driven up the industry's damage tally.

North Korea-Linked Actors Behind Largest Losses

North Korea-linked actors accounted for the biggest share of the latest losses, approximately $600 million. This included a $285 million drain from Drift and a $292 million attack on KelpDAO. Researchers traced both campaigns to social-engineering operations that originated on LinkedIn and culminated in the compromise of multi-signature wallet signers.

This attack vector is significant because multi-signature configurations are designed to require several independent approvals. The failure point therefore shifted from smart-contract code to the individuals and keys entrusted with control. For custodians and protocol teams, the findings direct attention toward signer identity, approval thresholds, and real-time transaction monitoring—areas that frequently fall outside traditional code audits.

Converging Data From Multiple Trackers

Immunefi's June ecosystem update counted 207 incidents and approximately $972 million in losses, while Quill Audits, focusing on DeFi, recorded 87 attacks and $935.3 million. The convergence among independent trackers indicates the record is not an artifact of one firm's methodology, but reflects a genuine increase in both attempted and successful intrusions.

The data also demonstrates that while headline dollar amounts have eased from prior peaks, the attack surface continues to widen across wallets, bridges, and deployment pipelines, creating a broader security challenge across multiple blockchain ecosystems. For operators, that means the risk picture now spans code, infrastructure, and human approval paths rather than any single failure point.

Divergent Risk Profiles: Ethereum vs. Solana

Ethereum's $332 million loss total reflected a markedly different risk profile from Solana's $326 million, despite both networks being the hardest-hit chains during the period. The report described Ethereum as home to many high-value protocols—including restaking systems, stablecoin contracts, and decentralized-exchange aggregators—making it a natural target for large smart-contract exploits.

Solana, by contrast, saw attackers focus less on contract logic and more on signature infrastructure, the layer responsible for authorizing transactions and account access. This divergence suggests that defenders must tailor security controls to each chain's architecture rather than applying a uniform audit checklist.

The report further noted that two of the four largest thefts of the half followed the same LinkedIn-based social-engineering pattern, in which attackers persuaded or tricked multisig signers into relinquishing control. Current safeguards remain insufficient to counter this approach, as identity verification, key custody, and approval workflows often sit outside the scope of conventional smart-contract audits. For Ethereum-based teams, this means hardware-key hygiene, signer rotation, and transaction simulation may be as critical as formal code verification.

DeFi Losses Decline Even as Incident Counts Rise

The same research showed that DeFi losses have fallen 74% from their 2022 peak, indicating that repeated audits and bug-bounty programs have reduced the size of individual drains even as incident counts continue to climb.

The emerging pressure point is automated software. A $216,000 drain from Bankr was identified as the first known AI-agent-related case, with the report estimating that blockchain AI deployment is expanding by roughly 10 times per year. Researchers anticipate more incidents in the second half involving AI crypto wallets or AI trading bots, with prompt-injection attacks used to feed malicious instructions to agents, followed by tool abuse and unauthorized signing.

Market Context

The broader market backdrop remains cautious. The Fear and Greed Index stood at 29 out of 100, indicating a fear reading, while Bitcoin dominance was at 69.8% of a $1.853 trillion total crypto market capitalization.

The security narrative appears to be shifting from rare catastrophic code failures toward frequent operational-security failures. The primary-source record—the security report and on-chain transaction trails—indicates the next defensive frontier encompasses signer management, access control, and AI-agent oversight.