Key Highlights

Crypto losses exceeded $1.1 billion across 212 verified incidents in H1 2026, the highest first-half total on record.

Lazarus-linked attackers accounted for about 55% of total losses, with KelpDAO and Drift Protocol among the biggest hacks.

Cross-chain bridges, EVM Layer-2 exploits, and compromised keys remained the leading attack vectors, highlighting growing security risks.

On-chain security platform Blockaid reported that security incidents across the cryptocurrency sector reached a record high in the first half of 2026, with total losses surpassing $1.1 billion across 212 verified incidents. 

According to Blockaid’s report, the first six months of 2026 marked the most-hacked half-year on record. The platform tracked 3.4 times as many high-threshold exploits as in all of 2025, although total dollar losses were lower than during the same period last year because there was no single breach comparable to the $1.5 billion Bybit hack.

Largest incidents drove losses

The four largest incidents, KelpDAO ($292 million), Drift Protocol ($285 million), Resolv, and CowSwap, accounted for approximately $707 million, or about 64% of the total losses in H1 2026. By comparison, the three largest incidents accounted for 72% of losses in 2025.

According to Blockaid, North Korea-linked hacking groups, particularly the TraderTraitor subgroup of the Lazarus Group, were responsible for a significant share of the losses. The KelpDAO, Drift Protocol, and Humanity Protocol exploits were attributed to the group, totaling roughly $609 million, or about 55% of all H1 losses.

Cross-chain bridges emerged as a major vulnerability area, with at least seven incidents reported. According to Blockaid, the KelpDAO exploit began with social engineering that compromised a LayerZero developer’s credentials, followed by the poisoning of RPC infrastructure to forge an attestation. The attack ultimately exploited a single-DVN configuration flaw.

Hackers targeted EVM Layer-2 networks 

New attack vectors also targeted Ethereum Virtual Machine (EVM) Layer 2 networks. 

According to the report, notable examples included the first production EIP-7702 wallet-delegation drain on Arbitrum and two ZK proof-boundary exploits on Aztec. The period also saw the emergence of novel techniques such as AI prompt injection attacks and single-DVN bridge compromises.

Recovery outcomes varied significantly. Exploits involving code vulnerabilities or operator errors sometimes resulted in partial or full fund recoveries, such as the $8.5 million returned after the Verus incident and a complete white hat return at IPOR Fusion. In contrast, funds stolen through operational security (OpSec) attacks were rarely recovered and were often quickly moved through mixers. 

Blockaid also participated in one recovery effort. During the Stellar Blend oracle manipulation incident, validators used the company’s real-time wallet clustering and cross-chain tracing tools to help quarantine $7.3 million, representing about 73% of the $10.2 million stolen.

The report also noted that legacy smart contracts remained a persistent risk. Several attacks in May and June targeted outdated contracts that were still active onchain, including exploits involving Aztec Connect and Raydium’s deprecated AMM V3.

Ethereum-related projects accounted for approximately $332 million in losses, primarily due to smart contract code vulnerabilities. 

Solana-related projects saw $326 million in losses, with over 98% stemming from compromised keys and signing infrastructure, notably affecting Drift Protocol and Step Finance. 

The largest single incident was the $292 million KelpDAO hack, which did not require a traditional contract bug but succeeded through a forged cross-chain message. Drift Protocol lost $285 million in under 12 minutes after attackers gained admin control via social engineering of multisig signers. 

Other major incidents included an $80 million mint of unbacked Resolv stablecoins and a $50.4 million loss from a single signature approval in the CowSwap protocol.

Investors advised to safeguard assets

As hacks, scams, and exploits continue to plague the cryptocurrency sector, investors are advised to take immediate steps to safeguard their assets. 

The majority of holdings should be stored in hardware wallets such as Ledger or Trezor, which keep private keys offline. Hot wallets should hold only small amounts needed for daily transactions. Strong two-factor authentication is essential, with hardware-based methods preferred over SMS to reduce the risk of SIM-swapping attacks. 

Seed phrases must never be shared and should be stored offline, ideally engraved on metal or locked in a secure safe, with advanced users considering Shamir’s Secret Sharing.

Investors are also urged to meticulously verify every address before sending funds, exercise extreme caution with smart contracts, and regularly revoke token approvals using tools like Revoke.cash. Only well-established platforms with features such as withdrawal whitelists and anti-phishing codes should be used.

Also Read: Crypto Daily Brief: Tether Expands, Cardano Advances Transparency, Sei Proposal


Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.




Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here