Blockchain AcademicsBlockchain Academics
Crypto Hacks Hit Record 212 Incidents in H1 2026, Totaling $1.1B in Losses

Crypto Hacks Hit Record 212 Incidents in H1 2026, Totaling $1.1B in Losses

The first half of 2026 was the most-hacked six-month stretch in crypto history. Security firm Blockaid counted 212 separate incidents between January and June, with total losses reaching $1.1 billion. North Korea-linked actors were responsible for the two largest exploits: KelpDAO ($292M) and...

Blockchain Academics NewsroomEdited by Wael RajabJuly 29, 20263 min read
Share

Crypto Hacks Hit Record 212 Incidents in H1 2026, Totaling $1.1B in Losses

The first half of 2026 was the most-hacked six-month stretch in crypto history. Security firm Blockaid counted 212 separate incidents between January and June, surpassing every prior half-year period on record, with total losses reaching $1.1 billion across all exploits.

Ethereum projects bore the heaviest damage at $332 million in losses, with Solana close behind at $326 million. Both figures reflect the chains' status as the two largest venues for decentralized finance activity rather than any unique protocol-level weakness: larger total value locked (TVL, the aggregate of assets deposited in DeFi protocols) simply means larger targets. Together, the two networks accounted for roughly 60% of all stolen funds.

Two exploits alone accounted for $577 million of the $1.1 billion total. The $292 million KelpDAO breach and the $285 million Drift exploit were both attributed to North Korea-linked actors. Blockaid's data confirmed that DPRK-affiliated groups executed both attacks, making state-sponsored theft the single largest driver of losses in the period. The concentration of damage in two incidents points to a targeted, sophisticated threat model rather than a broad deterioration in baseline protocol security.

"North Korea-linked actors drove the largest losses, with the $292M KelpDAO and $285M Drift exploits both tied to DPRK groups."

Blockaid

Compromised private keys and signer infrastructure accounted for 74% of all stolen funds, according to Blockaid. The dominant threat is not novel smart contract exploits or zero-day vulnerabilities in protocol code. It is operational security failures: leaked keys, compromised hardware wallets, phished signers, and inadequate multi-signature governance. For protocol teams and treasury managers, the implication is direct. Adoption of multi-sig schemes, hardware security modules, and stricter key management practices would address the majority of the attack surface without requiring any changes to underlying protocol code.

"Blockaid called it the most-hacked half-year on record, with compromised keys and signer infrastructure driving 74% of the money stolen."

Blockaid

The record incident count carries a methodological caveat. Improved detection tooling and broader coverage by security firms mean that breaches which would have gone unreported in 2022 or 2023 now appear in the tally. Some portion of the jump in incident count from prior periods reflects better visibility, not necessarily a proportional increase in attacker activity. Dollar losses are harder to inflate through improved reporting, and $1.1 billion across six months is a concrete figure that requires no adjustment for methodology.

The DPRK dimension places the H1 2026 data inside a longer pattern. The United Nations and multiple government agencies have documented North Korean hacking groups, particularly Lazarus Group, systematically targeting crypto infrastructure since at least 2017. The scale has escalated substantially: UN estimates have previously attributed hundreds of millions in annual crypto theft to DPRK operations, with the funds reportedly used to finance weapons programs. The KelpDAO and Drift exploits, if the attributions hold, would represent the largest single-half contribution from state-linked actors on record.

For Ethereum and Solana developers, the data reinforces a security priority discussed for years but incompletely implemented: the weakest link in most high-value protocols is not the smart contract code that security auditors review, but the human and infrastructure layer controlling administrative keys. Blockaid's H1 2026 figures put an $815 million price tag on that gap, calculated as 74% of $1.1 billion. The number makes the cost of inadequate key management concrete in a way that abstract security recommendations rarely do.

Discussion

Loading comments...