Key Highlights
- Crypto losses exceeded $1.1 billion throughout 212 verified incidents in H1 2026, the best first-half complete on file.
- Lazarus-linked attackers accounted for about 55% of complete losses, with KelpDAO and Drift Protocol among the many greatest hacks.
- Cross-chain bridges, EVM Layer-2 exploits, and compromised keys remained the main assault vectors, highlighting rising safety dangers.
On-chain safety platform Blockaid reported that safety incidents throughout the cryptocurrency sector reached a file excessive within the first half of 2026, with complete losses surpassing $1.1 billion throughout 212 verified incidents.
In keeping with Blockaid’s report, the primary six months of 2026 marked the most-hacked half-year on file. The platform tracked 3.4 instances as many high-threshold exploits as in all of 2025, though complete greenback losses have been decrease than throughout the identical interval final 12 months as a result of there was no single breach similar to the $1.5 billion Bybit hack.
Largest incidents drove losses
The 4 largest incidents, KelpDAO ($292 million), Drift Protocol ($285 million), Resolv, and CowSwap, accounted for about $707 million, or about 64% of the whole losses in H1 2026. By comparability, the three largest incidents accounted for 72% of losses in 2025.
In keeping with Blockaid, North Korea-linked hacking teams, significantly the TraderTraitor subgroup of the Lazarus Group, have been accountable for a major share of the losses. The KelpDAO, Drift Protocol, and Humanity Protocol exploits have been attributed to the group, totaling roughly $609 million, or about 55% of all H1 losses.
Cross-chain bridges emerged as a serious vulnerability space, with a minimum of seven incidents reported. In keeping with Blockaid, the KelpDAO exploit started with social engineering that compromised a LayerZero developer’s credentials, adopted by the poisoning of RPC infrastructure to forge an attestation. The assault in the end exploited a single-DVN configuration flaw.
Hackers focused EVM Layer-2 networks
New assault vectors additionally focused Ethereum Digital Machine (EVM) Layer 2 networks.
In keeping with the report, notable examples included the primary manufacturing EIP-7702 wallet-delegation drain on Arbitrum and two ZK proof-boundary exploits on Aztec. The interval additionally noticed the emergence of novel strategies corresponding to AI immediate injection assaults and single-DVN bridge compromises.
Restoration outcomes various considerably. Exploits involving code vulnerabilities or operator errors typically resulted in partial or full fund recoveries, such because the $8.5 million returned after the Verus incident and an entire white hat return at IPOR Fusion. In distinction, funds stolen by way of operational safety (OpSec) assaults have been hardly ever recovered and have been typically rapidly moved by way of mixers.
Blockaid additionally participated in a single restoration effort. Throughout the Stellar Mix oracle manipulation incident, validators used the corporate’s real-time pockets clustering and cross-chain tracing instruments to assist quarantine $7.3 million, representing about 73% of the $10.2 million stolen.
The report additionally famous that legacy sensible contracts remained a persistent threat. A number of assaults in Might and June focused outdated contracts that have been nonetheless lively onchain, together with exploits involving Aztec Connect and Raydium’s deprecated AMM V3.
Ethereum-related initiatives accounted for about $332 million in losses, primarily on account of sensible contract code vulnerabilities.
Solana-related initiatives noticed $326 million in losses, with over 98% stemming from compromised keys and signing infrastructure, notably affecting Drift Protocol and Step Finance.
The biggest single incident was the $292 million KelpDAO hack, which didn’t require a conventional contract bug however succeeded by way of a cast cross-chain message. Drift Protocol misplaced $285 million in below 12 minutes after attackers gained admin management by way of social engineering of multisig signers.
Different main incidents included an $80 million mint of unbacked Resolv stablecoins and a $50.4 million loss from a single signature approval within the CowSwap protocol.
Buyers suggested to safeguard belongings
As hacks, scams, and exploits proceed to plague the cryptocurrency sector, traders are suggested to take fast steps to safeguard their belongings.
Nearly all of holdings ought to be saved in {hardware} wallets corresponding to Ledger or Trezor, which preserve non-public keys offline. Scorching wallets ought to maintain solely small quantities wanted for each day transactions. Robust two-factor authentication is crucial, with hardware-based strategies most well-liked over SMS to scale back the chance of SIM-swapping assaults.
Seed phrases mustn’t ever be shared and ought to be saved offline, ideally engraved on steel or locked in a safe secure, with superior customers contemplating Shamir’s Secret Sharing.
Buyers are additionally urged to meticulously confirm each deal with earlier than sending funds, train excessive warning with sensible contracts, and often revoke token approvals utilizing instruments like Revoke.money. Solely well-established platforms with options corresponding to withdrawal whitelists and anti-phishing codes ought to be used.
Additionally Learn: Crypto Daily Brief: Tether Expands, Cardano Advances Transparency, Sei Proposal
Disclaimer: The knowledge researched and reported by The Crypto Instances is for informational functions solely and isn’t an alternative to skilled monetary recommendation. Investing in crypto belongings includes vital threat on account of market volatility. All the time Do Your Personal Analysis (DYOR) and seek the advice of with a certified Monetary Advisor earlier than making any funding choices.





