
Blockaid reports $1.1 billion stolen across 212 crypto incidents in H1 2026, with North Korea-linked groups responsible for 55% of losses. KelpDAO and Drift Protocol led the breaches.
The first half of 2026 was the most active six-month period for crypto exploits on record, with hackers stealing $1.1 billion across 212 incidents, according to blockchain security firm Blockaid.
Four major breaches accounted for roughly $707 million of the total. KelpDAO lost $292 million after attackers faked a cross-chain message to drain its Ethereum reserves. Drift Protocol, a Solana-based perpetuals exchange, was hit for $285 million within 12 minutes. Blockaid linked both cases to TraderTraitor, a state-sponsored North Korean subset of the Lazarus Group. Humanity Protocol’s $32 million loss was connected to the same cluster, bringing North Korea-linked losses to $609 million, or about 55% of all funds stolen in the period.
The pace of attacks accelerated through the year. Monthly incidents rose from 18 in January to 57 in June. April was the most costly month, with the KelpDAO and Drift Protocol hacks combining for $577 million, pushing total April losses to $635 million.
Privileged key misuse was the most expensive attack type, accounting for about $790 million, or roughly three-quarters of all stolen funds, Blockaid said. Unbacked mint exploits came second, led by the $80 million Resolv breach. Code-level hacks caused the most incidents, representing nearly four out of every five attacks.
AI agents emerged as a new target. In May, hackers used a prompt injection attack to trick Bankr’s AI agent into approving an unauthorized transaction worth about $216,000.
Cross-chain bridges also took a heavy hit. Attackers breached verification systems at KelpDAO and Taiko by forging proofs and attestations that destination chains accepted.
Blockaid identified four incidents involving EIP-7702 wallet delegation attacks, where a wallet hands control to a smart contract. Legacy smart contracts remained a common vulnerability, with about five cases in May and June, including two involving Aztec Connect and one targeting Raydium’s AMM V3.
Recent incidents outside the report period showed continued pressure on crypto infrastructure. On July 23, AFX Trade, BSquaredNetwork, and Verus were hit in separate attacks on the same day, collectively causing more than $35 million in losses. Verus had already suffered another exploit about two months earlier, and Blockaid linked both incidents to the same bridge contract and bug class.
Recovery varied by attack type. Code-related incidents sometimes allowed teams to freeze funds or negotiate returns, while attacks involving stolen keys usually ended with the money moving through mixers or cross-chain routes.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.