
Blockaid reports 212 crypto exploits in H1 2026, a record. Compromised keys drove 74% of $1.1B stolen. North Korea linked to 55% of losses. The risk shifts from code audits to key security.
Blockaid called it the most-hacked half-year on record, with compromised keys and signer infrastructure driving 74% of the money stolen.
Crypto lost roughly $1.1 billion across 212 verified exploit incidents in the first half of 2026, the most-hacked half-year on record by incident count, according to a report Blockaid published Tuesday. The security firm verified about 3.4 times as many incidents in six months as it recorded across all of 2025.
Dollar losses were lower than the year-earlier figure, which was inflated by Bybit’s $1.5 billion February 2025 breach. The four largest incidents so far this year, involving KelpDAO, Drift Protocol, Resolv, and CowSwap, accounted for roughly $707 million, or 64% of the total. Strip those out and more than 200 remaining attacks still produced about $358 million in losses.
Operational security attacks, meaning compromised credentials, private keys, signer infrastructure, bridge infrastructure, and backend systems, accounted for roughly $789 million, or 74% of funds stolen, despite representing a smaller share of incidents than smart contract exploits. For institutions weighing tokenized assets and onchain settlement, that shifts the diligence question from whether a contract has been audited to who holds the keys and how transactions get authorized.
Suspected North Korea-linked actors accounted for roughly 55% of H1 losses. Blockaid attributed both the $285 million Drift compromise and the $292 million KelpDAO compromise, 17 days apart in April, to DPRK-linked groups, and added Humanity Protocol’s $32 million loss to the same cluster. The firm said LinkedIn social engineering ending in multisig signer compromise produced two of the four largest incidents of the half and expects the pattern to continue. By network, Ethereum projects lost about $332 million, mostly through code vulnerabilities, while Solana projects lost about $326 million, with more than 98% of that traced to compromised keys and signing infrastructure.
LayerZero attributed the KelpDAO bridge exploit to North Korea’s Lazarus Group after attackers forged a cross-chain message through a single-verifier configuration, and Drift’s post-mortem described a six-month intelligence operation that included in-person meetings with contributors. Blockaid also flagged newer vectors, including the first reported exploit of an AI agent manipulated into approving an unauthorized transaction, a $216,000 loss at Bankr, plus abuse of EIP-7702 wallet delegation. During the Stellar Blend incident, the firm said its tracing helped quarantine roughly $7.3 million.
The report underscores a shift in crypto risk: the biggest threat is no longer smart contract bugs but the human and operational layer around key management. For exchanges and protocols, that means investing in multisig hygiene, hardware security modules, and insider‐threat monitoring. The next high‐profile compromise could come from a simple LinkedIn message, three analysts said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.