
Blockaid verified 212 crypto security incidents in H1 2026 totaling $1.1B. Operational attacks drove 74% of losses; a DPRK-linked cluster accounted for 55%. Drift and KelpDAO recovery plans are next catalysts.
Crypto security losses reached $1.1 billion across 212 verified incidents during the first half of 2026, according to an H1 report published by Blockaid on July 28.
Blockaid called the six-month incident count a record and said it verified more exploits during the first half than it did across all of 2025. Operational security attacks produced 74% of the stolen value. One cluster linked to the Democratic People's Republic of Korea accounted for 55% of the total, the security firm said.
The incident count was 3.4 times the 2025 full-year number, Blockaid said. Security companies use different definitions and coverage methods when compiling industry loss estimates, so comparisons across reports need to account for those differences.
Blockaid's numbers reflect a shift away from attacks that rely only on faulty smart-contract code. Compromised devices, privileged credentials, private keys, signing systems and off-chain infrastructure generated most of the measured losses. These attacks can produce valid-looking blockchain transactions because authorized credentials approve them.
That pattern limits the protection code audits can provide. Audits identify contract flaws. They cannot stop a compromised administrator from signing a malicious transaction or prevent a bridge verifier from relying on poisoned infrastructure, Blockaid said. New attack vectors emerged during the first half, the firm said, and some could expand during the second half.
Ethereum-related projects lost about $332 million, according to Blockaid's report. Code vulnerabilities accounted for much of that total. The largest Ethereum-linked case was KelpDAO, where attackers released 116,500 rsETH worth roughly $292 million from a bridge contract after falsifying a source-chain message.
Chainalysis linked the April 18 KelpDAO attack to North Korea's Lazarus Group. Its investigation found that attackers compromised internal RPC nodes and disrupted external nodes, causing a single-verifier system to accept a false burn event. The Ethereum-side bridge then released rsETH even though no corresponding tokens had been destroyed on the source chain.
KelpDAO completed the operational phase of its recovery plan on May 25 after transferring a final 20,373.72 rsETH tranche into its bridge adapter, crypto.news reported. Minting, redemptions and rewards resumed. Litigation and disputed claims involving frozen funds remained unresolved.
Solana-related projects lost about $326 million. More than 98% came from compromised keys and signing infrastructure rather than smart-contract bugs, Blockaid found. Drift Protocol and Step Finance accounted for most of that amount. Smaller code-related incidents affected projects including Raydium and Volo.
Drift suffered a privileged-access attack on April 1. Chainalysis said attackers used months of social engineering and pre-signed durable-nonce transactions to gain administrative control. Drift's April 16 recovery update valued stolen assets at $295.7 million, above the roughly $285 million early estimate used by Blockaid and several investigators.
Drift proposed a recovery pool supported by exchange revenue, Tether and other partners. Its plan included up to $127.5 million of proposed support from Tether, $20 million from other partners and a separate transferable recovery token. The protocol said its restart would require audits by OtterSec and Asymmetric, dedicated signing devices, timelocks and a redesigned multisig.
A wallet tied to the Drift exploiter moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash between July 23 and July 24 after roughly three months of inactivity.
Step Finance shut down after attackers compromised executive devices and drained up to $40 million from treasury-controlled assets, crypto.news reported. The company recovered about $4.7 million but said financing and acquisition talks did not produce a sustainable path forward.
Blockaid expects teams to focus more on transaction-intent checks, isolated signing devices, key segregation and monitoring across bridges and infrastructure. Those are company recommendations, not guarantees.
The next verified updates will come from Drift's recovery-token terms and relaunch schedule, Step Finance's remaining claims process, court proceedings tied to frozen KelpDAO funds and any asset seizures announced by law-enforcement agencies.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.