
North Korean hackers responsible for two-thirds of losses; KelpDAO and Drift Protocol breaches account for $577M. Regulatory pressure likely to intensify.
The first half of 2026 set a record for the highest number of crypto security breaches. Blockaid's H1 2026 report, released July 28, counted 212 verified exploits that drained over $1.1 billion from protocols and wallets across the ecosystem.
The dollar figure fell from roughly $2.3 billion in H1 2025. That comparison is misleading. Last year's total was inflated by the single Bybit breach that wiped out $1.5 billion. Strip out that mega-hack, and this year's losses would be far worse.
North Korean hackers were responsible for about 66% of all stolen funds, TRM Labs said. The firm independently tracked 207 incidents totaling $972 million in the same period. Two breaches dominated the tally. The KelpDAO exploit cost roughly $292 million, and the Drift Protocol incident cost around $285 million. Combined, those two hacks accounted for nearly $577 million, more than half of all funds stolen. Both were attributed to DPRK-linked groups.
Infrastructure compromises, which include social engineering attacks, drove about 76% of the total value lost, Blockaid said. They represented a smaller share of total incidents. Smart contract vulnerabilities were the most common attack vector by far. TRM Labs attributed roughly 125 of its 207 incidents to smart contract exploits.
Ethereum and Solana bore the heaviest losses by chain, with $332 million and $326 million stolen respectively. The two chains together accounted for roughly $658 million in losses, about 60% of the total.
Blockaid counted 212 incidents; TRM Labs counted 207. Divide $1.1 billion by 212 exploits and the average loss is about $5.2 million per incident. In H1 2025, the average was nearly double that, inflated by the Bybit breach. The industry is now averaging more than one breach per day.
The DPRK dimension adds a layer of regulatory pressure. Groups linked to North Korea funnelling $643 million from crypto protocols gives governments more ammunition for stricter oversight, according to analysts cited by TRM Labs. The 125 smart contract exploits recorded by TRM Labs represent vulnerabilities that better engineering practices could meaningfully reduce, the firm said. Infrastructure breaches linked to North Korean social engineering, by contrast, target a smaller number of high-value victims.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.