Crypto projects lost more than $1 billion to hacks during the first half of 2026, while the number of verified exploits surpassed Blockaid’s full-year 2025 count, according to a report released Tuesday by the security firm. The findings place H1 2026 as the “most-hacked half-year on record” by incident volume, even though total dollar losses remained below the previous year’s figure.
Blockaid attributed the lower year-on-year value largely to the exceptional scale of the $1.5 billion Bybit exploit recorded in 2025. Without an incident of that size in the first six months of 2026, losses were more dispersed across a larger set of attacks, exposing a security environment where breaches are becoming more frequent rather than simply dominated by one catastrophic theft.
North Korea-linked groups accounted for nearly $600 million of the funds stolen during the period, Blockaid said. The firm linked the $285 million Drift exploit and the $292 million KelpDAO exploit to Democratic People’s Republic of Korea, or DPRK, actors. Together, those two incidents represent more than half of the losses cited in Blockaid’s H1 estimate.
North Korean groups dominate losses
The concentration of funds attributed to DPRK-linked operators reinforces a pattern seen across cryptocurrency security reporting in recent years: state-backed groups have the resources and patience to pursue high-value targets, particularly where a compromise gives them access to large pools of onchain assets.
Blockaid said social engineering conducted through LinkedIn was a repeated entry point during the first half. Attackers used the professional-networking platform to target people with access to multisignature wallets, or multisigs. These wallets require approval from multiple authorized signers before assets can move, a safeguard designed to prevent a single compromised key from emptying a treasury.
The defense weakens sharply when attackers gain access to enough signers, or persuade an authorized participant to approve a malicious transaction. Blockaid said LinkedIn-led social engineering and multisig signer compromise were involved in two of the four largest incidents it tracked in H1.
That method shifts the attack surface away from purely technical flaws in smart contracts. A protocol may have code that has passed audits, yet remain exposed if the people controlling operational wallets, deployments, upgrades, or treasury transfers can be manipulated. The report expects attacks associated with North Korea to continue.
Estimates differ, but incident counts are rising
Industry loss figures vary because security firms apply different standards for identifying incidents, pricing stolen assets, and deciding whether to include categories such as phishing, private-key theft, or protocol exploits.
Immunefi reported approximately $972 million in losses across 207 hack incidents during H1 2026. Quill Audits separately estimated that $935.3 million was stolen in 87 decentralized-finance hacks over the same period. Blockaid’s figure exceeded $1 billion and included more verified exploit incidents than it had recorded in the whole of 2025.
Despite those methodological differences, the reports point in the same direction on attack frequency. Immunefi also described the first half of 2026 as the highest six-month period on record for incident count.
The rise in incidents has occurred alongside a longer-term reduction in DeFi exploit losses from their prior peak. Immunefi said losses so far in 2026 were down 74% from 2022 levels. That comparison suggests that the sector has reduced some of the conditions that enabled the largest historical protocol failures, while attackers have found more opportunities to exploit credentials, operational processes, and less visible infrastructure.
Ethereum and Solana face different attack patterns
Blockaid identified Ethereum and Solana as the two networks with the largest losses in its data set, at $332 million and $326 million, respectively.
On Ethereum, the firm attributed losses primarily to major code exploits affecting protocols with substantial value locked or routed through them. Restaking platforms, stablecoin systems, and decentralized-exchange aggregators were among the areas it identified. These categories often combine complex smart-contract logic with large and rapidly moving pools of assets, raising the cost of a successful vulnerability.
Solana’s losses reflected a different security problem, Blockaid said. Rather than concentrating mainly on contract-code flaws, attackers targeted signer infrastructure. That can include the systems, devices, applications, and procedures through which wallet owners or organizational signers authorize transactions.
The contrast matters for teams assessing their defenses. Smart-contract audits and formal code reviews can address vulnerabilities in protocol logic, but they cannot protect an organization whose signing environment has been compromised. Treasury controls, hardware-backed signing, separation of responsibilities, transaction simulation, and strict approval policies become especially relevant where a small group controls high-value wallets.
AI agents add a new security target
Blockaid also forecast more exploits involving artificial intelligence agents during the second half of 2026. The firm cited Bankr’s $216,000 exploit as the first incident of its kind and said AI-agent deployment is expanding at an estimated annual pace of roughly tenfold.
AI agents are software systems designed to take actions on a user’s behalf, potentially including interacting with applications, calling external tools, and signing blockchain transactions. Their growing use creates a new set of failure points if an attacker can alter the instructions an agent receives or steer it toward an unsafe action.
Blockaid expects prompt injection to lead AI-related attacks in the coming months. Prompt injection occurs when malicious text or content causes an AI system to disregard intended instructions. The firm also identified tool-use abuse and unauthorized signing as likely attack paths.
The forecast does not mean every AI-enabled wallet or application is exposed by default. It does place pressure on projects deploying autonomous or semi-autonomous tools to limit what those systems can access, isolate sensitive signing permissions, and require human review for high-value transfers.
The first-half numbers show a market in which a billion-dollar loss total no longer depends on a single extraordinary breach. More incidents, social engineering against signers, and emerging AI-related attack paths are pushing security decisions beyond smart-contract code and into the everyday systems used to control wallets and approve transactions.
Worried about rising exploits? Learn how to harden wallets and stay safe in our guide on crypto safety standards.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

