Skip to main content

Security Firm Blockaid Says 212 Onchain Exploits Stole $1.1B as AI and Wallet Attacks Accelerate

Importance High

The first half of 2026 marked the most active period for onchain security threats on record, with security firm Blockaid verifying a 3.4-fold increase in high-threshold exploits over all of 2025. According to Blockaid’s H1 2026 Onchain Security Report, total dollar losses reached $1.1 billion, though this trailed the first half of 2025 due to the absence of a single multibillion-dollar mega-heist.

Attackers carried out 212 verified exploits during the six months, peaking in June with 57 separate incidents. Four major incidents accounted for $707 million, or 64% of total stolen funds. North Korea’s ‘Trader Traitor’ hacking cluster, tied to the Lazarus Group, was responsible for approximately $609 million of overall losses.

The period’s two largest exploits targeted restaking protocol KelpDAO ($292 million) and Solana perpetual DEX Drift Protocol ($285 million), both attributed to Trader Traitor. Rather than smart contract bugs, these attacks focused on human and operational vectors. In the Drift breach, weeks of targeted social engineering granted attackers administrative multisig control, resulting in $285 million stolen in under 12 minutes. In the KelpDAO exploit, attackers used social engineering against a LayerZero developer to poison RPC infrastructure and forge cross-chain bridge attestations.

The report highlighted three major security boundaries emerging in H1 2026: EIP-7702 wallet delegation attacks, AI prompt injection, and off-chain bridge infrastructure. A May incident saw an attacker use prompt injection to trick Bankr’s AI agent into approving an unauthorized transaction, taking $216,000.

Recovery rates varied starkly by attack vector. Stolen funds from key compromises vanished almost immediately into mixers or cross-chain bridges, while protocol bugs occasionally allowed partial or full recovery through swift white-hat coordination or contract pauses.

Looking ahead, Blockaid warns of continued pressure in H2 2026, including persistent social engineering campaigns by sanctioned nation-state actors, scaling exploits around EIP-7702 wallet delegation, and a rapid rise in prompt-injection attacks against autonomous AI trading agents as adoption grows across decentralized finance.

Source: https://news.bitcoin.com/security/security-firm-blockaid-says-212-onchain-exploits-stole-1-1b-as-ai-and-wallet-attacks-accelerate/