Skip to main content

Crypto Hacks Drain $1.1B in First Half of 2026 Amid 212 Security Incidents

Importance Critical

The first half of 2026 was the most active six months for crypto exploits on record, according to a new report from Blockaid. Hackers stole $1.1 billion across 212 incidents.

Four major incidents—involving KelpDAO, Drift Protocol, Resolv, and CoW Swap—accounted for roughly $707 million of the total losses. KelpDAO suffered the largest loss at $292 million, after attackers faked a cross-chain message to drain the protocol’s Ethereum reserves. Drift Protocol, a perpetuals exchange on Solana, lost $285 million within 12 minutes.

Blockaid linked both the KelpDAO and Drift Protocol hacks to TraderTraitor, a state-sponsored North Korean subset of the Lazarus Group. Humanity Protocol’s $32 million loss was also connected to the same cluster, bringing North Korea-linked losses to $609 million—approximately 55% of all funds stolen in the period.

The pace of attacks increased through the year, with monthly incidents rising from 18 in January to 57 in June. April was the most costly month, as the KelpDAO and Drift Protocol hacks combined for $577 million in losses, pushing the monthly total to $635 million.

Privileged key misuse was the most costly attack type, causing approximately $790 million in losses—nearly three-quarters of all funds stolen. Unbacked mint exploits came second in value, led by the $80 million Resolv breach. However, code-level exploits caused the most incidents, accounting for nearly four out of five attacks by count.

New threats emerged in the period. AI agents became a target after hackers used a prompt injection attack in May to trick Bankr’s AI agent into approving an unauthorized $216,000 transaction. Cross-chain bridges also suffered major breaches, with attackers exploiting verification systems at KelpDAO and Taiko.

Security teams faced newer attack methods in 2026, including four incidents involving EIP-7702 wallet delegation attacks, where wallets can hand control to smart contracts. Legacy smart contracts remained a common vulnerability, with around five cases in May and June.

Recovery results varied by attack type. Code-related incidents sometimes allowed teams to freeze funds or negotiate returns, while attacks involving stolen keys typically ended with funds moving through mixers or cross-chain routes.

Source: https://cryptopotato.com/crypto-hacks-drain-1-1b-in-first-half-of-2026-amid-212-security-incidents/