
The first half of 2026 marked the most exploited period in blockchain history, with onchain security firm Blockaid verifying 212 incidents totalling $1.1 billion in losses — representing 3.4 times the number of high-threshold exploits recorded across all of 2025. While total dollar losses fell short of 2025’s figures, largely because no single event rivalled the $1.5 billion Bybit breach, the sheer volume and sophistication of attacks signal a structural escalation in the threat landscape.


Loss concentration remained pronounced. The four largest incidents — KelpDAO at $292M, Drift Protocol at $285M, Resolv at $80M, and CowSwap at $50.4M — collectively accounted for roughly 64% of all H1 losses. Two of these, KelpDAO and Drift, are directly attributed to TraderTraitor, a sub-group of North Korea’s Lazarus Group. Combined with the separately attributed Humanity Protocol breach of $32M, DPRK-linked actors were responsible for approximately $609 million, or 55% of the half-year total.
Compromised private keys emerged as the dominant loss driver by a wide margin, responsible for nearly $789 million — around 74% of all H1 damage — across roughly ten incidents. Both top-tier attacks began not with a contract vulnerability but with social engineering: DPRK operators targeted employees at Drift and KelpDAO through LinkedIn-style manipulation, ultimately gaining control over multisig signers and bridge verifier infrastructure. The KelpDAO breach, in particular, exploited a single-DVN configuration in the LayerZero bridge to forge a cross-chain attestation and drain $292 million from an Ethereum escrow.
Code exploits, while far less costly in aggregate at $203 million, dominated by incident count, comprising nearly 80% of all cases. Resolv’s $80 million unbacked mint was the largest in this category. A smaller but recurring pattern involved legacy or deprecated contracts that teams had migrated away from but not fully decommissioned. Five such incidents in May and June — including two separate attacks on the Aztec Connect rollup and a validation exploit on Raydium’s deprecated AMM V3 — totalled approximately $5.7 million, underscoring that migration timelines are not equivalent to sunsets.

Three novel attack vectors made their first appearances in H1. EIP-7702 wallet delegation, introduced by a new Ethereum standard, was abused across four incidents. An AI prompt injection attack on the Bankr agent in May — the first of its kind — extracted $216,000 by tricking an autonomous system into authorising an unauthorised transaction. Off-chain bridge prover infrastructure was also newly targeted, with KelpDAO and Taiko both breached through forged proofs accepted by destination chains.
Recovery outcomes proved sharply asymmetric. Code exploits sometimes yielded partial fund recovery through emergency pause functions or onchain coordination. Key compromises, by contrast, saw near-zero retrieval, with stolen assets typically routed through mixers within hours. The most successful containment of the period occurred on Stellar, where real-time wallet clustering by Blockaid enabled validators to quarantine $7.3 million — 73% of a $10.2 million oracle manipulation drain — within minutes of the attack.
The post Crypto Losses Hit $1.1B In First Half Of 2026 As DPRK Actors And New Attack Vectors Drive Record Incident Surge appeared first on Metaverse Post.