Blockchain security firm Blockaid has published its half-year assessment, and the headline number is stark: crypto projects lost more than $1 billion across a record count of exploit incidents in the first six months of 2026. The firm verified more individual attacks in that period than it did across the entirety of 2025.
Nearly $600 million of that total went to North Korea-linked actors, according to the report, making a single state programme responsible for something close to half of all losses. DPRK-linked groups carried out both the $285 million Drift exploit and the $292 million KelpDAO exploit, two of the largest single incidents of the year.
The figures vary by source, as they usually do in this field. Immunefi placed total H1 losses at $972 million and Quill Audits at $935.3 million, both slightly below Blockaid’s estimate. The differences reflect methodology, particularly which incidents get counted and how contested attributions are handled, so the honest framing is roughly $1 billion rather than a precise figure.
For context, Fortune noted that even the higher estimates represent less than half the $2.3 billion stolen in the first half of 2025. Total losses are down. Incident frequency is up. Both things are true, and the combination is worth understanding.
The Attack Surface Has Shifted
The most useful detail in the report is not the total but the breakdown by chain, because it reveals two distinct failure modes.
Ethereum projects suffered the highest losses at $332 million, driven primarily by protocol code vulnerabilities. These are bugs in smart contract logic, the classic DeFi exploit where an attacker finds a flaw in how a contract handles state, accounting or permissions and drains it.
Solana projects lost $326 million, but through a different route: signer infrastructure attacks. Rather than breaking code, attackers compromised the people and systems authorising transactions.
That distinction matters because the second category is where North Korea has concentrated. Blockaid attributes DPRK-linked attacks primarily to social engineering schemes against multisig signers. A multisignature wallet requires several independent parties to approve a transaction, which is precisely the design meant to prevent a single compromised key from causing catastrophe. It works well against technical attacks. It works considerably less well when the attacker persuades multiple signers to approve something they should not.
This is the same pattern that produced the largest thefts on record. The February 2025 Bybit hack, worth roughly $1.5 billion, involved compromising the signing process rather than the underlying cryptography. The lesson keeps arriving and keeps not being absorbed: the maths holds, and the humans operating it are the reliable target.
The AI Warning
Blockaid’s forward-looking projection is the part most worth flagging, and it concerns a category that barely existed a year ago.
The firm projects a rise in artificial intelligence-related exploits in the second half of 2026, citing the roughly $216,000 exploit of Bankr as an early example. That incident involved an attacker granting an AI agent transfer permissions through an NFT, then hiding a malicious instruction inside a Morse code message. The agent decoded the message, treated it as a legitimate command and executed the transfer.
Nothing was hacked in any conventional sense. Every step was a valid, permitted action. The failure was that a system converting natural language into financial transactions had no meaningful check on whether an instruction it received was one it should follow.
As more protocols connect AI agents to wallets, treasury operations and automated execution, that category of failure scales. An attacker no longer needs to find a vulnerability in code; they need to construct an input that a language model will faithfully obey. Blockaid’s projection is that this becomes a material loss category rather than a curiosity within months.
Why the Totals Fell While Incidents Rose
The divergence between falling dollar losses and rising incident counts is genuinely informative.
Part of it is price. Crypto asset values are substantially lower than in the first half of 2025, so an identical theft in token terms produces a smaller dollar figure. Bitcoin has fallen from six figures to the low $60,000s, and most altcoins have fared worse.
Part of it is that the largest single incidents have not repeated. The 2025 total was inflated by the Bybit hack alone. Nothing in 2026 has approached that scale, though Drift and KelpDAO at roughly $290 million each came closer than most.
But the rising incident count points to something less encouraging: the attack surface is broadening. More protocols, more bridges, more cross-chain infrastructure and more automated systems mean more independent points of failure, each individually smaller but collectively numerous. The industry is losing less money in more places, which is a different problem from losing more money in fewer.
What It Means
The practical implications differ by audience, and they are reasonably clear.
For protocol teams, the report is a direct argument for spending on operational security rather than only on code audits. A smart contract audit will not catch a compromised signer, and signer infrastructure accounted for the largest chunk of Solana losses. That means hardware-enforced signing, transaction simulation before approval, rigorous verification of who is requesting what, and treating any unusual request from a known contact as suspect by default. Social engineering succeeds because it exploits trust between colleagues, not gaps in code.
For users, the exposure is mostly indirect. Individuals were not the primary target of these attacks; protocols and their signers were. But funds sitting in a protocol are exposed to that protocol’s operational security, which users cannot inspect. Concentration risk in any single DeFi platform carries a component that no amount of personal security hygiene addresses.
For the industry more broadly, the persistence of North Korean operations is the most difficult element. Roughly $600 million in six months, against cumulative DPRK-linked thefts approaching $7 billion since 2019, represents a sustained state programme that ordinary security improvements have not deterred. Senator Cynthia Lummis has begun framing the stalled CLARITY Act as a tool against exactly this, pointing to provisions that would let exchanges freeze suspicious funds before obtaining court orders. Whether legislation closes that gap is unresolved, but the enforcement problem is not going away on its own.
The honest summary is that crypto security in 2026 is failing in more places and losing less money, while a single state actor takes half of what is lost. None of those three facts is comfortable.
FAQ
How much did crypto lose to hacks in the first half of 2026?
Blockaid reported losses exceeding $1 billion across a record number of individual exploit incidents, verifying more separate attacks in six months than in all of 2025 combined. Other firms put the total slightly lower: Immunefi at $972 million and Quill Audits at $935.3 million, with differences reflecting methodology. All estimates are below the $2.3 billion stolen in the first half of 2025, partly because asset prices are lower and no single incident matched the scale of the $1.5 billion Bybit hack.
How much did North Korea take?
DPRK-linked actors accounted for nearly $600 million, close to half the total, according to Blockaid. They carried out both the $285 million Drift exploit and the $292 million KelpDAO exploit. Their primary method was social engineering against multisignature signers rather than exploiting code vulnerabilities, meaning they targeted the people authorising transactions instead of the contracts executing them.
Which chains lost the most and why?
Ethereum projects lost the most at $332 million, primarily through protocol code vulnerabilities in smart contracts. Solana projects lost $326 million, but mainly through signer infrastructure attacks, where attackers compromised transaction authorisation processes rather than code. The distinction matters because code audits do not protect against compromised signers, which requires operational security measures like hardware-enforced signing and transaction simulation.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.



















