
Crypto security losses reached $1.1 billion across 212 verified incidents during the first half of 2026, according to an H1 report published by Blockaid on July 28.
Summary
- 212 verified incidents caused $1.1 billion in losses during 2026’s record-breaking first six months globally.
- 74% of stolen funds resulted from operational security failures rather than exploited smart contract code.
- One DPRK-linked cluster accounted for 55% of losses alone, according to Blockaid’s verified incident dataset.
Blockaid described the six-month incident count as a record and said it verified more exploits during H1 than throughout 2025.
Cperational security attacks caused 74% of the stolen value, while one cluster associated with the Democratic People’s Republic of Korea accounted for 55%. Blockaid also said the incident count was 3.4 times its 2025 total, though security companies use different definitions and coverage methods when compiling industry loss estimates.
Blockaid says operational failures drove crypto security losses
Blockaid’s figures point to a shift away from attacks that depend only on faulty smart-contract code. Compromised devices, privileged credentials, private keys, signing systems and off-chain infrastructure produced most of the measured losses. These attacks can generate valid-looking blockchain transactions because authorised credentials approve them.
That pattern reduces the protection offered by code audits alone. Audits can identify contract flaws, but they cannot stop a compromised administrator from signing a malicious transaction or prevent a bridge verifier from relying on poisoned infrastructure. Blockaid said new attack vectors emerged during H1 and warned that some could expand during the second half.
Ethereum and Solana suffered different attack patterns
Ethereum-related projects lost about $332 million, according to Blockaid’s report, with code vulnerabilities responsible for much of that total. The largest Ethereum-linked case was KelpDAO, where attackers released 116,500 rsETH worth roughly $292 million from a bridge contract after falsifying a source-chain message.
Solana-related projects lost about $326 million. More than 98% came from compromised keys and signing infrastructure rather than smart-contract bugs, Blockaid found. Drift Protocol and Step Finance accounted for most of that amount, while smaller code-related incidents affected projects including Raydium and Volo.
The network comparison does not establish that one blockchain is inherently safer. Instead, it reflects which applications were attacked and how their teams managed privileged access. A single large incident can also dominate a six-month network total.
KelpDAO and Drift dominated H1 theft
Chainalysis linked the April 18 KelpDAO attack to North Korea’s Lazarus Group. Its investigation found that attackers compromised internal RPC nodes and disrupted external nodes, causing a single-verifier system to accept a false burn event. The Ethereum-side bridge then released rsETH even though no corresponding tokens had been destroyed on the source chain.
As crypto.news reported, KelpDAO completed the operational phase of its recovery plan on May 25 after transferring a final 20,373.72 rsETH tranche into its bridge adapter. Minting, redemptions and rewards resumed, although litigation and disputed claims involving frozen funds remained unresolved.
Drift suffered a separate privileged-access attack on April 1. Chainalysis said attackers used months of social engineering and pre-signed durable-nonce transactions to gain administrative control. Drift’s April 16 recovery update valued stolen assets at $295.7 million, above the roughly $285 million early estimate used by Blockaid and several investigators.
In related coverage, crypto.news reported that Step Finance shut down after attackers compromised executive devices and drained up to $40 million from treasury-controlled assets. The company recovered about $4.7 million but said financing and acquisition talks did not produce a sustainable path forward.
Recovery continues while stolen funds remain active
Drift proposed a recovery pool supported by exchange revenue, Tether and other partners. Its plan included up to $127.5 million of proposed support from Tether, $20 million from other partners and a separate transferable recovery token. The protocol said its restart would require audits by OtterSec and Asymmetric, dedicated signing devices, timelocks and a redesigned multisig.
The theft remains an active on-chain case. As previously reported, a wallet tied to the Drift exploiter moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash between July 23 and July 24 after roughly three months of inactivity.
Blockaid expects teams to focus more heavily on transaction-intent checks, isolated signing devices, key segregation and monitoring across bridges and infrastructure. Those measures are company recommendations, not guarantees.
The next verified updates will come from Drift’s recovery-token terms and relaunch schedule, Step Finance’s remaining claims process, court proceedings tied to frozen KelpDAO funds and any asset seizures announced by law-enforcement agencies.
