EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

212 security incidents occurred in the first half of 2026, resulting in losses of $1.1 billion for c

2026-08-02 12:13:47
Bookmark

First half of 2026: Cryptocurrency hacking losses exceed US$1.1 billion

The first half of 2026 became the six most active months for cryptocurrency hacking incidents on record. According to Blockaid's latest report, a total of 212 hacking incidents occurred during this period, stealing a total of US$1.1 billion.

Crypto-hacking losses exceeded US$1.1 billion in the first half of the year.

The Blockaid report shows that four major incidents involving KelpDAO, Drift, Resolv and CoW Swap caused a total of approximately US$707 million in losses. Among them, KelpDAO suffered the most-hackers stole the Ethereum reserves held by the protocol by forging cross-chain messages, worth approximately US$292 million. Drift Protocol, a perpetual contract exchange based on the Solana chain, was also hit hard, with hackers stealing $285 million in 12 minutes.

Blockaid linked the two cases to TraderTraitor, a state-funded North Korean hacking group affiliated with the larger Lazarus Group. In addition, the $32 million lost by Humanity Protocol was also traced to the same attack group. So far, total losses from North Korea-related hacking attacks have reached US$609 million, accounting for approximately 55% of all stolen funds during the period.

The frequency of attacks also continues to climb-the average monthly number of incidents soared from 18 in January to 57 in June. April became the deadliest month: Two attacks, KelpDAO and Drift Protocol, stole a combined $577 million, bringing total losses for the month to $635 million.

Blockaid pointed out that privileged key abuse was the most costly type of attack in the first half of 2026, causing approximately $790 million in losses, accounting for nearly three-quarters of all stolen funds during the period. The second most valuable attack was the unsecured coin attack, and the largest was the hacking of Resolv, which lost $80 million. But in terms of the number of attacks, code-level vulnerabilities are the most common, accounting for about four-fifths of all attacks.

New threats emerge and attack methods continue to evolve

The report lists AI agents as emerging attack targets. In May this year, hackers used a tip-injection attack to trick Bankr's AI agent into approving an unauthorized transaction, causing approximately $216,000 in losses.

Cross-chain bridges were also severely damaged. The attacker successfully bypassed KelpDAO and Taiko's target chain verification systems and carried out the intrusion by forging certificates and verification information.

In addition, security teams will face more new attacks in 2026. Blockaid identified four incidents involving the EIP-7702 wallet delegation attack-an attack that allows wallets to transfer control to smart contracts. Traditional smart contract vulnerabilities are still widespread, with data showing that there were about five related incidents in May and June, including two attacks on Aztec Connect and one intrusion on Raydium AMM V3.

Recent incidents outside the reporting period also indicate continued pressure on the encryption infrastructure. For example, on July 23, AFX Trade, BSquaredNetwork and Verus were hacked on the same day, resulting in a total loss of more than US$35 million. It is worth mentioning that Verus had been attacked about two months ago, and Blockaid attributed both incidents to the same bridge contract and similar vulnerabilities.

Financial recovery results vary depending on the type of attack. Reports show that code-related vulnerabilities can sometimes allow teams to freeze funds or negotiate refunds; in attacks involving key theft, funds often end up being transferred through currency mixers or cross-chain routes.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP