Cryptocurrency theft and fraud losses exceed US$1 billion in the first half of 2026
According to Blockaid's security report for the first half of 2026 released on Tuesday, in the first six months of 2026, the total amount of cryptocurrency theft and fraud losses has exceeded US$1 billion. During this period, the number of cryptographic hacking incidents recorded by chain security companies also hit a half-year high.
Ethereum and Solana were the two chains with the biggest losses, losing approximately US$332 million and US$326 million respectively. Blockaid tracked a total of 212 security incidents during the six-month period, with the largest exploit involving KelpDAO, with reported losses of up to $292 million.
Core Points
Blockaid estimates that the total loss of crypto assets in the first half of 2026 exceeded US$1 billion, while its historical data also reached the highest number of hacking incidents in the first half of the year.
Ethereum led the loss (approximately US$332 million), mainly due to the exploitation of code and application layer vulnerabilities.
Solana's losses were equally severe (approximately $326 million), but the vast majority were related to private key leaks and attacks on the signature infrastructure.
The single largest incident mentioned in the report involved KelpDAO, with a loss of US$292 million.
Blockaid reported that the number of verifications for high-threshold exploit events increased sharply in the first half of 2026 compared to the whole of 2025.
Ethereum's losses highlight application-level risks
Blockaid said Ethereum suffered the most losses in security incidents in the first half of 2026, and attackers mainly targeted vulnerabilities in applications built on the network. In terms of quantity, code exploit was the main driver of the Ethereum incident. Blockaid also pointed out that several major loss incidents involved the disclosure of private keys.
Well-known incidents mentioned in the report include the Humanity Protocol and StablR attacks. CoWSwap is the only major Ethereum incident classified as user error rather than a protocol or code breach.
Blockaid describes common methods of Ethereum-related attacks, including bridging and smart contract vulnerabilities, unauthorized access to privileged accounts, and market manipulation. Although these techniques differ mechanically, they have one thing in common: high-value Ethereum apps provide attackers with a dense attack surface that allows them to find direct exploitation paths and gain privileged access.
Thereport also emphasizes that Ethereum serves as the central hub of major crypto infrastructures such as re-pledge platforms, stablecoins and decentralized exchanges. Large amounts of capital and complex integrations not only concentrate the value at risk, but also increase the probability of border situations that can be exploited.
Solana's stolen funds surge, attacks turn to private key leaks
Solana's losses in the first half of 2026 were almost equal to Ethereum. Blockaid estimates that approximately $326 million was stolen during the period, a significant jump from the approximately $127 million recorded in 2025.
One observation in the report pointed out that Blockaid CEO Ido Ben-Natan said that 63 incidents totaled US$2.58 billion in losses throughout 2025, with activity mainly concentrated in the first quarter, when Ethereum and Arbitrum were the networks with the largest financial losses.
However, Blockaid stated that Solana's deterioration in the first half of 2026 did not stem from a surge in smart contract vulnerability exploits. Instead, the leak of the private key caused more than 98% of Solana's losses, which Blockaid believes is mainly related to the Drift Protocol and Step Finance incidents. Blockaid also attributed the incidents to North Korea-linked cyber hacking groups.
This is critical because it redefines operational priorities for Solana-related infrastructure. The report pointed out that while the Ethereum incident was more related to protocol code vulnerabilities, Solana's losses were mainly related to signer infrastructure and organizational security vulnerabilities. In other words, the main threat vector during this period was not "vulnerabilities in execution" but errors in control systems and signature operations.
Blockaid points out that only a small portion of Solana's losses are related to code exploits-taking Raydium and Volo as examples-highlighting that the key to Solana's narrative in the report is key and signature security, not just on-chain contract flaws.
Changes in the threat landscape
In Blockaid's analysis of the first half of 2026, two changes are particularly prominent. First, Ethereum's risk profile still revolves around smart contract and application-layer weaknesses, where bridging, contract logic and privileged account access may be exploited. Second, although Solana's losses were comparable to Ethereum's, the main drivers were private key leaks and signature infrastructure issues-an operational and security governance issue rather than a purely software vulnerability issue.
Blockaid also reported that the number of high-threshold exploit events verified in the first half of 2026 was 3.4 times higher than in the whole of 2025. This either indicates that the attacker is pursuing a more serious, more deterministic exploitation path during this period, or that the environment (including targeting and integration) supports a higher-impact outcome. In effect, for teams protecting networks and protocols, this increases the likelihood that they will face fewer "minor problems" and more attacks that can directly lead to significant damage.
Finally, the largest single exploit reported-KelpDAO loss of $292 million-fits the overall pattern of high-value targets attracting concentrated attacks. Even if the total number of incidents changes, a few high-impact incidents may dominate the total amount of stolen funds, which is what appears in the breakdown of Blockaid's data for the first half of 2026.
Summary perspective
As losses in the first half of 2026 show, the most damaging threats are not uniform across chains: Ethereum's defenses should focus on application and privileged access security, while Solana stakeholders should make key management and resilience of the signature infrastructure a top priority. As for whether the difference between code-driven events and key-driven events will continue in the second half of 2026, and whether the number of incidents will remain high despite frequent high-threshold vulnerability exploitation activities, it deserves continued attention.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
SOL