EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Crypto hacker losses in the first half of 2026: Ethereum and Solana accounted for the highest propor

2026-07-29 18:33:12
Bookmark

Cryptocurrency theft and fraud losses exceed US$1 billion in the first half of 2026

According to Blockaid's security report for the first half of 2026 released on Tuesday, in the first six months of 2026, the total amount of cryptocurrency theft and fraud losses has exceeded US$1 billion. During this period, the number of cryptographic hacking incidents recorded by chain security companies also hit a half-year high.

Ethereum and Solana were the two chains with the biggest losses, losing approximately US$332 million and US$326 million respectively. Blockaid tracked a total of 212 security incidents during the six-month period, with the largest exploit involving KelpDAO, with reported losses of up to $292 million.

Core Points

Blockaid estimates that the total loss of crypto assets in the first half of 2026 exceeded US$1 billion, while its historical data also reached the highest number of hacking incidents in the first half of the year.

Ethereum led the loss (approximately US$332 million), mainly due to the exploitation of code and application layer vulnerabilities.

Solana's losses were equally severe (approximately $326 million), but the vast majority were related to private key leaks and attacks on the signature infrastructure.

The single largest incident mentioned in the report involved KelpDAO, with a loss of US$292 million.

Blockaid reported that the number of verifications for high-threshold exploit events increased sharply in the first half of 2026 compared to the whole of 2025.

Ethereum's losses highlight application-level risks

Blockaid said Ethereum suffered the most losses in security incidents in the first half of 2026, and attackers mainly targeted vulnerabilities in applications built on the network. In terms of quantity, code exploit was the main driver of the Ethereum incident. Blockaid also pointed out that several major loss incidents involved the disclosure of private keys.

Well-known incidents mentioned in the report include the Humanity Protocol and StablR attacks. CoWSwap is the only major Ethereum incident classified as user error rather than a protocol or code breach.

Blockaid describes common methods of Ethereum-related attacks, including bridging and smart contract vulnerabilities, unauthorized access to privileged accounts, and market manipulation. Although these techniques differ mechanically, they have one thing in common: high-value Ethereum apps provide attackers with a dense attack surface that allows them to find direct exploitation paths and gain privileged access.

The

report also emphasizes that Ethereum serves as the central hub of major crypto infrastructures such as re-pledge platforms, stablecoins and decentralized exchanges. Large amounts of capital and complex integrations not only concentrate the value at risk, but also increase the probability of border situations that can be exploited.

Solana's stolen funds surge, attacks turn to private key leaks

Solana's losses in the first half of 2026 were almost equal to Ethereum. Blockaid estimates that approximately $326 million was stolen during the period, a significant jump from the approximately $127 million recorded in 2025.

One observation in the report pointed out that Blockaid CEO Ido Ben-Natan said that 63 incidents totaled US$2.58 billion in losses throughout 2025, with activity mainly concentrated in the first quarter, when Ethereum and Arbitrum were the networks with the largest financial losses.

However, Blockaid stated that Solana's deterioration in the first half of 2026 did not stem from a surge in smart contract vulnerability exploits. Instead, the leak of the private key caused more than 98% of Solana's losses, which Blockaid believes is mainly related to the Drift Protocol and Step Finance incidents. Blockaid also attributed the incidents to North Korea-linked cyber hacking groups.

This is critical because it redefines operational priorities for Solana-related infrastructure. The report pointed out that while the Ethereum incident was more related to protocol code vulnerabilities, Solana's losses were mainly related to signer infrastructure and organizational security vulnerabilities. In other words, the main threat vector during this period was not "vulnerabilities in execution" but errors in control systems and signature operations.

Blockaid points out that only a small portion of Solana's losses are related to code exploits-taking Raydium and Volo as examples-highlighting that the key to Solana's narrative in the report is key and signature security, not just on-chain contract flaws.

Changes in the threat landscape

In Blockaid's analysis of the first half of 2026, two changes are particularly prominent. First, Ethereum's risk profile still revolves around smart contract and application-layer weaknesses, where bridging, contract logic and privileged account access may be exploited. Second, although Solana's losses were comparable to Ethereum's, the main drivers were private key leaks and signature infrastructure issues-an operational and security governance issue rather than a purely software vulnerability issue.

Blockaid also reported that the number of high-threshold exploit events verified in the first half of 2026 was 3.4 times higher than in the whole of 2025. This either indicates that the attacker is pursuing a more serious, more deterministic exploitation path during this period, or that the environment (including targeting and integration) supports a higher-impact outcome. In effect, for teams protecting networks and protocols, this increases the likelihood that they will face fewer "minor problems" and more attacks that can directly lead to significant damage.

Finally, the largest single exploit reported-KelpDAO loss of $292 million-fits the overall pattern of high-value targets attracting concentrated attacks. Even if the total number of incidents changes, a few high-impact incidents may dominate the total amount of stolen funds, which is what appears in the breakdown of Blockaid's data for the first half of 2026.

Summary perspective

As losses in the first half of 2026 show, the most damaging threats are not uniform across chains: Ethereum's defenses should focus on application and privileged access security, while Solana stakeholders should make key management and resilience of the signature infrastructure a top priority. As for whether the difference between code-driven events and key-driven events will continue in the second half of 2026, and whether the number of incidents will remain high despite frequent high-threshold vulnerability exploitation activities, it deserves continued attention.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP