In the first half of 2026, there were 212 cryptocurrency vulnerability attacks, resulting in losses of approximately US$1.1 billion.
According to a report released by security company Blockaid, in the first half of 2026, cryptocurrency projects lost approximately US$1.1 billion in 212 confirmed vulnerability attacks. This marks the highest level of attack incidents in six months on record, with a 3.4-fold increase in the number of vulnerability attacks compared to the full year of 2025.
Major incidents and total losses
The total dollar value of stolen assets was lower than the previous year, mainly due to the lack of single major thefts such as the $1.5 billion loss suffered by Bybit in February 2025. In 2026, the four largest single incidents affecting KelpDAO, Drift Protocol, Resolv and CowSwap combined caused approximately US$707 million in losses, accounting for 64% of total losses during the period.
Specific incidents include: KelpDAO loss of US$292 million (occurred in April, caused by organizations associated with North Korea);Drift Protocol loss of US$285 million (occurred in April, caused by organizations associated with North Korea);Resolv suffered a loss of unknown amount in 2026;CowSwap suffered a loss of unknown amount in 2026.
Excluding these major cases, the remaining more than 200 vulnerability attacks caused approximately US$358 million in losses, highlighting the trend of small and medium-sized but frequent attacks in the cryptocurrency ecosystem.
Attack methods and security risks
Blockaid pointed out that operational security vulnerabilities-such as disclosure of private keys, damage to signer infrastructure, attacks on bridging protocols and breaches of backend systems-are the main causes of damage. Although smart contract vulnerabilities account for the majority of incidents, these operational security attacks caused approximately $789 million in losses, accounting for 74% of the total stolen funds.
For institutions exploring tokenized assets and on-chain clearing, due diligence now focuses not only on contract audits, but also on key management and transaction authorization processes. The report notes that the nature of threats is changing, with attackers increasingly exploiting human and infrastructure weaknesses rather than just code flaws.
Role played by North Korea-linked participants
About 55% of first-half losses were related to North Korea-linked participants. Blockaid attributed the attacks on KelpDAO and Drift Protocol, valued at $292 million and $285 million respectively, and occurred 17 days apart, to groups linked to the Democratic People's Republic of Korea. The same attackers were also linked to the $32 million vulnerability attack on Humanity Protocol. The company highlighted that LinkedIn's social engineering activities, which ultimately lead to the intrusion of multiple signers, were a common entry point for these attacks, and expected this technique to continue in future incidents.
Cross-chain messaging protocol developer LayerZero specifically pointed out that the KelpDAO bridging attack was carried out by North Korea's Lazarus Group. In this attack, the attacker manipulated a single validator configuration and forged a cross-chain message. Drift Protocol's post-mortem analysis showed that it was a carefully planned intelligence operation that lasted for six months, including offline meetings with project contributors.
Network distribution and new attack methods
The Ethereum-based project suffered approximately US$332 million in explosion-related losses, mainly due to code vulnerabilities; while the Solana-based project lost approximately US$326 million, of which more than 98% can be traced to key theft and signature environment intrusion. Blockaid observed an increase in new attacks, including the first case where an artificial intelligence agent was manipulated to approve unauthorized transactions, resulting in a loss of $216,000 to the Bankr project. The report also mentioned abuse of the EIP-7702 wallet delegation mechanism. In the StellarBlend attack, Blockaid's tracking work helped sequester approximately $7.3 million in funds after the event.
LinkedIn based social engineering led to the breach of multiple signers in two of the four largest cases this year, and similar tactics are expected to continue to target critical infrastructure.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
SOL