Cryptographic security incidents caused more than US$1 billion in losses in the first half of 2026
According to Blockaid statistics, a total of 212 security incidents occurred in the first half of 2026, and cryptographic asset losses exceeded US$1 billion. Among them, Ethereum's losses mainly stem from smart contract vulnerabilities, while Solana's attacks mostly target the loss of keys and infrastructure. Operational security breaches were responsible for most of the losses, prompting projects to strengthen key management and transaction security.
The chain security company reported that 212 incidents had been confirmed as of June, making it the highest total in six months on record. The Ethereum and Solana projects suffered the most losses, while KelpDAO suffered the largest single attack.
Ethereum and Solana face different attack patterns
According to the "Chain Security Report for the First Half of 2026" released by Blockaid, Ethereum-related projects lost approximately US$332 million during this period. Most of the losses came from code vulnerabilities, including KelpDAO, which lost approximately $292 million due to attackers exploiting bridging contract vulnerabilities.
At the same time, Solana-related projects lost approximately US$326 million. However, more than 98% of the losses originated from key and signature infrastructure failures rather than smart contract vulnerabilities.
Blockaid pointed out that Drift Protocol and Step Finance were the main sources of Solana's losses. During the reporting period, smaller code-related incidents also affected Raydium and Volo.
Operational security breaches cause most of the damage
Blockaid reported that operational security breaches accounted for 74% of the total value stolen. In addition, a North Korea-related attack cluster accounted for 55% of all recorded losses.
Reports show that attackers are increasingly targeting devices, private keys, privileged certificates and signature systems. Because attackers used infected systems to approve transactions through authorization certificates, these transactions appeared legal.
The company said traditional smart contract audits cannot prevent administrators from approving malicious transactions after attackers breach the system.
Major incident recovery efforts continue
Recovery efforts continued on multiple affected projects after the attack. KelpDAO completed the operational phase of its recovery plan on May 25, transferring the last batch of rsETH to its bridge adapters.
At the same time, Drift proposed a recovery pool supported by exchange revenue, Tether and other partners. The agreement also outlines new security measures, including dedicated signature devices, time locks, redesigned multi-signature controls, and additional audits before restarting operations.
In addition, Blockaid expects that as investigations into several major incidents continue, the infrastructure team will strengthen transaction monitoring, quarantine signature devices, key separation, and bridging security.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
SOL