Blockchain security
Crypto Hacks Reach Record High in H1 2026, Blockaid Reports Over $1 Billion Lost
According to Blockaid, the first half of 2026 saw the highest number of crypto hack incidents ever recorded, with losses exceeding $1 billion. Although the dollar amount was lower than the previous year due to the absence of a single large exploit, the frequency of attacks reached unprecedented levels. North Korea-linked hackers were reportedly responsible for the largest share of stolen funds. Blockaid also anticipates a rise in artificial intelligence-related exploits in the coming months. All findings are based on media reporting and are not officially confirmed.

Record Number of Crypto Hacks in H1 2026
Blockaid, as reported by LBank News and originally sourced from theblock.co, stated that the first half of 2026 marked the highest number of crypto hack incidents ever recorded. The report emphasized that the surge in incidents was not necessarily reflected in the total dollar value stolen, which remained below the previous year's figure due to the absence of a single large exploit like the $1.5 billion Bybit hack in 2025. Instead, the focus was on the frequency and diversity of attacks, which reached unprecedented levels. This trend suggests that the crypto ecosystem is facing increasingly sophisticated and frequent threats, requiring a reevaluation of security practices across the industry.
Blockaid verified more exploit incidents in the first six months of 2026 than in all of 2025, underscoring the growing challenge for blockchain security. The report highlighted that the rise in hack incidents was driven by both targeted attacks on high-value protocols and opportunistic exploits across various platforms. The data, while not officially confirmed, points to a need for enhanced vigilance and proactive measures among crypto projects and exchanges. The findings also indicate that the industry must adapt to evolving attack vectors, including those leveraging social engineering and advanced technical vulnerabilities.
Financial Impact and Chain-Specific Losses
Blockaid reported that crypto projects lost more than $1 billion to hacks during the first half of 2026. While this figure is substantial, it is lower than the previous year's total, which was inflated by the Bybit exploit. The losses were distributed across multiple chains, with Ethereum and Solana bearing the brunt. According to Blockaid, Ethereum projects lost approximately $332 million, while Solana projects lost $326 million. The concentration of losses on these chains reflects their prominence and the high value of protocols operating on them.
The report attributed the high losses on Ethereum to the presence of mega code exploits targeting protocols such as restaking, stablecoins, and DEX aggregators. In contrast, Solana attackers focused on signer infrastructure rather than contract code, indicating a shift in attack strategies. These findings, though not officially confirmed, highlight the need for chain-specific security enhancements. The data also suggests that attackers are adapting their methods to exploit the unique vulnerabilities of different blockchain ecosystems.
Role of North Korea-Linked Hackers
Blockaid's report, as cited by LBank News, identified North Korea-linked hackers as responsible for the largest share of stolen funds during H1 2026. Specifically, Blockaid attributed both the $285 million Drift exploit and the $292 million KelpDAO exploit to actors associated with the Democratic People's Republic of Korea (DPRK). These incidents accounted for nearly $600 million in losses, underscoring the significant impact of state-linked cybercrime on the crypto sector.
The report further noted that the working pattern of LinkedIn-based social engineering leading to multisig signer compromise was a key factor in two of the four largest incidents. Blockaid stated that there is no structural reason for this attack vector to cease, suggesting that similar exploits may persist. While these findings are based on media reporting and not officially confirmed, they highlight the ongoing threat posed by sophisticated, organized hacking groups and the need for robust defenses against social engineering tactics.
Comparison with Other Reports and Industry Trends
Blockaid's statistics differ from those reported by Immunefi and Quill Audits. Immunefi's June 2026 Ecosystem Update stated that cryptocurrency projects lost approximately $972 million across 207 hack incidents during the first half of the year, while Quill Audits found $935.3 million lost across 87 DeFi hacks. Despite variations in reported figures, all sources agree that the number of incidents reached a record high. Immunefi also noted that DeFi exploit losses in 2026 have fallen 74% from their 2022 peak, indicating some improvement in loss mitigation despite the high frequency of attacks.
The discrepancy in loss figures highlights the challenges of accurately tracking and reporting crypto hack incidents. Different methodologies, definitions of incidents, and scope of coverage contribute to variations in reported data. While Blockaid's report is not officially confirmed, it aligns with broader industry observations regarding the increasing frequency of attacks and the evolving nature of threats. The consensus among multiple sources underscores the urgency for improved security measures and more transparent reporting standards in the crypto sector.
Emerging Threats: Artificial Intelligence-Related Exploits
Blockaid predicts that the number of artificial intelligence-related exploits will likely increase in the coming months. The report cited Bankr's $216,000 exploit as the first known AI agent incident, noting that agent deployment is growing rapidly, with an estimated tenfold increase per year. Blockaid expects multiple AI agent incidents in the second half of 2026, with prompt injection, tool-use abuse, and unauthorized signing identified as leading attack vectors.
The rise of AI-related exploits represents a new frontier in blockchain security. As AI agents become more integrated into crypto protocols and infrastructure, attackers are likely to develop novel methods to compromise these systems. While these predictions are based on media reporting and not officially confirmed, they signal the need for proactive risk assessment and the development of specialized defenses against AI-driven threats. Crypto projects should prioritize monitoring and securing AI components to mitigate potential vulnerabilities.
Recommendations and Industry Response
In light of the reported surge in hack incidents and evolving attack vectors, Blockaid recommends that crypto projects and exchanges strengthen their security protocols. Enhanced multisig protections, regular audits, and improved incident reporting are essential to mitigate risks. The report also emphasizes the importance of user education, particularly regarding social engineering tactics that have proven effective in compromising multisig signers. While these recommendations are based on media reporting and not officially confirmed, they reflect best practices for safeguarding assets and maintaining trust in the crypto ecosystem.
Industry stakeholders are urged to collaborate on developing standardized security frameworks and sharing threat intelligence. The increasing sophistication of attacks, including those linked to state actors and AI agents, requires a coordinated response. Crypto exchange users should remain vigilant, monitor security advisories, and exercise caution when interacting with new protocols or AI-driven tools. As the landscape evolves, proactive measures and transparent communication will be critical to minimizing losses and ensuring resilience.
Cexvia conclusion
Concrete Finding and Next Steps
Blockaid's report, not officially confirmed, indicates that crypto projects experienced a record number of hacks in H1 2026, with losses surpassing $1 billion. North Korea-linked actors were reportedly responsible for the largest share of stolen funds, and the trend of increasing AI-related exploits is expected to continue.
- Risk meaning
- The reported surge in crypto hacks during H1 2026, especially those attributed to North Korea-linked actors and emerging AI-related threats, highlights significant vulnerabilities in blockchain security. The frequency and sophistication of attacks suggest that both centralized and decentralized projects face heightened risks, requiring urgent attention to security protocols and incident response strategies.
- User action
- Crypto exchange users and project operators should closely monitor security advisories, update their protocols, and remain vigilant against social engineering and AI-related threats. Enhanced multisig protections, regular audits, and prompt incident reporting are recommended. Users should be aware that these findings are based on media reports and not officially confirmed, so caution is advised when making decisions based on this information.

