News archive

Security Incident Analysis

Crypto Security Losses Reach $1.1 Billion in H1 2026: Blockaid Report (not officially confirmed)

According to crypto.news, Blockaid's H1 2026 report indicates that crypto security incidents led to $1.1 billion in losses across 212 cases globally, with operational security failures surpassing smart contract bugs as the main cause. The findings are not officially confirmed and rely on media reporting. The report highlights a shift in attack patterns, with compromised keys and infrastructure now responsible for most losses. Major incidents involving KelpDAO and Drift Protocol dominated the period, and recovery efforts are ongoing. The report also notes that one DPRK-linked cluster accounted for over half of the losses.

Blockaid's H1 2026 crypto security losses report (not officially confirmed)
Image: crypto.news

Overview of Reported Losses in H1 2026

According to crypto.news, Blockaid's H1 2026 report details a record-breaking period for crypto security incidents, with $1.1 billion in losses across 212 cases globally. The report, which is not officially confirmed, suggests that the first half of 2026 saw more verified incidents than the entire year of 2025. This surge in losses reflects a significant escalation in the frequency and impact of attacks targeting crypto assets and infrastructure. The data is based on Blockaid's incident dataset, but industry estimates may vary due to differing definitions and coverage methods.

The reported losses are attributed primarily to operational security failures rather than traditional smart contract vulnerabilities. Blockaid's analysis indicates that 74% of stolen funds resulted from compromised devices, privileged credentials, private keys, signing systems, and off-chain infrastructure. This marks a departure from previous years, where code flaws were the dominant cause. The findings highlight the evolving nature of threats facing crypto exchanges and projects, emphasizing the need for robust operational controls.

Shift in Attack Patterns: Operational Security Takes Center Stage

Blockaid's report, as relayed by crypto.news, underscores a notable shift in the nature of crypto security incidents. Attacks that exploit operational weaknesses, such as compromised keys and privileged access, now account for the majority of losses. These incidents often involve attackers gaining control over authorized credentials, enabling them to execute valid-looking blockchain transactions. This method bypasses protections offered by smart contract audits, as audits cannot prevent malicious actions by compromised administrators or bridge verifiers.

The report warns that new attack vectors emerged during H1 2026, with some expected to expand in the future. The reliance on off-chain infrastructure and privileged credentials has created vulnerabilities that are difficult to address through traditional security measures. As a result, crypto exchanges and projects must adapt their risk management strategies, focusing on operational controls, key segregation, and transaction-intent verification to mitigate these evolving threats.

Major Incidents: KelpDAO and Drift Protocol

Among the reported incidents, KelpDAO and Drift Protocol stand out as the most significant cases in H1 2026. According to Blockaid's report, the KelpDAO attack was linked to North Korea's Lazarus Group, with attackers compromising internal RPC nodes and disrupting external nodes. This allowed a single-verifier system to accept a false burn event, resulting in the release of 116,500 rsETH worth approximately $292 million from a bridge contract. The Ethereum-side bridge released assets despite no corresponding tokens being destroyed on the source chain.

Drift Protocol suffered a separate privileged-access attack, where attackers used social engineering and pre-signed durable-nonce transactions to gain administrative control. The recovery update valued stolen assets at $295.7 million, higher than earlier estimates. These incidents illustrate the scale and complexity of operational security breaches, with recovery efforts ongoing and litigation processes unresolved. The affected user groups include participants in Ethereum and Solana projects, who face continued uncertainty regarding asset recovery.

Network Comparison: Ethereum and Solana

Blockaid's report, as cited by crypto.news, provides a comparative analysis of losses across Ethereum and Solana-related projects. Ethereum projects lost approximately $332 million, with code vulnerabilities responsible for much of that total. The largest Ethereum-linked case was KelpDAO, which accounted for the majority of losses. Solana projects lost about $326 million, with over 98% attributed to compromised keys and signing infrastructure rather than smart contract bugs. Drift Protocol and Step Finance were the primary contributors to Solana's losses.

The report cautions that network comparisons do not establish inherent safety differences between blockchains. Instead, they reflect which applications were targeted and how privileged access was managed. A single large incident can dominate network totals, underscoring the importance of operational security across all platforms. The findings suggest that both Ethereum and Solana projects must strengthen their controls over privileged credentials and signing systems to reduce exposure to similar attacks.

Recovery Efforts and Ongoing Risks

Recovery efforts following the reported incidents are ongoing, with affected entities implementing various strategies to mitigate losses and restore operations. KelpDAO completed the operational phase of its recovery plan, transferring a final tranche of rsETH into its bridge adapter and resuming minting, redemptions, and rewards. However, litigation and disputed claims involving frozen funds remain unresolved. Drift Protocol proposed a recovery pool supported by exchange revenue, Tether, and other partners, along with a transferable recovery token. The protocol's restart requires audits, dedicated signing devices, timelocks, and a redesigned multisig.

Despite these efforts, the thefts remain active on-chain cases, with stolen funds still in circulation. For example, a wallet tied to the Drift exploiter moved significant amounts of Ether into Tornado Cash after months of inactivity. Blockaid expects teams to focus more heavily on transaction-intent checks, isolated signing devices, key segregation, and monitoring across bridges and infrastructure. These recommendations are not guarantees, and the next verified updates will depend on recovery-token terms, relaunch schedules, claims processes, and potential asset seizures by law enforcement.

Implications for Crypto Exchanges and User Groups

The reported findings from Blockaid's H1 2026 report, as relayed by crypto.news, have significant implications for crypto exchanges, project teams, and user groups. The shift toward operational security failures as the primary cause of losses necessitates a reevaluation of risk management practices. Exchanges and projects must prioritize controls over privileged credentials, signing systems, and off-chain infrastructure. Users should be aware of the increased risks associated with compromised keys and participate in recovery processes where applicable.

The ongoing recovery and litigation efforts highlight the complexity of asset restitution in the aftermath of large-scale security incidents. Affected user groups, particularly those involved in Ethereum and Solana projects, face continued uncertainty regarding the status of their assets. The report emphasizes the importance of staying informed about recovery updates, claims processes, and potential law enforcement actions. Enhanced operational security measures and monitoring are essential to mitigate future risks and protect user assets.

Cexvia conclusion

Concrete Finding: Blockaid's Reported Losses in H1 2026 Remain Unconfirmed, Affecting Ethereum and Solana User Groups

Blockaid's H1 2026 report, as relayed by crypto.news, identifies $1.1 billion in crypto security losses across 212 incidents, with operational failures now the leading cause. These findings are not officially confirmed and remain based on media reporting. The most significant losses were linked to compromised keys and privileged access, especially in incidents involving KelpDAO and Drift Protocol. Recovery and litigation processes are ongoing, and the affected user groups include participants in Ethereum and Solana projects.

Risk meaning
The reported shift from smart contract vulnerabilities to operational security failures signals a change in the risk landscape for crypto exchanges and projects. Attackers increasingly target privileged credentials, signing systems, and off-chain infrastructure, making traditional code audits insufficient for comprehensive protection. This trend increases the risk of large-scale thefts and highlights the need for enhanced operational controls and monitoring.
User action
Users and project teams should prioritize operational security measures, including isolated signing devices, key segregation, and transaction-intent verification. Reliance solely on smart contract audits is no longer sufficient. Monitoring privileged access and off-chain infrastructure is essential, and users should stay informed about ongoing recovery efforts and potential asset seizures. Participation in recovery pools and claims processes may be necessary for affected parties.