Home Latest Insights | News Blockaid H1 2026 Onchain Security Report Finds Crypto Lost $1.1B Across 212 Exploits

Blockaid H1 2026 Onchain Security Report Finds Crypto Lost $1.1B Across 212 Exploits

Blockaid H1 2026 Onchain Security Report Finds Crypto Lost $1.1B Across 212 Exploits

Blockaid, the blockchain security company protecting more than $500 billion in digital assets and screening over 500 million blockchain transactions each month.

Today released its H1 2026 Onchain Security Report, finding that the crypto security landscape is expanding beyond traditional smart contract vulnerabilities as attackers increasingly target operational systems, infrastructure dependencies, and emerging technology layers.

The report analyzed more than 212 verified exploit incidents during the first half of 2026, representing approximately $1.1 billion in losses. H1 2026 recorded the highest exploit volume by incident count, with attackers targeting a wider range of systems including smart contracts, signer infrastructure, bridge systems, wallets, and off-chain services.

While smart contract vulnerabilities remained the most common exploit type by incident count, operational security attacks, including compromised credentials, private keys, signer infrastructure, bridge infrastructure, and backend systems, accounted for approximately $789 million, or 74%, of total funds stolen.

Register for Tekedia Mini-MBA edition 20 (June 8 – Sept 5, 2026).

Register for Tekedia AI in Business Masterclass.

Join Tekedia Capital Syndicate and co-invest in great global startups.

Register for Nigeria Capital Market Masterclass.

The findings show that the largest losses in H1 2026 came from attacks targeting the systems and access controls used to operate blockchain infrastructure.

As organizations continue adopting stablecoins, tokenized assets, and onchain settlement, protecting the infrastructure and operational controls behind digital assets has become an increasingly important security priority.

The biggest crypto attacks are no longer just breaking code. They’re compromising the systems and access points that control it, said Ido Ben-Natan, Co-Founder and CEO of Blockaid. The largest incidents we analyzed this year began with compromised credentials, signer infrastructure, or operational controls.

As digital assets become part of the broader financial system, organizations need security strategies that protect the entire transaction lifecycle, from authorization to execution.

Suspected North Korea-linked Attackers Account for 55% of H1 Losses

The report found that suspected North Korea-linked threat actors accounted for approximately 55% of all exploit losses during the first half of 2026. The two largest incidents of the period were in April.

The Drift Protocol compromise and the KelpDAO / LayerZero DVN compromise — represented approximately $577 million in losses, or roughly 52% of total H1 losses. Including Humanity Protocol, which has been attributed to the same broader attacker cluster, the total reached approximately $609 million, about 55% of all H1 losses

Across these incidents, attackers relied on similar tactics, including social engineering campaigns, compromised developer or employee access, and theft of privileged signing capabilities.

The findings highlight how a small number of sophisticated threat actors can drive a significant share of industry-wide losses by targeting operational weaknesses, rather than relying solely on vulnerabilities in deployed code.

Operational Security Attacks Drive Majority of Losses

Blockaid found that operational security attacks accounted for approximately $789 million in losses during H1 2026, despite representing a smaller share of incidents than smart contract exploits. The largest operational security incidents included:

KelpDAO / LayerZero DVN compromise: A $292 million loss involving compromised infrastructure and signer access. Drift Protocol compromise: A $285 million loss involving a compromised signer environment.

Humanity Protocol compromise: A $32 million loss linked to the same broader attacker cluster behind several other operational compromises. These incidents demonstrate how attackers are increasingly targeting privileged access points used to authorize and execute transactions, rather than directly exploiting blockchain code.

Although H1 2026 losses were lower than the record-setting levels seen in 2025, the number of incidents increased significantly. Blockaid recorded 212 verified exploit incidents during H1 2026. The first half of 2026 alone represented approximately 3.4 times the full-year 2025 incident count.

A small number of large incidents continued to account for the majority of losses. The top four incidents — KelpDAO, Drift, Resolv, and CowSwap — represented approximately $707 million, or 64%, of total H1 losses. However, excluding those incidents, more than 200 additional attacks still resulted in approximately $358 million in losses.

The data shows that while mega-exploits continue to drive headlines, attackers are also targeting a broader range of protocols, applications, and infrastructure components.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here