The first half of 2026 was the most-hacked six-month period in cryptocurrency history by incident count. Security firm Blockaid's H1 report, released July 28, tallied 212 verified exploits that drained more than $1.1 billion from protocols, wallets, and infrastructure, according to Crypto Briefing's coverage of the findings. The industry now averages more than one breach per day at roughly $5.2 million per exploit, and while total dollar losses actually fell from the $2.3 billion stolen in H1 2025, that comparison flatters 2026: last year's figure was inflated by the single $1.5 billion Bybit breach.
Three security firms, three tallies, one conclusion
Blockaid is not alone in calling this a record period, though the exact numbers vary by methodology. CertiK's Hack3D report, covered by Forbes, documented $1.315 billion across 344 incidents, while TRM Labs independently tracked 207 incidents totaling $972 million. The differences come down to what each firm counts and verifies, but the direction is identical:
| Firm | H1 2026 losses | Incidents |
|---|---|---|
| Blockaid | $1.1 billion+ | 212 |
| CertiK | $1.315 billion | 344 |
| TRM Labs | $972 million | 207 |
CertiK's data also undercuts any optimism about the headline year-over-year decline. Excluding Bybit from the 2025 baseline, H1 2026 losses were roughly 28% higher on a comparable basis, and incident frequency jumped to 194 in Q2 2026 from 145 in Q2 2025. Attacks are becoming more frequent and more precise at the same time.
Is North Korea really behind most of the losses?
Largely, yes. According to The Crypto Times' analysis of the Blockaid report, Lazarus Group operatives, specifically the TraderTraitor subgroup, orchestrated roughly 55% of total H1 losses, approximately $609 million. Three major attacks carry that attribution: KelpDAO at $292 million, Drift Protocol at $285 million, and Humanity Protocol at $36 million. The two largest alone, both hit in April, account for nearly 44% of everything stolen in the half, and concentration ran even deeper than that: just four breaches, KelpDAO, Drift Protocol, Resolv, and CowSwap, collectively represented about 64% of H1 losses, roughly $707 million in total.
What makes those two breaches instructive is what they were not: neither involved a smart contract vulnerability. CertiK found that wallet and key compromise was the costliest attack vector at $444 million, averaging about $13 million per event, "by far the highest of any category," in the words of CertiK CEO Ronghui Gu. Code bugs remained the most frequent failure at 204 incidents but produced only $151.6 million in losses. As Gu put it, "a protocol can pass a flawless code audit and still lose millions because of a compromised admin key."
TRM Labs' data adds a complementary angle: smart contract vulnerabilities were still the most common attack vector by frequency, appearing in approximately 125 of its 207 recorded incidents, yet infrastructure compromises, including social engineering, were responsible for about 76% of total value lost. In other words, the attacks that happen most often and the attacks that cost the most are now different attacks.
The chain-level data tells the same story. Ethereum-related projects lost about $332 million, primarily to contract vulnerabilities, while Solana ecosystem losses hit $326 million, with over 98% stemming from compromised keys. Together the two chains absorbed roughly 60% of all losses.
July kept the pressure on
The second half of the year opened no better. On July 22, attackers drained about $24.15 million in USDC from an AFX-operated bridge on Arbitrum, converting the haul into roughly 12,467.5 ETH, per CryptoRank's reporting. It was the fourteenth significant hack of the month, pushing July's running total to about $97 million, already ahead of June's $75.32 million. Offchain Labs co-founder Steven Goldfeder was quick to clarify scope, stating that "the Arbitrum native bridge has not been hacked or exploited in any way"; the failure sat in third-party bridge infrastructure, which Blockaid identifies as one of the period's three dominant attack surfaces alongside EVM Layer-2 vulnerabilities and compromised signing infrastructure.
What actually works against surgical attackers
The H1 data points defenders toward a clear reallocation of effort:
- Key management over code audits. With roughly 76% of value lost to infrastructure and social engineering compromises rather than code flaws, multi-party signing, hardware isolation, and personnel security now matter more than another audit pass.
- Bridge skepticism. At least seven bridge exploits in H1, plus the July AFX incident, confirm that cross-chain infrastructure remains the sector's most reliable failure point.
- Rapid response capability. Recovery is possible when detection is fast: Blockaid assisted in quarantining $7.3 million during the Stellar Blend incident, roughly 73% of the stolen assets.
- New attack surfaces. Both CertiK and Blockaid flag AI agents with wallet access as an emerging target class heading into the second half.
The uncomfortable summary of H1 2026 is that the industry has largely won the battle it spent a decade fighting, and is losing a different one. Smart contract security has matured to the point where code bugs, though frequent, yield relatively little. What has replaced them is patient, well-resourced targeting of people and keys, dominated by a state actor that treats crypto theft as a revenue program. With 212 verified exploits in six months and a state-sponsored group responsible for more than half the money taken, the sector's security problem is no longer primarily a software problem. Until operational security across exchanges, protocols, and bridge operators catches up with the sophistication of TraderTraitor, record incident counts look less like an anomaly and more like the new baseline.
