Crypto security firm Blockaid reports over $1 billion in losses from hacks and exploits in the first half of 2026, with nearly $600 million attributed to North Korea-linked groups. Ethereum and Solana projects were among the hardest hit.
More than $1 billion in cryptocurrency was stolen from blockchain projects during the first half of 2026, according to a report from security firm Blockaid. The firm's analysis, published July 28, found that the number of confirmed incidents in the first six months of the year already surpassed the total for all of 2025, even as the overall dollar value of losses declined compared to the same period last year. The 2025 figures were skewed by the $1.5 billion Bybit exploit, which remains the largest single crypto hack on record.
Blockaid's report highlights the continued vulnerability of decentralized finance (DeFi) protocols and infrastructure, with attackers exploiting both technical weaknesses and human factors. The firm attributed nearly $600 million of the 2026 losses to hackers linked to North Korea's government. Two of the largest incidents-the $285 million Drift exploit and the $292 million KelpDAO exploit-were both traced to actors associated with the Democratic People's Republic of Korea (DPRK). In both cases, attackers reportedly used LinkedIn-based social engineering to compromise multisignature wallet signers, a method that Blockaid warns remains a persistent risk with no structural fix currently in place.
North Korea-Linked Attacks
The scale and sophistication of North Korea-linked exploits continue to raise concerns among security professionals and regulators. According to Blockaid, the two DPRK-attributed incidents accounted for two of the four largest crypto thefts in the first half of 2026. The repeated use of social engineering tactics targeting key protocol participants underscores the challenge of defending against attacks that bypass technical controls by exploiting human trust and operational processes.
Other security firms reported similar trends. Immunefi, a prominent bug bounty and security platform, counted approximately $972 million in losses across 207 incidents during the same period, while Quill Audits recorded $935.3 million lost in 87 DeFi-specific hacks. All three firms identified the first half of 2026 as the highest six-month incident count on record, even as the total dollar value of losses has declined from the 2022 peak. Immunefi noted that DeFi exploit losses in 2026 have fallen 74% from their 2022 high, suggesting that while attacks remain frequent, the average size of each incident may be decreasing.
Ethereum and Solana Most Affected
Ethereum-based projects suffered the largest aggregate losses, with Blockaid reporting $332 million stolen from protocols on the Ethereum network in the first half of 2026. Solana-based projects followed closely, losing $326 million. According to Blockaid, Ethereum losses were concentrated in high-value protocols such as restaking platforms and decentralized exchange aggregators, while Solana losses were primarily linked to attacks on signer infrastructure rather than smart contract vulnerabilities. This distinction highlights the evolving nature of attack vectors as protocols mature and security practices adapt.
Blockaid's report also identified a new area of concern: the exploitation of AI agents integrated into DeFi platforms. The first recorded incident of this type involved a $216,000 exploit targeting the Bankr platform. Blockaid estimates that AI agent deployment in DeFi is growing at a rate of roughly 10x per year and expects additional incidents in the second half of 2026. The firm warns that prompt injection, tool-use abuse, and unauthorized transaction signing are likely to become more common as AI-driven automation expands across the crypto ecosystem.
Incident Data and Market Impact
According to Blockaid, the total value lost to crypto exploits in the first half of 2026 exceeded $1 billion, with North Korea-linked incidents accounting for roughly $577 million. Immunefi and Quill Audits reported similar figures, with Immunefi tracking $972 million in losses across 207 incidents and Quill Audits recording $935.3 million across 87 DeFi hacks. The largest single incidents were the Drift and KelpDAO exploits, both attributed to DPRK-linked actors. Ethereum and Solana projects together accounted for more than $650 million in losses, with Ethereum-based protocols losing $332 million and Solana-based protocols losing $326 million during the period.
For U.S. users, investors, and developers, the persistence of large-scale exploits underscores the importance of robust security practices, including multisignature wallet management, operational security, and ongoing monitoring for social engineering threats. The growing use of AI agents in DeFi introduces new risks that may not be fully addressed by existing security frameworks. As the number and complexity of attacks increase, both technical and human factors remain critical points of vulnerability for the crypto industry.
Social engineering attacks, such as those leveraging professional networking platforms to target protocol signers, have become a favored tactic for sophisticated threat actors. Unlike purely technical exploits, these attacks often bypass code-level defenses by manipulating individuals with privileged access. Multisignature wallets, while designed to distribute control and reduce single points of failure, can still be compromised if enough signers are deceived or coerced. As DeFi protocols and infrastructure providers expand their use of automation and AI, the attack surface is likely to grow, requiring new approaches to both technical and operational security.