Crypto security losses H1 2026 reached $1.1 billion across 212 verified incidents, with a single North Korea-linked cluster responsible for 55% of that total, according to the Blockaid H1 2026 report published on 28 July. The incident count was 3.4 times Blockaid’s full-year 2025 total, which the firm described as a record for any six-month period.
A separate Immunefi report, issued at the end of June, also identified the highest-ever incidence of crypto hacks over a six-month stretch, corroborating the record-high finding, according to Yahoo Finance.
Operational failures, not code bugs, drove crypto security losses H1 2026
Seventy-four percent of stolen value came from operational security failures: compromised private keys, poisoned signing infrastructure, privileged-credential abuse, and corrupted off-chain systems. Smart-contract code vulnerabilities accounted for the remainder. Code audits can catch contract flaws; they cannot stop an attacker who has already obtained administrator credentials.
DPRK-linked actors stole nearly $600 million of the H1 total, with social engineering against multisig signers as the primary vector, according to the Investing News Network summary of Blockaid’s findings. That figure pushes the cumulative DPRK crypto haul to $6.75 billion since tracking began, per yellow.com’s analysis citing Chainalysis data.
KelpDAO: poisoned nodes and a three-minute near-miss
Ethereum-related projects lost about $332 million in H1. The KelpDAO bridge exploit on 18 April accounts for most of that figure.
Attackers compromised internal RPC nodes so that those nodes reported rsETH burns on the source chain (Unichain) that never occurred. The LayerZero DVN (decentralised verification network), reading only from those poisoned nodes, confirmed the fraudulent cross-chain message as valid, and the Ethereum-side bridge released 116,500 rsETH worth roughly $292 million, according to the Chainalysis blog.
LayerZero attributed the attack to Lazarus Group’s TraderTraitor subunit. Blockchain security firm Cyvers reported that attackers came within three minutes of draining a further $100 million before a rapid blacklist cut them off, according to Yahoo Finance reporting on LayerZero’s analysis. The shock to DeFi confidence was immediate: more than $10 billion in withdrawals left Aave in the aftermath.
At the time of the exploit, KelpDAO’s TVL exceeded $1.6 billion, and the 116,500 rsETH released represented approximately 18% of KelpDAO’s entire circulating rsETH supply, according to QuillAudits’ hack analysis. KelpDAO completed the operational phase of its recovery plan on 25 May. Minting, redemptions and rewards have resumed; litigation over frozen funds is ongoing.
Drift Protocol: 31 withdrawals in 12 minutes
Solana-related projects lost about $326 million in H1. More than 98% stemmed from compromised keys and signing infrastructure rather than smart-contract bugs, with Drift Protocol and Step Finance accounting for the bulk.
The Drift exploit on 1 April involved a zero-timelock 2-of-5 multisig installed five days before the attack. Attackers used months of social engineering and pre-signed durable-nonce transactions to gain administrative control, then executed 31 withdrawals in roughly 12 minutes, according to Blockhead. Drift’s own recovery update valued stolen assets at $295.7 million, above the roughly $285 million early estimate used by Blockaid and several investigators. The protocol’s TVL fell from $550 million to roughly $230 million immediately after the exploit, and the DRIFT governance token dropped over 30%, according to BeInCrypto.
Drift’s recovery financing package totals up to nearly $150 million, structured as a $100 million revenue-linked credit facility, an ecosystem grant, and loans to market makers, with Tether as lead backer, according to DL News. USDT replaces USDC as the protocol’s settlement asset on relaunch. The protocol had more than 128,000 users and 35 ecosystem partners before the exploit.
The case remains active on-chain. A wallet tied to the Drift exploiter moved 23,095.1 ETH, worth about $44.4 million, into Tornado Cash between 23 and 24 July after roughly three months of inactivity.
What the second half of 2026 depends on
Blockaid flagged new attack vectors that emerged during H1 and warned some could expand in H2. Its recommendations centre on transaction-intent verification, isolated signing devices, key segregation, and dedicated bridge monitoring. These are mitigations, not guarantees.
The immediate catalysts to watch: Drift’s recovery-token terms and relaunch schedule (which requires audits by OtterSec and Asymmetric, timelocks, and a redesigned multisig), Step Finance’s remaining claims process, court proceedings over frozen KelpDAO funds, and any law-enforcement asset seizures tied to DPRK-linked wallets. Given that DPRK actors have now accumulated $6.75 billion and are still actively moving funds, the seizure question is not hypothetical.
