Crypto security had its worst first half on record by one important measure. Blockchain security firm Blockaid reported that more than $1.1 billion was stolen across 212 separate incidents in the first six months of 2026, the highest incident count it has recorded for any half-year.

The headline dollar figure is large, but the more useful story is in the breakdown: a small number of protocol exploits did most of the damage, state-linked groups remained the dominant threat, and the number of attacks rose sharply even as total losses stayed below the previous year. Each of those points matters for how holders and builders think about risk in the second half of the year.

A few incidents did most of the damage

Losses in crypto theft are almost never evenly distributed, and H1 2026 followed that pattern. Blockaid reported that the four largest incidents alone, KelpDAO ($292 million), Drift Protocol ($285 million), Resolv and CowSwap, accounted for roughly $707 million, or about 64% of the total.

That concentration has a practical implication. The tail of small phishing scams and minor contract bugs is loud and constant, but the number that moves the annual total is a handful of failures at larger protocols. A holder trying to manage exposure gets more protection from avoiding concentration in any single unaudited or newly launched protocol than from chasing every low-level scam alert.

State-linked groups stayed dominant

Blockaid attributed a significant share of the half-year total to North Korea-linked activity, specifically the TraderTraitor subgroup associated with the Lazarus Group. The firm tied the KelpDAO, Drift Protocol and Humanity Protocol exploits, together worth about $609 million, to that cluster, roughly 55% of all reported losses.

This continues a multi-year pattern in which a state-backed operation, rather than opportunistic individual hackers, sits behind the biggest single thefts. It also shapes what “security” means at the protocol level. Defending against a well-resourced, persistent group that targets keys and infrastructure is a different problem from stopping a one-off smart-contract bug, and it tends to reward operational discipline, such as key management and access controls, as much as code audits.

The attack surface: bridges, layer-2s and keys

On method, Blockaid pointed to three leading attack vectors: cross-chain bridges, exploits on Ethereum layer-2 networks, and compromised private keys. None of these is new, and that is part of the point. The industry has known for years that bridges concentrate value and complexity in one place, and that key compromise bypasses otherwise sound contract logic entirely.

By ecosystem, the report put Ethereum-related losses at roughly $332 million and Solana-related losses at about $326 million, a near-even split between the two largest smart-contract platforms. That balance is worth noting: heavy activity on either network brings a comparable share of the total risk, so neither ecosystem offered a clear safe harbour in this period.

Metric (H1 2026)Reported figure
Total stolen~$1.1 billion
Number of incidents212
Top four incidents’ share~$707M (~64%)
North Korea-linked share~$609M (~55%)
Ethereum-related losses~$332 million
Solana-related losses~$326 million

More attacks, but fewer mega-breaches

One of the more nuanced findings is that the count of serious exploits rose even as the dollar total did not set a record. Blockaid said it tracked about 3.4 times as many high-threshold exploits as in all of 2025.

Yet total dollar losses came in below the equivalent period a year earlier. The reason is the shape of the losses rather than their frequency: 2025 included the roughly $1.5 billion Bybit hack, a single event with no equivalent in the first half of 2026. Strip out one outlier year and the trend is more attacks, spread across more protocols, with the damage per incident generally smaller.

For anyone reading a single scary headline number, that distinction matters. “Record number of hacks” and “record dollars stolen” are different claims, and this half-year set the first record without setting the second.

What holders can actually do with this

Aggregate loss data does not tell an individual which protocol will be hit next, but the pattern points to a few defensive habits that are within a user’s control:

  • Limit exposure to any single protocol, especially newly launched or lightly audited ones, since a few large failures drive most of the annual total.
  • Treat bridges as high-risk infrastructure. Move only what you need across chains, and avoid leaving large balances parked in bridge contracts.
  • Prioritise key security. Because compromised keys were a leading vector, hardware wallets, careful signing hygiene and separating hot from cold storage matter as much as any protocol’s audit badge.
  • Read incident reports for method, not just amount. Whether a loss came from a bridge, a contract bug or a stolen key tells you more about your own risk than the dollar figure does.

None of these eliminates risk. They shift the odds, which is the realistic goal in a market where a determined state-backed group is one of the largest single threats.

Bottom line

Blockaid’s H1 2026 report describes a security environment that is getting busier rather than calmer: a record number of incidents, more than $1.1 billion stolen, and a familiar cast of causes led by state-linked groups, bridge exploits and key compromise. The absence of a Bybit-scale mega-breach kept the dollar total below the prior year, but the rising incident count is the signal that deserves attention.

The data is a reminder that most large losses trace back to a few concentrated failures. Managing exposure to any single protocol, guarding keys, and treating bridges with caution remain the levers most within a user’s reach as the second half of the year plays out.

Advertisement

Sources and review

This article was checked against the primary or authoritative sources below .

Frequently asked questions

How much crypto was stolen in the first half of 2026?

Security firm Blockaid counted more than $1.1 billion stolen across 212 separate incidents in the first six months of 2026, which it described as the most-hacked half-year on record by incident count.

Was 2026 worse than 2025 for crypto theft?

By number of incidents, yes. Blockaid tracked roughly 3.4 times as many high-threshold exploits as in all of 2025. In pure dollar terms the H1 2026 total was lower than the same period a year earlier, because 2025 included the single $1.5 billion Bybit breach and 2026 had no comparable event.

Which hacks caused the most damage?

According to Blockaid, the four largest incidents, KelpDAO, Drift Protocol, Resolv and CowSwap, accounted for about $707 million, or roughly 64% of the half-year total.

Who was behind the largest thefts?

Blockaid attributed a large share of losses to North Korea-linked groups, particularly the TraderTraitor subgroup associated with Lazarus. It tied the KelpDAO, Drift Protocol and Humanity Protocol exploits, totalling about $609 million, to that activity.

What were the most common attack methods?

The report cited cross-chain bridges, exploits on Ethereum layer-2 networks and compromised private keys as the leading attack vectors during the period.

Advertisement

V

Vijay Rathod

Independent crypto and financial-markets analyst covering Bitcoin, altcoins, macroeconomics, and trading news. More about the author →