Blockaid recorded more crypto exploit incidents in H1 2026 than in all of 2025, with DPRK-linked hackers responsible for nearly $600M of the $1B+ in total losses.
Cryptocurrency projects lost more than $1 billion to exploits in the first half of 2026, according to a report published July 28 by blockchain security firm Blockaid. The firm said the number of verified incidents in that six-month window exceeded its full-year total for 2025.
Total dollar losses were lower than the same period last year. The 2025 comparison was heavily influenced by the $1.5 billion Bybit exploit, which remains the single largest crypto hack on record.
North Korea Linked to Nearly $600M in Thefts
Blockaid attributed two major exploits to hackers connected to North Korea's government. The $285 million Drift exploit and the $292 million KelpDAO exploit were both tied to Democratic People's Republic of Korea (DPRK)-linked actors, bringing their combined total to roughly $577 million for the half-year.
Both incidents involved the same method: LinkedIn-based social engineering that led to the compromise of multisig signers. Blockaid said that pattern produced two of the four largest incidents of the period and that no structural change exists to prevent its continued use.
Security firms reported varying totals for the period. Immunefi counted approximately $972 million in losses across 207 incidents, while Quill Audits recorded $935.3 million across 87 DeFi hacks. All three firms identified H1 2026 as the highest six-month incident count on record. Immunefi also noted that DeFi exploit losses in 2026 have fallen 74% from their 2022 peak.
Related Article: AFX Trade Bridge Exploited for $24M in USDC on Arbitrum
Ethereum and Solana Projects Lost the Most
Blockaid's report identified AI agent exploits as a risk for the second half of 2026. A $216,000 exploit targeting the Bankr platform was the first recorded incident of that type. The firm said AI agent deployment is growing at a rate of roughly 10x per year and that it expects additional incidents in H2 2026, with prompt injection as the most likely method, followed by tool-use abuse and unauthorized transaction signing.
