Gold 24K AED 477.59/gUSD/AED 3.6725USDT/AED 3.6692AED/INR 26.01All live rates →

Crypto Hacks 2026: 212 Exploits and a $1B Warning

Key takeaways: Crypto hacks 2026 set a record for incident count in the first half, with $1.1 billion stolen across 212 verified exploits. North Korea-linked actors accounted for close to $600 million, and roughly three-quarters of the value lost came from operational-security failures rather than exploited contract code. Ethereum and Solana projects lost the most. Blockaid expects AI agent exploits, led by prompt injection, to become a meaningful vector in the second half.

Crypto hacks 2026 have already produced the most-hacked half-year on record — by frequency, not by dollars. In a report published on 28 July, security firm Blockaid said it verified more exploit incidents in the first six months of 2026 than in all of 2025, tallying 212 verified exploits and more than $1.1 billion drained. Dollar losses still trailed last year — H1 2025 saw roughly $2.3 billion vanish — but that total was distorted by the single $1.5 billion Bybit exploit.

Record crypto hacks 2026 with 212 verified exploits and over $1 billion stolen
Crypto hacks 2026: the incident count set a record even as dollar losses stayed below 2025.

The short answer: more attacks, smaller average size, and a decisive shift in method. The largest incidents of H1 2026 were not clever contract bugs. They were compromised humans holding keys — and the report’s forward-look argues the next class of compromised signer will be an AI agent.

Where the money went in H1

Blockaid attributed the largest share of stolen funds — close to $600 million — to North Korea-linked actors. It assigned both of the half’s biggest single incidents to DPRK-linked groups: the $292 million KelpDAO exploit, which succeeded through a forged cross-chain message, and the $285 million Drift Protocol loss, drained through a multisig compromise. These are the firm’s attributions, not confirmed legal findings.

By chain, Ethereum projects lost about $332 million and Solana projects about $326 million. Blockaid’s own explanation of the split is the most useful line in the report: on Ethereum, “mega code exploits concentrate” where the highest-value restaking, stablecoin and aggregator protocols live, while on Solana, “attackers target signer infrastructure rather than contract code.” More than 98% of Solana losses traced to compromised keys and signing infrastructure.

Why the crypto hacks 2026 numbers disagree

Anyone comparing headlines will find three different totals. The methodologies, not the events, are what differ.

TrackerH1 2026 lossesIncidents counted
BlockaidAbove $1 billion~212 verified exploits
Second tracker (see note)~$972 million207
QuillAudits$935.3 million87 DeFi hacks

A note on the middle row: outlets disagree on whose dataset that is. The Block attributes the $972 million / 207-incident count to Immunefi’s June 2026 Ecosystem Update; Crypto Briefing attributes the same figures to TRM Labs. The numbers are consistent across both reports; the attribution is not, so treat the source as unsettled.

All three agree on the direction: a record number of incidents. The same reporting adds a useful counterweight — DeFi exploit losses in 2026 are down roughly 74% from the 2022 peak. Read together, the picture is an industry that has hardened its contracts and displaced the attack surface somewhere else.

The vector nobody can audit

That somewhere else is people, and the reports put a number on it: infrastructure compromises — the category that includes social engineering — accounted for roughly 74% to 76% of all value lost in H1, depending on which write-up you read, despite making up a smaller share of total incidents. Contract bugs were more numerous; compromised humans were more expensive.

Blockaid was blunt about the repeat pattern: “The working pattern of LinkedIn social engineering leading to multisig signer compromise produced two of the four largest H1 incidents, and there is no structural reason for it to stop.”

This is the part a smart contract audit cannot reach. A protocol can ship formally verified code and still lose nine figures because a signer accepted a recruiter’s take-home assignment. The same lesson ran through the recent Coldcard incident from the retail side: custody failures increasingly begin outside the chain.

The AI agent warning in the crypto hacks 2026 report

Blockaid’s forward-look is where the report stops being a retrospective. It flags the $216,000 exploit of Bankr as, in its words, the first of its kind, notes that agent deployment is growing roughly tenfold a year, and predicts “multiple AI agent incidents in H2, with prompt injection leading and tool-use abuse and unauthorized signing to follow.”

Line that up against the H1 pattern and the trajectory is uncomfortable. The dominant 2026 attack was persuading a human with signing authority to do something they should not. An autonomous agent with a wallet is the same category of target with three differences: it never gets suspicious, it operates continuously, and it can be reached by anything it reads. As agentic payments settle onto stablecoin rails, the number of these signers is growing faster than the controls around them.

What this means

For builders, the implication is that security spend is misallocated. Audit budgets scale with contract complexity; H1 2026 losses scaled with signer count and staff hygiene. The controls that would have blocked the two largest incidents are procedural — hardware-enforced signing, transaction simulation before approval, quorum policies that assume at least one signer is compromised, and recruitment channels treated as an attack surface.

There is a regional read too. Gulf regimes have been quietly ahead of this. VARA’s operational-resilience and AML expectations for Dubai VASPs, and ADGM’s technology governance requirements, sit on key management, staffing and incident response rather than on code review. That looked bureaucratic when the threat was contract bugs. It looks better calibrated now. UAE users weighing where their assets sit can start with which regulator actually covers the service.

The honest caveat: a half-year is a short window, attribution to state-linked groups is inference rather than proof, and one $216,000 agent exploit is a data point, not a trend. But the direction of travel — from exploiting code to exploiting whoever, or whatever, holds the key — is now visible in three independent datasets.

Frequently asked questions

Were crypto hacks in 2026 worse than in 2025?

By incident count, yes. Blockaid describes H1 2026 as the most-hacked half-year on record and says it verified more exploits in six months than in all of 2025. By dollar value the answer is no: 2025 totals were higher, inflated by the single $1.5 billion Bybit exploit.

Why do published crypto hack totals for 2026 disagree?

Trackers use different inclusion rules. Blockaid counted 212 verified exploits and more than $1.1 billion, a second dataset reported roughly $972 million across 207 incidents (attributed to Immunefi by The Block and to TRM Labs by Crypto Briefing), and QuillAudits counted $935.3 million across 87 DeFi hacks. The gaps come from what each firm counts as an exploit, which chains and off-chain compromises are in scope, and how recovered funds are treated.

Sources

By Vaibhav Ali

This article is for informational purposes only and does not constitute financial, investment, or legal advice.

Explore the guides: Agentic AI in finance →
📧 The Gulf reads Cryptonite first
Get MENA regulation moves, RWA deals and AI-money trends in one weekly brief — plus instant alerts when the MENA Regulation Tracker changes. Free, no spam.
Was this briefing useful?Thanks for the feedback!
Vaibhavv Ali
Vaibhavv Ali

Vaibhav Ali is the founder and editor of Cryptonite (cryptonite.ae), an independent digital-asset news and analysis publication with a UAE focus. He covers virtual-asset regulation — VARA, ADGM and the UAE Central Bank — alongside real-world-asset tokenization, stablecoins and agentic AI in finance. Every Cryptonite article is human-edited and its sources are linked.

More articles by Vaibhavv Ali →

Leave a Comment

About  ·  Contact  ·  Privacy Policy  ·  Editorial Policy  ·  Advertise  ·  Newsletter
Follow: X  ·  LinkedIn  ·  Instagram  ·  Binance Square  ·  CoinMarketCap  ·  Gate