Key takeaways: Crypto hacks 2026 set a record for incident count in the first half, with $1.1 billion stolen across 212 verified exploits. North Korea-linked actors accounted for close to $600 million, and roughly three-quarters of the value lost came from operational-security failures rather than exploited contract code. Ethereum and Solana projects lost the most. Blockaid expects AI agent exploits, led by prompt injection, to become a meaningful vector in the second half.
Crypto hacks 2026 have already produced the most-hacked half-year on record — by frequency, not by dollars. In a report published on 28 July, security firm Blockaid said it verified more exploit incidents in the first six months of 2026 than in all of 2025, tallying 212 verified exploits and more than $1.1 billion drained. Dollar losses still trailed last year — H1 2025 saw roughly $2.3 billion vanish — but that total was distorted by the single $1.5 billion Bybit exploit.

The short answer: more attacks, smaller average size, and a decisive shift in method. The largest incidents of H1 2026 were not clever contract bugs. They were compromised humans holding keys — and the report’s forward-look argues the next class of compromised signer will be an AI agent.
Where the money went in H1
Blockaid attributed the largest share of stolen funds — close to $600 million — to North Korea-linked actors. It assigned both of the half’s biggest single incidents to DPRK-linked groups: the $292 million KelpDAO exploit, which succeeded through a forged cross-chain message, and the $285 million Drift Protocol loss, drained through a multisig compromise. These are the firm’s attributions, not confirmed legal findings.
By chain, Ethereum projects lost about $332 million and Solana projects about $326 million. Blockaid’s own explanation of the split is the most useful line in the report: on Ethereum, “mega code exploits concentrate” where the highest-value restaking, stablecoin and aggregator protocols live, while on Solana, “attackers target signer infrastructure rather than contract code.” More than 98% of Solana losses traced to compromised keys and signing infrastructure.
Why the crypto hacks 2026 numbers disagree
Anyone comparing headlines will find three different totals. The methodologies, not the events, are what differ.
| Tracker | H1 2026 losses | Incidents counted |
|---|---|---|
| Blockaid | Above $1 billion | ~212 verified exploits |
| Second tracker (see note) | ~$972 million | 207 |
| QuillAudits | $935.3 million | 87 DeFi hacks |
A note on the middle row: outlets disagree on whose dataset that is. The Block attributes the $972 million / 207-incident count to Immunefi’s June 2026 Ecosystem Update; Crypto Briefing attributes the same figures to TRM Labs. The numbers are consistent across both reports; the attribution is not, so treat the source as unsettled.
All three agree on the direction: a record number of incidents. The same reporting adds a useful counterweight — DeFi exploit losses in 2026 are down roughly 74% from the 2022 peak. Read together, the picture is an industry that has hardened its contracts and displaced the attack surface somewhere else.
The vector nobody can audit
That somewhere else is people, and the reports put a number on it: infrastructure compromises — the category that includes social engineering — accounted for roughly 74% to 76% of all value lost in H1, depending on which write-up you read, despite making up a smaller share of total incidents. Contract bugs were more numerous; compromised humans were more expensive.
Blockaid was blunt about the repeat pattern: “The working pattern of LinkedIn social engineering leading to multisig signer compromise produced two of the four largest H1 incidents, and there is no structural reason for it to stop.”
This is the part a smart contract audit cannot reach. A protocol can ship formally verified code and still lose nine figures because a signer accepted a recruiter’s take-home assignment. The same lesson ran through the recent Coldcard incident from the retail side: custody failures increasingly begin outside the chain.
The AI agent warning in the crypto hacks 2026 report
Blockaid’s forward-look is where the report stops being a retrospective. It flags the $216,000 exploit of Bankr as, in its words, the first of its kind, notes that agent deployment is growing roughly tenfold a year, and predicts “multiple AI agent incidents in H2, with prompt injection leading and tool-use abuse and unauthorized signing to follow.”
Line that up against the H1 pattern and the trajectory is uncomfortable. The dominant 2026 attack was persuading a human with signing authority to do something they should not. An autonomous agent with a wallet is the same category of target with three differences: it never gets suspicious, it operates continuously, and it can be reached by anything it reads. As agentic payments settle onto stablecoin rails, the number of these signers is growing faster than the controls around them.
What this means
For builders, the implication is that security spend is misallocated. Audit budgets scale with contract complexity; H1 2026 losses scaled with signer count and staff hygiene. The controls that would have blocked the two largest incidents are procedural — hardware-enforced signing, transaction simulation before approval, quorum policies that assume at least one signer is compromised, and recruitment channels treated as an attack surface.
There is a regional read too. Gulf regimes have been quietly ahead of this. VARA’s operational-resilience and AML expectations for Dubai VASPs, and ADGM’s technology governance requirements, sit on key management, staffing and incident response rather than on code review. That looked bureaucratic when the threat was contract bugs. It looks better calibrated now. UAE users weighing where their assets sit can start with which regulator actually covers the service.
The honest caveat: a half-year is a short window, attribution to state-linked groups is inference rather than proof, and one $216,000 agent exploit is a data point, not a trend. But the direction of travel — from exploiting code to exploiting whoever, or whatever, holds the key — is now visible in three independent datasets.
Frequently asked questions
Were crypto hacks in 2026 worse than in 2025?
By incident count, yes. Blockaid describes H1 2026 as the most-hacked half-year on record and says it verified more exploits in six months than in all of 2025. By dollar value the answer is no: 2025 totals were higher, inflated by the single $1.5 billion Bybit exploit.
Why do published crypto hack totals for 2026 disagree?
Trackers use different inclusion rules. Blockaid counted 212 verified exploits and more than $1.1 billion, a second dataset reported roughly $972 million across 207 incidents (attributed to Immunefi by The Block and to TRM Labs by Crypto Briefing), and QuillAudits counted $935.3 million across 87 DeFi hacks. The gaps come from what each firm counts as an exploit, which chains and off-chain compromises are in scope, and how recovered funds are treated.
Sources
- Blockaid — H1 2026 report
- The Block — Crypto hacks hit record high in H1 2026 as losses top $1 billion (28 July 2026)
- Crypto Briefing — Crypto records most hacked half-year ever with 212 exploits
- Bitcoin.com News — Blockaid says 212 onchain exploits stole $1.1B
- QuillAudits — H1 2026 DeFi security report
By Vaibhav Ali
This article is for informational purposes only and does not constitute financial, investment, or legal advice.
