Crypto hackers stole about $1.1 billion in the first six months of 2026 across 212 separate incidents, making it the busiest half-year on record for exploits, according to a new report from security firm Blockaid.

The report points to a sharp rise in attack activity over the period, with a handful of very large breaches accounting for much of the financial damage. Blockaid said four cases alone — KelpDAO, Drift, Resolv, and CoW Swap — represented roughly $707 million in losses.

A record period driven by a few outsized hacks

Blockaid said the pace of incidents accelerated during the half, rising from 18 attacks in January to 57 in June. April was the worst month by losses after the KelpDAO and Drift breaches together erased about $577 million, pushing the month’s total to $635 million.

KelpDAO recorded the largest single loss in the period at $292 million after attackers allegedly used a fake cross-chain message to drain Ethereum reserves. Drift Protocol followed with a $285 million exploit that Blockaid said unfolded within 12 minutes.

DPRK-linked activity accounted for more than half of losses

Blockaid linked the KelpDAO and Drift incidents to TraderTraitor, which it described as a North Korean subset of the Lazarus Group. The security firm also connected Humanity Protocol’s $32 million loss to the same attacker cluster.

Using those attributions, Blockaid estimated that DPRK-linked actors were responsible for $609 million in thefts during the first half of the year, or about 55% of all funds stolen in the period.

Key misuse was the most expensive attack vector

By category, privileged key misuse caused the largest financial damage in H1 2026, with losses of around $790 million, nearly three-quarters of the total amount stolen. Unbacked mint exploits were the next major source of losses, led by the $80 million Resolv breach.

Even so, code-level vulnerabilities remained the most common kind of incident by count. Blockaid said they accounted for nearly four out of every five attacks recorded during the half-year.

New attack paths widened the threat landscape

The report said 2026 also introduced newer exploit routes. After May, AI agents became a target, including a prompt injection attack that reportedly tricked Bankr’s AI into approving an unauthorized transaction worth about $216,000.

Cross-chain systems were also hit through forged proofs and attestations. Blockaid further noted four incidents tied to EIP-7702 wallet delegation attacks, while older smart contracts continued to create openings. About five such legacy-contract cases were logged in May and June, including two involving Aztec Connect and one affecting Raydium’s AMM V3.

Pressure continued beyond June

Blockaid said recovery outcomes depended heavily on how the breach happened. In some code-related attacks, projects were able to freeze assets or negotiate returns, while incidents involving stolen keys more often ended with funds moving through mixers or across chains.

The report also pointed to attacks outside the January-to-June window as a sign that pressure on crypto infrastructure had not eased. On July 23, AFX Trade, BSquaredNetwork, and Verus were each hit in separate incidents on the same day, with combined losses of more than $35 million. Blockaid said Verus had suffered exploits about two months earlier as well, and linked both episodes to the same bridge contract and bug class.

Source: cryptopotato.com