Crypto security losses totaled $1.1 billion across 212 verified on-chain incidents in the first half of 2026, according to a July 28 report from security firm Blockaid. The findings point to a notable change in how major losses are occurring, with operational-security breakdowns driving most of the damage rather than flaws in smart-contract code.

Shift from code exploits to infrastructure failures

Blockaid said 74% of recorded losses came from compromised devices, privileged credentials, private keys, signing systems and other off-chain infrastructure. In other words, the bulk of losses in the period were linked not to bugs in on-chain applications themselves, but to failures around the systems and people controlling access.

The report describes this as a move away from the traditional focus on smart-contract exploits. That distinction matters because it suggests attackers are increasingly targeting operational weak points that sit outside the code of decentralized applications, including the tools and systems used to authorize transactions.

A single cluster tied to North Korea dominated losses

According to Blockaid, one DPRK-linked cluster was responsible for about 55% of all losses recorded in the first half of the year. The report did not frame that figure as the total number of incidents, but as the share of overall value lost.

The pace of incidents was also much higher than in the previous year. Blockaid said the 212 incidents recorded in H1 2026 amounted to 3.4 times the total number seen across all of 2025. That comparison indicates a sharp rise in attack frequency even without implying that every event was equally severe.

Ethereum and Solana showed different risk profiles

The report highlighted different attack patterns across major ecosystems. Ethereum-related projects saw losses of about $332 million, with code vulnerabilities remaining a significant factor. Blockaid cited KelpDAO as an example of the kind of incident driven by smart-contract weaknesses.

Solana-related projects, by contrast, lost about $326 million, and more than 98% of that amount was linked to compromised keys and signing infrastructure. That made Solana’s losses heavily concentrated in the operational-security category described in the report.

Among the notable incidents, Drift Protocol and Step Finance were identified as major cases during the period. Their inclusion underscored the scale of losses associated with compromised access and transaction-authorization systems.

Recovery efforts and security recommendations

Blockaid said some recovery actions have followed the large incidents. In Drift’s case, those efforts included a proposed recovery pool and token. The report also referred to partial recoveries and continuing litigation over frozen funds, indicating that the financial and legal consequences of several attacks remain unresolved.

The firm argued that stronger defensive practices are needed across the industry. Its recommendations included transaction-intent checks, isolated signing devices and better monitoring across bridges and broader infrastructure. The emphasis of those measures reflects the report’s broader conclusion that protecting wallets, credentials and signing environments has become at least as important as auditing code.

The findings add to evidence that crypto security risks are increasingly tied to the operational layers around blockchain systems, not only to vulnerabilities embedded in smart contracts. While Ethereum and Solana showed different patterns in Blockaid’s breakdown, the report’s central message was that compromised access points and infrastructure now account for most of the largest verified on-chain losses.

Source: crypto.news