Crypto protocols lost a record $1.1 billion to 212 on-chain exploits in the first six months of the year, according to a report cited in the source article. The figures point to a sharp rise in both the scale of attacks and the number of successful incidents.
The report said groups linked to North Korea were tied to about $609 million of the total, or roughly 55% of losses. Ethereum and Solana bore the largest network-level damage, with about $332 million and $326 million in losses respectively.
Losses concentrated in a handful of major incidents
Two of the biggest breaches named in the report were KelpDAO and Drift Protocol. The losses were estimated at about $292 million and $285 million, and both incidents were linked to the same North Korea cluster.
Those two attacks alone represented a large share of the half-year total, underscoring how a small number of high-value compromises can heavily shape overall loss figures. The report nevertheless counted 212 separate exploits, showing that the damage was spread across a broad set of incidents as well.
Attack pace accelerated through the half
The number of reported exploits increased steadily over the period. The report said there were 18 incidents in January, compared with 57 in June, indicating a clear rise in attack frequency by the end of the half.
April stood out as the most expensive month, with $635 million stolen. That suggests the record loss total was driven not only by more attacks, but also by several very large breaches landing in a short window.
Operational failures outweighed code bugs
According to the report, operational security failures were the main source of damage. Roughly $790 million in losses were attributed to issues such as privileged key misuse, a total that far exceeded losses tied to code vulnerabilities.
That distinction matters because it points to a different risk profile for protocols. Rather than only flaws in smart contract logic, attackers increasingly appear to be exploiting internal access, key management, and other security weaknesses around the protocol itself.
New attack methods are adding pressure
The report also flagged emerging threats beyond the more familiar exploit patterns. These included prompt-injection attacks aimed at AI agents and newer wallet delegation exploits that can bypass traditional defenses.
In some cases, vulnerabilities can allow partial fund freezes or recoveries through code-based mechanisms, though the report said outcomes vary widely from one incident to another. The next confirmed step is likely to be continued monitoring of whether these newer attack vectors become a larger share of future crypto losses.
Source: dailyhodl.com