Crypto security incidents increased sharply in the first half of 2026, even as the total value lost declined from a year earlier, according to a new semi-annual report from OKX produced with SlowMist and OtterSec. The study logged 182 publicly disclosed Web3 security incidents and $956 million in total losses.
More incidents, lower losses
The report says the number of incidents rose 50% compared with the first half of 2025. At the same time, total losses were down about 60% year over year. According to the report, that drop was largely due to the absence of a single unusually large loss event during the period.
Two incidents accounted for the biggest disclosed losses in the dataset. The KelpDAO attack led with about $292 million in losses, followed by the Drift Protocol attack at roughly $285 million.
Attack methods continue to shift
OKX said the threat landscape moved away from a pattern dominated mainly by smart contract exploits. In its place, the report points to a broader mix of attack vectors, including supply-chain compromises, social engineering, cloud key theft, and failures tied to single points of validation.
By category, supply-chain attacks produced the largest losses at around $298 million. Contract logic issues were next at $152 million, while private key leaks accounted for about $130 million in losses.
The figures suggest attackers are increasingly targeting weak links around protocols and infrastructure rather than relying only on direct flaws in onchain code. The report frames this as a structural shift in how losses are being generated across the sector.
AI-related risks enter the picture
The report also highlights the emergence of AI-driven attack risks. One example cited is the Bankr incident, where manipulation of an AI agent reportedly involved prompt injections and abuse of trusted inputs. That incident enabled transfers estimated at around $150,000 to $200,000.
In OKX’s assessment, users and AI agents are becoming the main targets in a changing threat environment. Rather than focusing only on code audits or isolated contract defenses, the report says future protections are likely to rely more on layered controls across devices, signatures and trust systems.
What defenses may look like
The report points to several defensive approaches it expects to become more important, including sandboxed tool use, permission tiering, pre-execution simulation and real-time risk detection. The stated goal of such measures is to stop malicious activity before a seed phrase is exposed or a harmful connection is approved.
Taken together, the findings describe a market where attack frequency is rising even as aggregate losses have eased from last year’s level. The report does not present that decline as a sign of lower risk, but rather as a result shaped by the mix of incidents recorded in the period and the lack of an extreme outlier.
Source: Coin Edition