The first six months of 2026 produced the highest volume of onchain security breaches ever recorded, with 212 major exploits stripping an estimated $1.1bn from crypto users and protocols, according to a new report by security firm Blockaid.
Blockaid’s H1 2026 Onchain Security Report says the number of “high-threshold” exploits it verified between January and June was 3.4 times greater than the total seen across the whole of 2025. The firm defines these incidents as large-scale, technically validated attacks on onchain systems.
While the overall value stolen in the first half of 2026 fell short of the equivalent period in 2025 – largely because there was no single multibillion-dollar “mega-heist” – the report concludes that both the frequency and technical sophistication of attacks have escalated sharply.
Over the six-month window, attackers carried out 212 confirmed exploits, with activity peaking in June when 57 separate incidents were logged. Just four of those cases accounted for $707m, or 64% of all funds taken.
Blockaid attributes around $609m of the total losses to North Korea’s “Trader Traitor” hacking cluster, which is associated with the Lazarus Group and is described in the report as the primary driver of the largest thefts during the period.
North Korea-linked cluster behind biggest raids
The report states that a small number of high-profile operations, mainly linked to North Korean state-sponsored actors, were responsible for the majority of financial damage.
The two largest attacks of the half-year targeted restaking protocol KelpDAO and Solana-based perpetual DEX Drift Protocol. The KelpDAO exploit resulted in losses of $292m, while the Drift Protocol breach saw $285m stolen. Both incidents were attributed by Blockaid to the Trader Traitor cluster.
Unlike many traditional crypto hacks that have centred on smart contract vulnerabilities, these operations focused on human and operational weaknesses.
In the Drift Protocol case, Blockaid says the attackers spent weeks conducting tailored social engineering to gain control of the project’s administrative multisig. Once in control, they were able to drain $285m in under 12 minutes.
The KelpDAO attack followed a different route but still relied on social manipulation. According to the report, Trader Traitor operatives targeted a LayerZero developer, using social engineering tactics to compromise remote procedure call (RPC) infrastructure and falsify cross-chain bridge attestations, enabling the theft of $292m.
New attack frontiers: wallets, AI and bridges
Blockaid’s analysis highlights three emerging “security boundaries” that played a prominent role in incidents during the first half of 2026 – areas it says are often left outside the scope of conventional code audits.
These are: EIP-7702 wallet delegation attacks, AI prompt injection, and weaknesses in off-chain bridge infrastructure.
The report singles out AI-related risks as a rapidly growing concern. As an example, it cites a May 2026 attack on Bankr, in which an adversary “used prompt injection to trick Bankr’s AI agent into approving an unauthorized transaction, taking $216K”. Blockaid says this illustrates how autonomous AI agents deployed in decentralized finance are becoming attractive targets.
The growing use of EIP-7702-style wallet delegation features – which allow spending authority to be handed to external agents or contracts – is also flagged as fertile ground for future exploits if not properly secured.
Recovery depends on how attackers get in
Blockaid notes that the prospects of recovering stolen funds varied sharply depending on the method used by attackers.
Where compromises involved private keys, the firm says assets typically disappeared almost immediately through mixers or cross-chain bridges, making subsequent tracing and retrieval highly unlikely.
By contrast, when losses were caused by protocol-level bugs, there were occasional opportunities for partial or full recovery. In some instances, rapid coordination between white-hat hackers, developers and infrastructure providers – including the ability to pause contracts – allowed teams to secure remaining funds or negotiate returns.
Outlook: more pressure expected in second half of 2026
Looking ahead, Blockaid warns that Web3 ecosystems should be braced for sustained – and potentially intensifying – pressure over the remainder of the year.
The report identifies three principal areas of concern: continuing social engineering campaigns run by sanctioned nation-state actors, a likely increase in attacks exploiting EIP-7702 wallet delegation mechanisms, and a steep rise in prompt-injection assaults on autonomous AI trading agents as their use spreads across decentralized finance.
Although Blockaid’s latest figures focus on the first half of 2026, the firm also notes that the final quarter of the year has already been labelled by observers as the most heavily hacked three-month period in crypto’s history, with around 70 separate exploits draining funds from users and protocols.
With no sign of attackers slowing down, the report concludes that security assumptions built around traditional smart contract auditing are no longer sufficient on their own, and that human, AI and off-chain components now sit at the heart of the most damaging onchain thefts.
