Crypto Security Breaches Surge to $1.1 Billion in First Half of 2026
Blockchain security firm Blockaid reported that crypto hacks and exploits reached $1.1 billion across 212 verified incidents in the first half of 2026, according to data published July 28.

The figure exceeds the aggregate loss recorded across all of 2025 and sets a new record in incident count. For NFT traders and DeFi liquidity providers operating across Ethereum and Solana, the dataset points to a structural shift: compromised keys and signing infrastructure, not faulty smart-contract code, now drive most of the measured theft.
The Damage Breakdown
- $1.1B total losses across 212 incidents — 3.4× Blockaid's 2025 incident count
- Operational security attacks account for 74% of stolen value
- A single cluster linked to the Democratic People's Republic of Korea represents 55% of the total
- Ethereum ecosystem: ~$332M lost; Solana ecosystem: ~$326M lost
- On Solana, >98% of losses stemmed from compromised keys and signing infrastructure, not code flaws
Where the Capital Went
Blockaid's findings challenge the assumption that audited code equals protected capital. On Ethereum, the dominant case was KelpDAO's April 18 bridge exploit — attackers falsified a source-chain message and released 116,500 rsETH (~$292M). Chainalysis attributed the operation to North Korea's Lazarus Group, tracing the entry point to compromised internal RPC nodes that fed a single-verifier system a false burn event. On Solana, the bulk of losses concentrated in Drift Protocol and Step Finance, both classified as privileged-access failures. Drift's April 1 incident involved months of social engineering and pre-signed durable-nonce transactions; its April 16 recovery filing pegged stolen assets at $295.7M, above initial estimates.
What NFT Traders Should Track
1. Code audits are necessary but insufficient. Audits identify contract flaws; they do not stop an administrator with stolen credentials from signing a malicious transaction. Vault custodians, mint operators, and bridge teams managing NFT-related liquidity should now be evaluated on key-management infrastructure, not just audit reports.
2. Network-level comparisons mislead. Ethereum's higher code-vulnerability share and Solana's higher credential-loss share reflect which applications were targeted, not which chain is structurally safer. A single large incident can dominate a six-month total.
3. Sanctions-driven wallet rotation adds counterparty risk. Separate reporting from TRM Labs documented that exchange HTX rotated hot wallets across Tron, Ethereum, BNB Smart Chain, and Solana after UK OFSI sanctions in May. Traders routing volume through intermediaries with opaque funding flows should expect greater counterparty risk and possible withdrawal friction.
Risk Read
The H1 dataset is a record in incident count, not necessarily in average loss per incident. The metric that matters for the second half is whether privileged-access attacks continue to scale faster than detection tooling. Until that ratio inverts, capital parked in cross-chain bridges, custodial mint flows, and admin-keyed vaults carries measurable tail risk that no audit can underwrite.