← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] 212 Crypto Hacks in H1 2026: Code Isn't the Problem

Zephyra|July 30, 2026|BPF
EXECUTIVE SUMMARY

Cryptocurrency protocols suffered $1.1 billion in verified losses across 212 separate incidents during H1 2026, according to a Blockaid report published July 28, 2026. Immunefi's parallel dataset counted 207 incidents totaling $972 million. Both represent the highest incident counts ever recorded...

"What we are watching is not a North Korean campaign that is broader — it is one that is sharper." — Ari Redbord, Global Head of Policy, TRM Labs

Executive Summary

Cryptocurrency protocols suffered $1.1 billion in verified losses across 212 separate incidents during H1 2026, according to a Blockaid report published July 28, 2026. Immunefi's parallel dataset counted 207 incidents totaling $972 million. Both represent the highest incident counts ever recorded for a six-month period.

The headline number obscures the structural shift underneath it. Per-incident losses dropped significantly from H1 2025, when the Bybit exploit alone accounted for $1.5 billion and total losses reached $2.58 billion across 63 incidents. The 2026 data shows a market where attacks are more frequent, more targeted, and increasingly directed at human and infrastructure weaknesses rather than smart contract code. Blockaid's dataset attributes 74% of stolen funds to operational security failures — compromised keys, social engineering of multisig signers, and poisoned infrastructure — rather than on-chain code vulnerabilities.

North Korea-linked actors, primarily the Lazarus Group, accounted for 55% to 66% of total losses depending on the dataset, with TRM Labs estimating DPRK-attributed theft at $643 million and cumulative theft since 2017 exceeding $6 billion.

Table of Contents

  1. H1 2026 by the Numbers
  2. The Operational Security Problem
  3. Two Attacks, $577 Million
  4. Bridge Exploits: The Persistent Structural Weakness
  5. North Korea: State-Level Threat Actor
  6. Network-Level Breakdown
  7. The Bug Bounty Counterweight
  8. July 2026: The Pace Continues
  9. Key Takeaways
  10. Conclusion

H1 2026 by the Numbers

Two independent security firms tracked H1 2026 losses and arrived at broadly consistent figures:

| Metric | Blockaid | Immunefi | |--------|----------|----------| | Total incidents | 212 | 207 | | Total losses | $1.1 billion | $972 million | | H1 2025 comparison | $2.58 billion (63 incidents) | ~$2.3 billion | | Year-over-year loss change | -57% | -57% | | Largest single incident | KelpDAO ($292M) | Drift Protocol ($285M) |

The discrepancy between the two datasets reflects methodological differences in incident classification and verification timelines. Blockaid includes a broader set of verified incidents; Immunefi applies stricter deduplication criteria. The directional conclusion is identical: more attacks, less money lost per event.

Smart contract exploits accounted for 125 of 207 incidents in Immunefi's count, making them the most frequent attack type. However, they represented only approximately 11% of total dollar losses. The remaining 88.3% of financial damage came from operational and infrastructure compromises — a ratio that represents a fundamental inversion from the 2021-2022 era when reentrancy bugs and flash loan manipulations drove the largest losses.

The Operational Security Problem

Blockaid's data shows 74% of H1 2026 losses stemmed from operational security failures rather than exploited code. Chainalysis data corroborates this, attributing approximately 76% of crypto-related hack losses globally in 2026 to attacks targeting key management, multisig governance, and signing infrastructure.

The pattern is consistent: attackers are moving up the stack. Rather than searching for logic errors in audited Solidity code, they target the humans and systems that hold the keys to deploy, upgrade, or authorize transactions on those contracts.

This is a direct consequence of improved code-level security. As protocols adopt formal verification, multiple audit rounds, and competitive audit platforms, the marginal cost of finding an exploitable smart contract bug has increased. Operational infrastructure — RPC nodes, multisig coordination processes, team communication channels — has not received equivalent hardening.

The economic logic is straightforward. A compromised multisig key yields access to every asset the protocol controls. A smart contract bug yields access to the specific vulnerability surface. Attackers follow the higher expected value.

Two Attacks, $577 Million

Nearly 44% of all H1 2026 losses came from two incidents, both in April, both attributed to North Korean actors, and both exploiting operational rather than code-level vulnerabilities.

Drift Protocol — April 1, 2026 — $285 million

Attackers drained Drift, a Solana-based decentralized futures exchange, in approximately 12 minutes. According to Chainalysis's post-incident analysis, the attack did not exploit a smart contract bug. Instead, attackers spent months building relationships with Drift team members and used Solana's "durable nonces" feature to get Drift Security Council members to unknowingly pre-sign transactions that transferred admin control.

Once in control, attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. The attack wiped out more than 50% of Drift's total value locked.

KelpDAO — April 18, 2026 — $292 million

Attackers compromised the off-chain infrastructure supporting KelpDAO's cross-chain bridge, built on LayerZero. The breach targeted a 1-of-1 DVN (Decentralized Verifier Network) setup. By poisoning the RPC nodes the single verifier relied on and DDoS-ing external nodes, attackers caused the system to attest to a fabricated cross-chain message claiming 116,500 rsETH had been locked when no such transaction existed.

The Ethereum contract released the funds based on the phantom attestation. According to OpenZeppelin's analysis, no smart contract bugs were found — the contracts performed exactly as designed. The failure was entirely in the off-chain verification infrastructure.

The downstream impact extended across more than 20 blockchains where wrapped rsETH circulated. Approximately 89,567 rsETH was deposited on Aave as collateral to borrow $190 million in WETH — against assets now backed by nothing.

Bridge Exploits: The Persistent Structural Weakness

Cross-chain bridges have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value ever hacked in Web3, according to data compiled by Phemex Research. The 2022 peak included the Ronin Bridge ($625M), Wormhole ($320M), and Nomad ($190M).

The KelpDAO exploit demonstrates that the bridge vulnerability surface has not narrowed despite four years of industry attention. A bridge custodying wrapped assets across 20 chains represents a single point of failure for every protocol downstream. The concentration of trust in off-chain verification systems — particularly those with insufficient redundancy — creates exploitable chokepoints that attackers can target without writing a single line of exploit code.

Bridge TVL has declined below $45 billion following the 2026 exploit spree, according to Times of Blockchain, reflecting reduced user confidence in cross-chain infrastructure.

North Korea: State-Level Threat Actor

Multiple attribution sources converge on the same conclusion: North Korean state-backed hackers dominated crypto theft in H1 2026.

| Source | DPRK Attribution | Percentage of Total | |--------|-----------------|---------------------| | TRM Labs | $643 million | 66% | | Blockaid | ~$605 million | 55% | | Chainalysis | ~76% of global losses | 76% |

TRM Labs attributes the bulk of DPRK-linked theft to two April incidents — Drift ($285M) and KelpDAO ($292M) — totaling $577 million. The group's cumulative crypto theft since 2017 exceeds $6 billion, according to TRM Labs data presented in Congressional testimony on May 21, 2026.

TRM Labs' Ari Redbord testified before the House Committee on Financial Services that the 2026 campaign represents a qualitative shift. The Drift attack involved North Korean operatives spending months in person building relationships with protocol personnel — a tactic Redbord described as "unprecedented in North Korea's crypto hacking campaign."

The proceeds fund North Korea's nuclear weapons program, according to U.S. government assessments cited in the Congressional testimony.

Network-Level Breakdown

Ethereum and Solana absorbed the largest losses by network in H1 2026, though the attack vectors differed substantially:

| Network | Estimated Losses | Primary Vector | |---------|-----------------|----------------| | Ethereum | ~$332 million | Smart contract vulnerabilities | | Solana | ~$326 million | Compromised keys and signing infrastructure (98%+) |

On Solana, more than 98% of losses stemmed from compromised keys and signing infrastructure rather than code exploits, per Blockaid's dataset. On Ethereum, smart contract code vulnerabilities remained the primary vector, though the KelpDAO exploit — the largest Ethereum-related loss — was an infrastructure attack rather than a code bug.

EVM Layer-2 exploits also represented a growing share of the attack surface as more value migrated to rollups and sidechains.

The Bug Bounty Counterweight

Immunefi's H1 2026 data provides a measure of the security industry's defensive output:

  • $13.45 million paid to researchers for 837 valid bug reports
  • 92,000+ registered security researchers on the platform
  • $180 billion+ in protocol assets under coverage across 650+ protocols
  • $140 million in cumulative lifetime researcher payouts (milestone crossed June 2026)
  • $25 billion+ in estimated prevented losses from disclosed vulnerabilities

The platform's defensive economics are asymmetric: $13.45 million in bounty payments against $972 million in actual losses suggests the cost of defense remains a fraction of the cost of failure. However, bug bounties primarily address code-level vulnerabilities. The 74% of losses attributable to operational security failures fall largely outside the scope of traditional bug bounty programs, which focus on smart contract code review.

This gap represents a structural mismatch. The industry has built a functional marketplace for code auditing. No equivalent marketplace exists for operational security assessment of protocol teams, their key management practices, or their infrastructure dependencies.

July 2026: The Pace Continues

July 2026 data, not yet captured in the H1 reports, shows the attack cadence continuing:

  • Summer.fi (July 6): $6 million drained via flash loan manipulation of asset share accounting. The attacker used a $65.4 million flash loan to inflate protocol balances and extract the spread.
  • Allbridge Core (July 19): $1.65 million lost through a flash-loan-driven pool imbalance on Solana — the same chain and same vector the protocol had previously patched, but the fix had not been applied to Solana pools.
  • Lien Finance (July 24): $542,000 in USDC stolen through manipulation of a flawed bond-verification function in the protocol's OTC pools.
  • Weekly total (July 19-25): More than $47 million in confirmed losses across incidents at AFX Trade, Wanchain, Verus, Allbridge Core, B² Network, and Lien Finance.

The July incidents reinforce the H1 pattern: frequent, smaller-scale attacks exploiting specific protocol-level weaknesses, with bridge and cross-chain infrastructure remaining disproportionately targeted.

Key Takeaways

  • 212 incidents in H1 2026 represent the highest attack count ever recorded for a six-month period, even as total dollar losses fell 57% year-over-year.
  • 74% of stolen funds came from operational security failures — compromised keys, social engineering, infrastructure poisoning — not from smart contract code exploits.
  • Two incidents (Drift, KelpDAO) accounted for 44% of all losses and both exploited human and infrastructure weaknesses, not code bugs.
  • North Korean actors accounted for 55-76% of losses depending on the attribution source, with cumulative theft since 2017 exceeding $6 billion.
  • Cross-chain bridges have produced $2.8 billion in cumulative losses since 2022, approximately 40% of all value ever hacked in Web3.
  • Bug bounty programs paid $13.45 million for 837 valid bugs in H1 2026, but primarily cover code-level vulnerabilities — not the operational failures driving most losses.
  • The security gap is structural: the industry has mature code auditing infrastructure but lacks equivalent frameworks for operational security assessment.

Conclusion

The H1 2026 data describes an industry that has partially solved one security problem while exposing another. Smart contract auditing has matured to the point where code-level exploits, while still frequent, produce a small minority of financial damage. The dominant threat vector has shifted to operational security — the humans, keys, infrastructure, and processes that surround the code.

This shift has implications for how protocols allocate security spending. Code audits and bug bounties address approximately 11-26% of the loss surface. The remaining 74-88% requires investment in key management practices, multisig governance procedures, infrastructure redundancy, and personnel security — areas where the crypto industry has historically underinvested relative to traditional financial institutions.

The concentration of losses in state-backed actors, particularly North Korea's Lazarus Group, adds a dimension that individual protocol security teams are not equipped to address alone. The Drift attack — where operatives spent months building in-person relationships to compromise multisig signers — represents a threat model that no smart contract audit can defend against.

The data suggests that the next phase of crypto security will be defined less by what happens on-chain and more by what happens around it.

Sources & References

  1. Blockaid H1 2026 Report — Crypto Hacks Cross $1.1B in Record H1 2026 Losses — Published July 29, 2026. Primary dataset for incident count and loss totals.
  2. Immunefi H1 2026 Report — Crypto Hack Losses Fall Below $1B Despite Record Attack Volume — Parallel dataset with 207 incidents and $972M in losses.
  3. TRM Labs — H1 2026 Crypto Hacks Reach Record High — North Korea attribution data and $643M DPRK estimate.
  4. Chainalysis — Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Post-incident technical analysis of the Drift exploit.
  5. Chainalysis — Inside the KelpDAO Bridge Exploit — Technical breakdown of the KelpDAO infrastructure compromise.
  6. OpenZeppelin — $292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — Analysis confirming no smart contract vulnerabilities in KelpDAO.
  7. CoinDesk — The $292M Kelp DAO Exploit Shows Why Crypto Bridges Are Still the Weakest Link — Bridge vulnerability analysis.
  8. Forbes — Fewer But Far More Surgical: Crypto Hacks Hit $1.3B in 2026 — Industry analysis of attack pattern shifts.
  9. TRM Labs — Ari Redbord Congressional Testimony, May 21, 2026 — Congressional testimony on DPRK crypto theft.
  10. CryptoTimes — Crypto Loses Over $47M in a Week — July 2026 weekly incident data.
  11. The Block — North Korea Accounts for 76% of 2026 Crypto Hack Losses — DPRK cumulative theft exceeding $6B.
  12. Phemex — Every Major DeFi Hack in 2026: Bridge Exploits Dominate — Cumulative bridge losses of $2.8B since 2022.