Cryptocurrency protocols suffered $1.1 billion in verified losses across 212 separate incidents during H1 2026, according to a Blockaid report published July 28, 2026. Immunefi's parallel dataset counted 207 incidents totaling $972 million. Both represent the highest incident counts ever recorded...
"What we are watching is not a North Korean campaign that is broader — it is one that is sharper." — Ari Redbord, Global Head of Policy, TRM Labs
Cryptocurrency protocols suffered $1.1 billion in verified losses across 212 separate incidents during H1 2026, according to a Blockaid report published July 28, 2026. Immunefi's parallel dataset counted 207 incidents totaling $972 million. Both represent the highest incident counts ever recorded for a six-month period.
The headline number obscures the structural shift underneath it. Per-incident losses dropped significantly from H1 2025, when the Bybit exploit alone accounted for $1.5 billion and total losses reached $2.58 billion across 63 incidents. The 2026 data shows a market where attacks are more frequent, more targeted, and increasingly directed at human and infrastructure weaknesses rather than smart contract code. Blockaid's dataset attributes 74% of stolen funds to operational security failures — compromised keys, social engineering of multisig signers, and poisoned infrastructure — rather than on-chain code vulnerabilities.
North Korea-linked actors, primarily the Lazarus Group, accounted for 55% to 66% of total losses depending on the dataset, with TRM Labs estimating DPRK-attributed theft at $643 million and cumulative theft since 2017 exceeding $6 billion.
Two independent security firms tracked H1 2026 losses and arrived at broadly consistent figures:
| Metric | Blockaid | Immunefi | |--------|----------|----------| | Total incidents | 212 | 207 | | Total losses | $1.1 billion | $972 million | | H1 2025 comparison | $2.58 billion (63 incidents) | ~$2.3 billion | | Year-over-year loss change | -57% | -57% | | Largest single incident | KelpDAO ($292M) | Drift Protocol ($285M) |
The discrepancy between the two datasets reflects methodological differences in incident classification and verification timelines. Blockaid includes a broader set of verified incidents; Immunefi applies stricter deduplication criteria. The directional conclusion is identical: more attacks, less money lost per event.
Smart contract exploits accounted for 125 of 207 incidents in Immunefi's count, making them the most frequent attack type. However, they represented only approximately 11% of total dollar losses. The remaining 88.3% of financial damage came from operational and infrastructure compromises — a ratio that represents a fundamental inversion from the 2021-2022 era when reentrancy bugs and flash loan manipulations drove the largest losses.
Blockaid's data shows 74% of H1 2026 losses stemmed from operational security failures rather than exploited code. Chainalysis data corroborates this, attributing approximately 76% of crypto-related hack losses globally in 2026 to attacks targeting key management, multisig governance, and signing infrastructure.
The pattern is consistent: attackers are moving up the stack. Rather than searching for logic errors in audited Solidity code, they target the humans and systems that hold the keys to deploy, upgrade, or authorize transactions on those contracts.
This is a direct consequence of improved code-level security. As protocols adopt formal verification, multiple audit rounds, and competitive audit platforms, the marginal cost of finding an exploitable smart contract bug has increased. Operational infrastructure — RPC nodes, multisig coordination processes, team communication channels — has not received equivalent hardening.
The economic logic is straightforward. A compromised multisig key yields access to every asset the protocol controls. A smart contract bug yields access to the specific vulnerability surface. Attackers follow the higher expected value.
Nearly 44% of all H1 2026 losses came from two incidents, both in April, both attributed to North Korean actors, and both exploiting operational rather than code-level vulnerabilities.
Drift Protocol — April 1, 2026 — $285 million
Attackers drained Drift, a Solana-based decentralized futures exchange, in approximately 12 minutes. According to Chainalysis's post-incident analysis, the attack did not exploit a smart contract bug. Instead, attackers spent months building relationships with Drift team members and used Solana's "durable nonces" feature to get Drift Security Council members to unknowingly pre-sign transactions that transferred admin control.
Once in control, attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. The attack wiped out more than 50% of Drift's total value locked.
KelpDAO — April 18, 2026 — $292 million
Attackers compromised the off-chain infrastructure supporting KelpDAO's cross-chain bridge, built on LayerZero. The breach targeted a 1-of-1 DVN (Decentralized Verifier Network) setup. By poisoning the RPC nodes the single verifier relied on and DDoS-ing external nodes, attackers caused the system to attest to a fabricated cross-chain message claiming 116,500 rsETH had been locked when no such transaction existed.
The Ethereum contract released the funds based on the phantom attestation. According to OpenZeppelin's analysis, no smart contract bugs were found — the contracts performed exactly as designed. The failure was entirely in the off-chain verification infrastructure.
The downstream impact extended across more than 20 blockchains where wrapped rsETH circulated. Approximately 89,567 rsETH was deposited on Aave as collateral to borrow $190 million in WETH — against assets now backed by nothing.
Cross-chain bridges have produced more than $2.8 billion in cumulative losses since 2022, representing approximately 40% of all value ever hacked in Web3, according to data compiled by Phemex Research. The 2022 peak included the Ronin Bridge ($625M), Wormhole ($320M), and Nomad ($190M).
The KelpDAO exploit demonstrates that the bridge vulnerability surface has not narrowed despite four years of industry attention. A bridge custodying wrapped assets across 20 chains represents a single point of failure for every protocol downstream. The concentration of trust in off-chain verification systems — particularly those with insufficient redundancy — creates exploitable chokepoints that attackers can target without writing a single line of exploit code.
Bridge TVL has declined below $45 billion following the 2026 exploit spree, according to Times of Blockchain, reflecting reduced user confidence in cross-chain infrastructure.
Multiple attribution sources converge on the same conclusion: North Korean state-backed hackers dominated crypto theft in H1 2026.
| Source | DPRK Attribution | Percentage of Total | |--------|-----------------|---------------------| | TRM Labs | $643 million | 66% | | Blockaid | ~$605 million | 55% | | Chainalysis | ~76% of global losses | 76% |
TRM Labs attributes the bulk of DPRK-linked theft to two April incidents — Drift ($285M) and KelpDAO ($292M) — totaling $577 million. The group's cumulative crypto theft since 2017 exceeds $6 billion, according to TRM Labs data presented in Congressional testimony on May 21, 2026.
TRM Labs' Ari Redbord testified before the House Committee on Financial Services that the 2026 campaign represents a qualitative shift. The Drift attack involved North Korean operatives spending months in person building relationships with protocol personnel — a tactic Redbord described as "unprecedented in North Korea's crypto hacking campaign."
The proceeds fund North Korea's nuclear weapons program, according to U.S. government assessments cited in the Congressional testimony.
Ethereum and Solana absorbed the largest losses by network in H1 2026, though the attack vectors differed substantially:
| Network | Estimated Losses | Primary Vector | |---------|-----------------|----------------| | Ethereum | ~$332 million | Smart contract vulnerabilities | | Solana | ~$326 million | Compromised keys and signing infrastructure (98%+) |
On Solana, more than 98% of losses stemmed from compromised keys and signing infrastructure rather than code exploits, per Blockaid's dataset. On Ethereum, smart contract code vulnerabilities remained the primary vector, though the KelpDAO exploit — the largest Ethereum-related loss — was an infrastructure attack rather than a code bug.
EVM Layer-2 exploits also represented a growing share of the attack surface as more value migrated to rollups and sidechains.
Immunefi's H1 2026 data provides a measure of the security industry's defensive output:
The platform's defensive economics are asymmetric: $13.45 million in bounty payments against $972 million in actual losses suggests the cost of defense remains a fraction of the cost of failure. However, bug bounties primarily address code-level vulnerabilities. The 74% of losses attributable to operational security failures fall largely outside the scope of traditional bug bounty programs, which focus on smart contract code review.
This gap represents a structural mismatch. The industry has built a functional marketplace for code auditing. No equivalent marketplace exists for operational security assessment of protocol teams, their key management practices, or their infrastructure dependencies.
July 2026 data, not yet captured in the H1 reports, shows the attack cadence continuing:
The July incidents reinforce the H1 pattern: frequent, smaller-scale attacks exploiting specific protocol-level weaknesses, with bridge and cross-chain infrastructure remaining disproportionately targeted.
The H1 2026 data describes an industry that has partially solved one security problem while exposing another. Smart contract auditing has matured to the point where code-level exploits, while still frequent, produce a small minority of financial damage. The dominant threat vector has shifted to operational security — the humans, keys, infrastructure, and processes that surround the code.
This shift has implications for how protocols allocate security spending. Code audits and bug bounties address approximately 11-26% of the loss surface. The remaining 74-88% requires investment in key management practices, multisig governance procedures, infrastructure redundancy, and personnel security — areas where the crypto industry has historically underinvested relative to traditional financial institutions.
The concentration of losses in state-backed actors, particularly North Korea's Lazarus Group, adds a dimension that individual protocol security teams are not equipped to address alone. The Drift attack — where operatives spent months building in-person relationships to compromise multisig signers — represents a threat model that no smart contract audit can defend against.
The data suggests that the next phase of crypto security will be defined less by what happens on-chain and more by what happens around it.