← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Record 207 Crypto Hacks in H1 2026, DPRK Takes 66%

Zephyra|August 6, 2026|BPF
EXECUTIVE SUMMARY

The cryptocurrency industry recorded its highest-ever six-month incident count in the first half of 2026. Immunefi tracked 207 separate hack events totaling $972 million in losses. Blockaid's independent tally put the figure at 212 incidents and $1.1 billion. CertiK, using a broader methodology t...

"We made a mistake. The 1-of-1 DVN configuration directly contradicted our standing recommendation." — Bryan Pellegrino, CEO, LayerZero Labs

Executive Summary

The cryptocurrency industry recorded its highest-ever six-month incident count in the first half of 2026. Immunefi tracked 207 separate hack events totaling $972 million in losses. Blockaid's independent tally put the figure at 212 incidents and $1.1 billion. CertiK, using a broader methodology that includes phishing, logged $1.32 billion across 344 incidents — a 46.8% decline year-over-year in dollar terms, but only because H1 2025 was inflated by the $1.5 billion Bybit hack. Remove that single outlier, and H1 2026 losses were approximately 28% higher than the comparable period.

Two North Korean operations — the $292 million KelpDAO bridge exploit on April 18 and the $285 million Drift Protocol governance hijack on April 1 — accounted for more than 70% of Q2 losses. TRM Labs estimated DPRK-linked groups stole $643 million in H1 2026, representing 66% of all funds stolen. The attack surface has shifted decisively: compromised accounts and social engineering now cause more damage than smart contract bugs, and AI-agent infrastructure is emerging as the next exploit frontier.

Table of Contents

  1. H1 2026 by the Numbers
  2. The Two Attacks That Defined the Half
  3. Bridge Exploits: The Persistent Vulnerability
  4. DPRK's Expanding Crypto Campaign
  5. Attack Vector Shift: People Over Code
  6. AI Agents: The Emerging Threat
  7. Recovery Rates and Insurance Gaps
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

H1 2026 by the Numbers

Three independent security firms published H1 2026 retrospectives in late July, each using different methodologies. Their findings converge on a single conclusion: more attacks, more often.

| Metric | Immunefi | Blockaid | CertiK | |--------|---------|---------|--------| | Incidents | 207 | 212 | 344 | | Total Losses | $972M | $1.1B | $1.32B | | YoY Change (Losses) | -57% | N/A | -46.8% | | Record? | Highest incident count ever | Most incidents in any H1 | Most-hacked quarter (Q2) |

The discrepancies reflect scope: Immunefi covers protocol exploits and bridge hacks; Blockaid adds wallet-level attacks; CertiK includes phishing campaigns. What all three confirm is that H1 2026 set the highest-ever six-month incident count, regardless of methodology.

CertiK's quarterly breakdown shows acceleration. Q1 recorded $508.2 million in losses, driven primarily by phishing. Q2 surged 59% to $807.5 million, with two state-sponsored attacks responsible for the bulk. Q2 2026 logged 83 separate exploits through June 22, making it the most attack-heavy quarter on record by incident count.

The longer trend line offers limited comfort. DeFi exploit losses have fallen 74% from the 2022 peak of $2.62 billion to $680.3 million, according to Immunefi. But median loss per exploit also dropped 75% over the same period — meaning attackers are launching far more operations at smaller individual scale, a pattern consistent with industrialized, state-backed campaigns rather than opportunistic lone actors.

The Two Attacks That Defined the Half

KelpDAO: $292 Million (April 18)

The largest single exploit of 2026 did not involve a smart contract vulnerability. On April 18, attackers drained 116,500 rsETH from KelpDAO's bridge, built on LayerZero's cross-chain messaging protocol.

The attack chain began on March 6, when an attacker socially engineered a LayerZero Labs developer, harvesting session keys and pivoting into LayerZero's RPC cloud environment. From there, the attacker poisoned internal RPC nodes while simultaneously DDoS-ing external nodes. This fed false data into what KelpDAO had configured as a 1-of-1 DVN (Decentralized Verifier Network) setup — a single-point-of-failure verification architecture. A phantom token burn convinced the Ethereum-side contract to release the rsETH.

LayerZero Labs acknowledged the flaw, stating the 1-of-1 DVN configuration "directly contradicted" its recommendation for diversified multi-DVN setups. The company subsequently committed to migrating all defaults to 5/5 DVN where possible and no less than 3/3. Mandiant, CrowdStrike, and independent researchers attributed the attack to TraderTraitor (UNC4899), a known Lazarus Group subunit.

Drift Protocol: $285 Million (April 1)

The second-largest exploit of 2026 was a months-long social engineering campaign targeting Drift Protocol, a Solana-based perpetuals DEX. Attackers spent months building relationships with the Drift team, then exploited Solana's "durable nonces" feature to get Drift Security Council members to unknowingly pre-sign transactions that transferred admin control.

Once in possession of governance keys, the attackers whitelisted a worthless, artificially priced fake token (CVT) as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH — all within approximately 12 minutes. TRM Labs attributes the attack to North Korean operators tied to the Lazarus Group. Elliptic logged it as the 18th DPRK-linked operation of 2026.

Bridge Exploits: The Persistent Vulnerability

Cross-chain bridges remain the most expensive single category of DeFi failure. PeckShield data through mid-May 2026 documented eight significant bridge-related incidents resulting in cumulative losses of approximately $329 million. Bridges accounted for 42% of May losses alone.

Historically, bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing roughly 40% of all value hacked in Web3, according to multiple security firms.

The Verus-Ethereum Bridge illustrated the persistent nature of bridge vulnerabilities. On May 18, an attacker drained approximately $11.58 million — 1,625 ETH, 103.6 tBTC, and 147,000 USDC — by exploiting a validation flaw where the bridge verified state roots and transaction hashes but failed to confirm actual backing asset amounts during settlement. The attacker swapped stolen assets for 5,402.4 ETH and routed funds through Tornado Cash. Security researchers noted the exploit resembled the same verification flaw class behind the 2022 Wormhole and Nomad bridge attacks.

The Verus bridge was then hit a second time on July 23 for $7.54 million, with the original flaw still unfixed.

The institutional response is consolidating around fewer, more audited infrastructure providers. On August 4, BitGo announced it selected Chainlink CCIP as its exclusive cross-chain infrastructure provider, covering more than $7.7 billion of Wrapped Bitcoin. Chainlink Labs completed a SOC 2 Type 2 examination by Deloitte & Touche LLP in April, validating the operating effectiveness of CCIP's security controls — making it the only oracle platform to hold this certification tier. CCIP's architecture includes 16 independent validator nodes and built-in rate-limit protections.

DPRK's Expanding Crypto Campaign

North Korean state-sponsored hackers have become the dominant threat actor in cryptocurrency security. TRM Labs reported DPRK-linked groups stole $643 million in H1 2026 — 66% of all cryptocurrency stolen during the period. In the first four months alone, DPRK accounted for 76% of all hack value, concentrated in just two operations (KelpDAO and Drift).

The scale is cumulative and accelerating. DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase, pushing their all-time cumulative total to $6.75 billion since 2017, according to Chainalysis and TRM Labs. Proceeds are funneled toward the regime's nuclear weapons program.

The operational pattern has evolved. Where earlier campaigns targeted exchange hot wallets through malware, 2025-2026 operations increasingly rely on long-duration social engineering, governance manipulation, and infrastructure-level compromise. Both the KelpDAO and Drift attacks required months of preparation and targeted human relationships rather than code vulnerabilities.

Attack Vector Shift: People Over Code

A structural shift in attack methodology is now statistically confirmed. Compromised accounts now represent more than 50% of all DeFi attacks by incident count, overtaking traditional smart contract exploits as the primary source of losses for the first time, according to multiple H1 reports.

CoinDesk's analysis of 2025 data — $3.4 billion stolen that year — concluded it "wasn't a smart contract problem. It was a people problem." That assessment extends into 2026. Wallet compromise is now the costliest attack vector, with attackers targeting key management, multisig governance, and operational security failures rather than on-chain logic.

The attack taxonomy is shifting accordingly:

  • Social engineering: Months-long relationship building to harvest credentials (Drift, KelpDAO)
  • Governance hijacking: Exploiting multisig or council structures to gain admin control
  • Infrastructure compromise: Targeting RPC nodes, cloud environments, and verification networks
  • Phishing at scale: $508.2 million in Q1 2026 losses attributed to phishing (CertiK)

AI Agents: The Emerging Threat

Blockaid's H1 report identified AI agent exploits as a primary threat category for H2 2026. AI agent deployments are growing roughly tenfold per year, and Blockaid expects multiple AI agent incidents with prompt injection attacks leading.

UC Berkeley researchers documented malicious AI API routers actively draining ETH wallets and injecting code into autonomous agent tools. The attack targets the routing layer between AI agents and language models — infrastructure that currently operates without meaningful security standardization.

SlowMist classified a major 2026 incident as "AI agent permission chain abuse," a category where one AI system's output is treated as trusted financial authorization by a second AI system with no independent verification of intent or source. On May 10, the first fully autonomous post-exploitation attack orchestrated by an LLM-driven agent was documented: the agent fanned out API requests through Cloudflare Workers, exfiltrated SSH private keys, pivoted to bastion servers, and enumerated SQL databases within one hour.

A 2026 Dark Reading poll found 48% of security professionals rank agentic AI as the top attack vector for the year.

Recovery Rates and Insurance Gaps

Recovery rates for stolen crypto remain structurally low for large-scale incidents. CertiK's H1 data shows $1.32 billion in gross losses and approximately $1.2 billion net after recoveries — implying roughly 9% recovery across all incidents. For individual large hacks, the picture is worse: Bybit's recovery rate sat below 5% as of early 2026.

Smaller incidents fare better. The Verus incident saw $8.5 million returned. Stellar Blend validators quarantined $7.3 million, approximately 73% of the $10.2 million stolen. A white hat working with BTCC recovered $1.8 million (78% recovery rate). But these are exceptions.

The insurance gap is significant. Nexus Mutual, the largest onchain insurance provider, reports $5.2 billion in crypto assets safeguarded and $18 million in total claims paid out — across the platform's entire history. DeFi insurance covers smart contract failures, custody events, and depeg scenarios, but excludes phishing, user error, and social engineering — precisely the attack categories now causing the most damage.

The mismatch between insured risk and actual risk is growing. If 50%+ of losses stem from compromised accounts and social engineering, and insurance policies explicitly exclude these categories, the effective coverage ratio for the industry's actual threat profile is near zero for the dominant attack vector.

Key Takeaways

  • Record incident volume: H1 2026 recorded 207-344 crypto hack incidents (depending on methodology), the highest six-month count ever documented by Immunefi, Blockaid, and CertiK independently.
  • DPRK dominance: North Korean state-sponsored hackers accounted for 66% of all stolen funds ($643M) in H1 2026, concentrated in two April operations.
  • Bridge vulnerability persists: Cross-chain bridges produced approximately $329 million in losses through mid-May, representing 42% of monthly losses and continuing a pattern responsible for $2.8 billion since 2022.
  • Human > Code: Compromised accounts surpassed smart contract bugs as the primary attack vector for the first time, with social engineering and governance hijacking replacing traditional code exploits.
  • AI agents next: Security firms expect AI agent exploits to emerge as a primary threat category in H2 2026, with prompt injection and permission chain abuse as leading attack patterns.
  • Insurance mismatch: The industry's largest DeFi insurer has paid $18 million in total claims against $1+ billion in H1 2026 losses. Dominant attack vectors (social engineering, governance manipulation) fall outside standard coverage.
  • Recovery remains low: Net recovery across all H1 incidents was approximately 9%. Large-scale hacks see recovery rates below 5%.

Conclusion

The first half of 2026 confirms a structural transformation in cryptocurrency security risk. The threat is no longer primarily technical — it is operational, organizational, and increasingly state-sponsored. North Korea's Lazarus Group and its subunits have industrialized crypto theft, running patient, months-long campaigns that target people and governance structures rather than smart contract code.

The industry's defensive infrastructure has not kept pace with this shift. Bridge architectures still concentrate verification in single points of failure. Governance structures remain vulnerable to social engineering. Insurance products exclude the attack categories now responsible for the majority of losses. And AI agent infrastructure is being deployed at scale without standardized security frameworks.

The data suggests a divergence: individual protocol security is improving (per-exploit losses down 75% from 2022), but systemic risk from state-sponsored actors and infrastructure-level compromise is increasing. The $643 million attributed to DPRK in six months represents a geopolitical problem that smart contract audits alone cannot address.

Sources & References

  1. Crypto hack losses fall below $1 billion in H1 2026 despite record attack volume: Immunefi — Immunefi H1 2026 report: 207 incidents, $972M in losses
  2. Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — Blockaid H1 2026 report: 212 incidents, $1.1B in losses
  3. CertiK Hack3D: H1 2026 Report — CertiK logs $1.32B across 344 incidents in H1 2026
  4. Fewer but far more surgical: crypto hacks hit $1.3 billion in 2026 — Forbes/CertiK CEO analysis of H1 2026 trends
  5. North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks — TRM Labs DPRK attribution data
  6. North Korea-linked hackers steal $643M in crypto in H1 2026 — DPRK H1 2026 total theft figure
  7. LayerZero says it 'made a mistake' in $292 Million Kelp exploit — LayerZero acknowledgment of DVN configuration flaw
  8. Inside the KelpDAO Bridge Exploit — Chainalysis technical analysis of KelpDAO attack
  9. Drift Protocol Hack: $285M Stolen in 12 Min — Drift Protocol attack technical breakdown
  10. Drift Protocol Hit by $285M Exploit: Crypto's Biggest Hack of 2026 — Yahoo Finance coverage of Drift hack
  11. Verus suffers $11.5M hack as bridge-related exploits hit $329M in 2026 — PeckShield bridge exploit data through May 2026
  12. Verus Ethereum Bridge hacked again for $7.54M after May exploit — Second Verus bridge exploit in July
  13. Crypto hacks hit $17 billion in 2025, but the real threat was people, not code — CoinDesk analysis of 2025 attack vector shift
  14. Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target — Blockaid AI agent threat assessment
  15. BitGo Names Chainlink CCIP Its Exclusive Cross-Chain Provider — BitGo-CCIP infrastructure consolidation
  16. Q2 2026 ramps up to close as crypto's most hacked quarter on record — Q2 2026 incident count record
  17. North Korea's $6 Billion Crypto Crime Spree: The Full Picture in 2026 — Cumulative DPRK theft statistics
  18. $292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin post-mortem analysis