Three independent security firms — Blockaid, Immunefi, and Quill Audits — converged on the same conclusion in late July 2026: the first half of the year produced more verified crypto exploit incidents than any comparable period in the sector's history. Blockaid counted 212 high-threshold exploits...
"Less than 1% of the industry uses firewalls, and fewer than 10% use AI detection tools." — Mitchell Amador, CEO, Immunefi
Three independent security firms — Blockaid, Immunefi, and Quill Audits — converged on the same conclusion in late July 2026: the first half of the year produced more verified crypto exploit incidents than any comparable period in the sector's history. Blockaid counted 212 high-threshold exploits totaling $1.1 billion in losses. Immunefi tracked 207 incidents at $972 million. Quill Audits logged 87 DeFi-specific hacks at $935.3 million. The figures differ by methodology, but the direction is unanimous.
The paradox: total dollar losses remain below the $2.58 billion recorded in H1 2025, when the $1.5 billion Bybit exploit alone accounted for 58% of that figure. In H1 2026, attacks are more frequent but individually smaller — the median loss per incident has fallen from $6 million in 2022 to approximately $1.5 million. The threat is diffuse rather than concentrated. Operational security failures, not smart contract bugs, drove 74% of dollar losses. And a new category — AI agent prompt injection — made its first recorded appearance.
Blockaid's H1 2026 Onchain Security Report, published July 28, 2026, documented 212 verified exploits — a 3.4x increase in incident volume over all of 2025. The monthly trajectory rose from 18 incidents in January to 57 in June, with April representing the costliest single month at $635 million in aggregate losses.
The three reporting firms' figures:
| Firm | Incidents | Total Losses | Scope | |------|-----------|-------------|-------| | Blockaid | 212 | $1.1B | All onchain exploits | | Immunefi | 207 | $972M | Hacks and scams | | Quill Audits | 87 | $935.3M | DeFi-specific |
Despite the record incident count, dollar losses remain well below historical peaks. DeFi exploit losses have fallen 74% from their 2022 peak of $2.62 billion, according to Immunefi. Bridge exploits, which represented 73% of losses in 2022, accounted for just 3% in the latest reporting period. Flash loan attacks dropped from 54% of losses to less than 1%.
The shift suggests improved smart contract security at the code level — and a corresponding migration of attacker focus toward operational infrastructure and human targets.
Four breaches accounted for $707 million, or 64% of total H1 2026 losses per Blockaid's count.
KelpDAO — $292 million (April 18, 2026) The largest single exploit of 2026. Attackers compromised KelpDAO's LayerZero bridge infrastructure by exploiting a 1-of-1 verifier configuration. The protocol relied on a single node to validate cross-chain messages before releasing funds. Attackers forced legitimate nodes offline, isolated the verifier, and fed it fraudulent cross-chain messages authorizing the release of approximately 116,500 rsETH. The theft triggered a $10 billion withdrawal cascade across lending protocols including Aave, SparkLend, and Fluid, all of which froze rsETH markets. Attribution points to North Korea's Lazarus Group via the TraderTraitor subcluster.
Drift Protocol — $285 million (April 1, 2026) Solana's largest DeFi exploit since the $326 million Wormhole bridge hack of 2022. Attackers spent months building relationships with the Drift team through LinkedIn social engineering, then used Solana's "durable nonces" feature to get Security Council members to unknowingly pre-sign transactions that transferred admin control. Once inside, the attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, ETH, and other assets across nearly 20 vaults. The entire drain took less than 12 minutes. Preliminary on-chain indicators are consistent with previously attributed DPRK operations.
Resolv — $80 million extracted / $25 million realized (March 22, 2026) An attacker deposited $200,000 in USDC and minted 80 million USR stablecoin tokens by exploiting a gap in the minting logic. The smart contract lacked maximum mint limits — it only checked that a valid off-chain signature existed. The attacker swapped USR across protocols into USDC, USDT, and then ETH, extracting approximately $25 million before the protocol was paused. USR crashed to $0.025 on Curve before partially recovering to approximately $0.85.
CoW Swap — details pending The fourth of Blockaid's "Big Four" incidents. Full loss figures have been attributed to the H1 total but individual post-mortem details remain limited in public reporting.
The distribution of attack vectors in H1 2026 reveals a structural shift in how crypto assets are stolen.
By dollar value:
By incident count:
The implication is clear: the most frequent attacks target code, but the most expensive attacks target people. Blockaid's report noted that "the working pattern of LinkedIn social engineering leading to multisig signer compromise produced two of the four largest H1 incidents, and there is no structural reason for it to stop."
Both the KelpDAO and Drift Protocol exploits followed the same template: weeks or months of social engineering targeting team members, culminating in administrative control takeover. In the Drift case, attackers specifically exploited Solana's durable nonce mechanism to collect pre-signed transactions over time without triggering immediate execution — a patient, infrastructure-level attack that no code audit would catch.
Ethereum and Solana absorbed the heaviest losses, each exceeding $300 million:
| Chain | Losses | Primary Attack Surface | |-------|--------|----------------------| | Ethereum | $332M | Smart contract exploits targeting restaking protocols, stablecoins, DEX aggregators | | Solana | $326M | Signer infrastructure compromises, administrative key takeover |
The near-parity between the two chains is notable. Ethereum's losses concentrate in protocol-level vulnerabilities — complex DeFi composability creating exploitable surfaces. Solana's losses concentrate in infrastructure-level compromises — fewer but larger exploits targeting administrative access points.
Other chains contributed to the remaining $442 million in losses, though detailed per-chain breakdowns beyond the top two have not been published.
North Korea-linked hacking groups, specifically the TraderTraitor subcluster of the Lazarus Group, were responsible for approximately $609 million in H1 2026 losses — roughly 55% of the total. The KelpDAO ($292M), Drift Protocol ($285M), and Humanity Protocol ($32M) exploits have been attributed to this group by Blockaid, Chainalysis, and Elliptic.
An existing webthreepedia report covers the DPRK crypto theft apparatus in depth. The H1 2026 data reinforces the core finding: state-sponsored actors operate at a scale and patience level that dwarfs private criminal operations. The LinkedIn social engineering campaigns used against Drift and KelpDAO involved months of relationship building — a resource investment unavailable to most independent threat actors.
In May 2026, an attacker used prompt injection to trick Bankr's AI agent into approving an unauthorized $216,000 transaction. Blockaid characterized this as the first recorded AI-agent exploit in crypto.
The incident is small in dollar terms but large in implications. Autonomous trading agents and AI-powered DeFi bots are proliferating, with deployments growing approximately tenfold annually according to Blockaid. The attack surface is novel: prompt injection targets the decision-making layer rather than the execution layer. Traditional smart contract audits do not cover this vector.
Immunefi CEO Mitchell Amador, speaking at the WAIB Summit in Monaco, attributed the broader resurgence in DeFi exploits to attacker-side AI adoption: newer frontier models allow faster discovery and exploitation of protocol flaws. He estimated a three-to-four-year lag before defenders can leverage comparable AI capabilities, and noted that "less than 1% of the industry uses firewalls, and fewer than 10% use AI detection tools."
Blockaid projected multiple AI agent incidents in H2 2026, with prompt injection leading, followed by tool-use abuse and unauthorized signing.
Ethereum's EIP-7702 upgrade, which allows externally owned accounts to delegate execution to smart contracts, introduced a new phishing surface. Blockaid recorded four EIP-7702-related incidents in H1 2026.
The attack pattern: delegation instructions are expressed as signed authorization tuples whose effects are not visible in the transaction fields users typically examine. Attackers craft authorization requests that appear harmless but install delegated code with arbitrary wallet logic. One documented case on April 28, 2026, exploited a legacy contract to route a call through an EIP-7702 delegated EOA registered as an admin, draining approximately $124,900 in QNT tokens.
According to security firm research, over 97% of EIP-7702 delegations observed on-chain are linked to identical wallet-draining contracts designed to automatically sweep incoming funds. Any smart contract wallet built before EIP-7702 is potentially vulnerable to front-running attacks waiting for authorization signatures.
The data points to a structural asymmetry between attacker and defender capabilities.
Offense advantages:
Defense deficits:
The economics are unfavorable. Bug bounty researchers surfaced 837 valid vulnerabilities for $13.45 million in rewards. Attackers exploited 212 vulnerabilities for $1.1 billion in stolen assets. The ratio of defender reward to attacker reward is approximately 82:1 in the attacker's favor.
Code-level security has measurably improved — DeFi exploit losses are down 74% from the 2022 peak, and both bridge exploits and flash loan attacks have been largely mitigated. But attackers have adapted by targeting the human and infrastructure layers where code audits provide no protection.
The H1 2026 data describes a security landscape that is improving at the code level and deteriorating at the operational level. Smart contract exploits, bridge attacks, and flash loans — the dominant vectors of 2021-2023 — have been substantially mitigated. But the aggregate loss figure continues to rise because attackers have migrated to targets that audits cannot reach: human trust, administrative key management, off-chain infrastructure, and now AI decision-making agents.
The implications for economic value in the blockchain ecosystem are direct. Every dollar stolen represents a wealth transfer from protocol users to threat actors — a cost ultimately borne by depositors, liquidity providers, and token holders. The $1.1 billion in H1 2026 losses exceeds the approximately $3.1 billion in annual base-layer blockchain fee revenue estimated across the entire industry. The security tax on the ecosystem, measured as theft relative to legitimate revenue, remains punitive.
Whether the AI-agent vector scales as projected, and whether EIP-7702 delegation attacks move from isolated incidents to systematic campaigns, will determine whether H2 2026 exceeds or breaks the pattern. The structural incentives — a 1:82 defender-to-attacker reward ratio, sub-1% firewall adoption, and a three-to-four-year projected lag in defensive AI capabilities — suggest the attack surface will continue expanding faster than the industry's capacity to defend it.