Key Takeaways
Blockaid verified a record 212 crypto exploits in H1 2026.OpSec and key theft caused 74% of losses, with Drift and KelpDAO losing $577M.Blockaid expects rising EIP-7702 and AI prompt-injection attacks in H2 2026.
North Korean Hackers Drive $600M in Stolen Funds
The first half of 2026 marked the most active period for onchain security threats on record, with security firm Blockaid noting a 3.4-fold increase in high-threshold exploits over all of 2025. According to Blockaid’s H1 2026 Onchain Security Report, total dollar losses reached $1.1 billion, trailing the first half of 2025 due to the absence of a single multibillion-dollar mega-heist.
However, the volume and technical sophistication of attacks escalated dramatically. Study data show attackers carried out 212 verified exploits during the six months, peaking in June with 57 separate incidents. Just four major incidents accounted for $707 million, or 64%, of total stolen funds. North Korea’s “Trader Traitor” hacking cluster, tied to the Lazarus Group, was responsible for approximately $609 million of overall losses, Blockaid said.
A majority of financial losses were concentrated in a handful of high-profile security breaches driven by North Korean state-sponsored threat actors. The period’s two largest exploits, restaking protocol KelpDAO ($292 million) and Solana perpetual DEX Drift Protocol ($285 million), were both attributed to Trader Traitor.
Rather than relying on smart contract bugs, these attacks targeted human and operational vectors. In the Drift breach, weeks of targeted social engineering granted attackers administrative multisig control, resulting in $285 million stolen in less than 12 minutes. In the KelpDAO exploit, attackers used social engineering against a LayerZero developer to poison RPC infrastructure and forge cross-chain bridge attestations.
Meanwhile, the report highlighted three major security boundaries that emerged in the first half of 2026 — areas historically outside standard audit scopes: EIP-7702 wallet delegation attacks, AI prompt injection, and off-chain bridge infrastructure. To highlight the threat posed by AI vulnerabilities, the report pointed to a May incident in which an attacker “used prompt injection to trick Bankr’s AI agent into approving an unauthorized transaction, taking $216K”.
Recovery rates remained starkly split depending on the attack vector. Stolen funds stemming from key compromises vanished almost immediately into mixers or cross-chain bridges. Conversely, protocol bugs occasionally allowed for partial or full recovery through swift white-hat coordination or contract pauses.
Looking ahead, Blockaid warns that Web3 ecosystems should prepare for continued pressure in the second half of the year. Key areas of concern include persistent social engineering campaigns by sanctioned nation-state actors, scaling exploits around EIP-7702 wallet delegation features, and a rapid rise in prompt-injection attacks against autonomous AI trading agents as adoption grows across decentralized finance.






