Crypto Losses Hit $1.1B In First Half Of 2026 As DPRK Actors And New Attack Vectors Drive Record Incident Surge

The first half of 2026 marked probably the most exploited interval in blockchain historical past, with onchain safety agency Blockaid verifying 212 incidents totalling $1.1 billion in losses — representing 3.4 occasions the variety of high-threshold exploits recorded throughout all of 2025. While whole greenback losses fell in need of 2025’s figures, largely as a result of no single occasion rivalled the $1.5 billion Bybit breach, the sheer quantity and class of assaults sign a structural escalation within the risk panorama.


Loss focus remained pronounced. The 4 largest incidents — KelpDAO at $292M, Drift Protocol at $285M, Resolv at $80M, and CowSwap at $50.4M — collectively accounted for roughly 64% of all H1 losses. Two of those, KelpDAO and Drift, are immediately attributed to TraderTraitor, a sub-group of North Korea’s Lazarus Group. Combined with the individually attributed Humanity Protocol breach of $32M, DPRK-linked actors had been accountable for roughly $609 million, or 55% of the half-year whole.
Compromised personal keys emerged because the dominant loss driver by a large margin, accountable for almost $789 million — round 74% of all H1 injury — throughout roughly ten incidents. Both top-tier assaults started not with a contract vulnerability however with social engineering: DPRK operators focused workers at Drift and KelpDAO by LinkedIn-style manipulation, finally gaining management over multisig signers and bridge verifier infrastructure. The KelpDAO breach, particularly, exploited a single-DVN configuration within the LayerZero bridge to forge a cross-chain attestation and drain $292 million from an Ethereum escrow.
Legacy Blind Spots and Novel Vectors Expand the Attack Surface
Code exploits, whereas far less expensive in mixture at $203 million, dominated by incident rely, comprising almost 80% of all circumstances. Resolv’s $80 million unbacked mint was the biggest on this class. A smaller however recurring sample concerned legacy or deprecated contracts that groups had migrated away from however not absolutely decommissioned. Five such incidents in May and June — together with two separate assaults on the Aztec Connect rollup and a validation exploit on Raydium’s deprecated AMM V3 — totalled roughly $5.7 million, underscoring that migration timelines are usually not equal to sunsets.

Three novel assault vectors made their first appearances in H1. EIP-7702 pockets delegation, launched by a brand new Ethereum commonplace, was abused throughout 4 incidents. An AI immediate injection assault on the Bankr agent in May — the primary of its variety — extracted $216,000 by tricking an autonomous system into authorising an unauthorised transaction. Off-chain bridge prover infrastructure was additionally newly focused, with KelpDAO and Taiko each breached by solid proofs accepted by vacation spot chains.
Recovery outcomes proved sharply uneven. Code exploits typically yielded partial fund restoration by emergency pause capabilities or onchain coordination. Key compromises, in contrast, noticed near-zero retrieval, with stolen property sometimes routed by mixers inside hours. The most profitable containment of the interval occurred on Stellar, the place real-time pockets clustering by Blockaid enabled validators to quarantine $7.3 million — 73% of a $10.2 million oracle manipulation drain — inside minutes of the assault.
The submit Crypto Losses Hit $1.1B In First Half Of 2026 As DPRK Actors And New Attack Vectors Drive Record Incident Surge appeared first on Metaverse Post.
