Crypto security losses reach $1.1 billion in first half of 2026 across 212 incidents
Crypto security losses reached $1.1 billion across 212 incidents in the first half of 2026. Operational security failures, rather than smart contract bugs, drove 74% of the stolen value. A single North Korea-linked cluster accounted for 55% of the total losses, including a $292 million exploit of KelpDAO. Drift Protocol also suffered a $295.7 million compromise, while Step Finance was forced to shut down after losing $40 million.
H1 2026 crypto security losses
▪The number of verified crypto exploits in the first half of 2026 was 3.4 times the total recorded in 2025.
▪Crypto security losses reached $1.1 billion across 212 verified incidents during the first half of 2026.
Operational security failures
▪Solana-related projects lost approximately $326 million in the first half of 2026, with over 98% resulting from compromised keys and signing infrastructure.
▪Operational security failures, rather than smart contract code exploits, caused 74% of the stolen crypto funds in the first half of 2026.
▪Ethereum-related projects lost approximately $332 million in the first half of 2026, with code vulnerabilities responsible for much of the total.
North Korea-linked attacks
▪A single cluster associated with the Democratic People's Republic of Korea accounted for 55% of the crypto security losses in the first half of 2026.
▪Chainalysis linked the April 18, 2026 KelpDAO bridge exploit to North Korea's Lazarus Group.
KelpDAO bridge exploit
▪KelpDAO completed the operational phase of its recovery plan on May 25, 2026, after transferring 20,373.72 rsETH into its bridge adapter.
▪Attackers compromised internal RPC nodes to release 116,500 rsETH worth approximately $292 million from the KelpDAO bridge contract.
Drift Protocol compromise
▪A wallet tied to the Drift Protocol exploiter moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash between July 23 and July 24, 2026.
▪Attackers used months of social engineering and pre-signed durable-nonce transactions to gain administrative control of Drift Protocol.
▪Drift Protocol suffered a privileged-access attack on April 1, 2026, resulting in the theft of assets valued at $295.7 million.
Recovery efforts
▪Drift Protocol proposed a recovery pool including up to $127.5 million of support from Tether and $20 million from other partners.
▪Step Finance shut down after attackers compromised executive devices and drained up to $40 million from treasury-controlled assets.
Story comments
Loading comments…