{"id":35731,"date":"2026-07-29T05:09:58","date_gmt":"2026-07-29T05:09:58","guid":{"rendered":"https:\/\/bitunikey.com\/news\/crypto-security-losses-hit-1-1b-in-h1-2026-blockaid-report\/"},"modified":"2026-07-29T05:10:37","modified_gmt":"2026-07-29T05:10:37","slug":"crypto-security-losses-hit-1-1b-in-h1-2026-blockaid-report","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/crypto-security-losses-hit-1-1b-in-h1-2026-blockaid-report\/","title":{"rendered":"Crypto security losses hit $1.1B in H1 2026: Blockaid report"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Crypto security losses reached $1.1 billion across 212 verified incidents during the first half of 2026, according to an H1 report published by Blockaid on July 28.\u00a0<\/p>\n<div id=\"cn-block-summary-block_f72b6ef4f262a49ef01f7eaba0e0f860\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>212 verified incidents caused $1.1 billion in losses during 2026\u2019s record-breaking first six months globally.<\/li>\n<li>74% of stolen funds resulted from operational security failures rather than exploited smart contract code.<\/li>\n<li>One DPRK-linked cluster accounted for 55% of losses alone, according to Blockaid\u2019s verified incident dataset.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Blockaid <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.blockaid.io\/h1-report-2026\" target=\"_blank\" rel=\"nofollow\">described<\/a> the six-month incident count as a record and said it verified more exploits during H1 than throughout 2025.<\/p>\n<p>Cperational security attacks caused 74% of the stolen value, while one cluster associated with the Democratic People\u2019s Republic of Korea accounted for 55%. Blockaid also said the incident count was 3.4 times its 2025 total, though security companies use different definitions and coverage methods when compiling industry loss estimates.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">$1.1B lost across 212 onchain exploits in H1 2026, more than all of 2025 combined.<\/p>\n<p>\u2193 What Blockaid&#8217;s data reveals about where the losses came from, and what onchain teams should watch in H2: <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/bkB5ZzMnNk\">https:\/\/t.co\/bkB5ZzMnNk<\/a><\/p>\n<p>\u2014 Blockaid (@blockaid_) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/blockaid_\/status\/2082127793916145944?ref_src=twsrc%5Etfw\">July 28, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Blockaid says operational failures drove crypto security losses<\/strong><\/h2>\n<p>Blockaid\u2019s figures point to a shift away from attacks that depend only on faulty smart-contract code. Compromised devices, privileged credentials, private keys, signing systems and off-chain infrastructure produced most of the measured losses. These attacks can generate valid-looking blockchain transactions because authorised credentials approve them.<\/p>\n<p>That pattern reduces the protection offered by code audits alone. Audits can identify contract flaws, but they cannot stop a compromised administrator from signing a malicious transaction or prevent a bridge verifier from relying on poisoned infrastructure. Blockaid said new attack vectors emerged during H1 and warned that some could expand during the second half.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Ethereum and Solana suffered different attack patterns<\/strong><\/h2>\n<p>Ethereum-related projects lost about $332 million, according to Blockaid\u2019s report, with code vulnerabilities responsible for much of that total. The largest Ethereum-linked case was KelpDAO, where attackers released 116,500 rsETH worth roughly $292 million from a bridge contract after falsifying a source-chain message.<\/p>\n<p>Solana-related projects lost about $326 million. More than 98% came from compromised keys and signing infrastructure rather than smart-contract bugs, Blockaid found. Drift Protocol and Step Finance accounted for most of that amount, while smaller code-related incidents affected projects including Raydium and Volo.<\/p>\n<p>The network comparison does not establish that one blockchain is inherently safer. Instead, it reflects which applications were attacked and how their teams managed privileged access. A single large incident can also dominate a six-month network total.<\/p>\n<h2 class=\"wp-block-heading\"><strong>KelpDAO and Drift dominated H1 theft<\/strong><\/h2>\n<p>Chainalysis <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.chainalysis.com\/blog\/kelpdao-bridge-exploit-april-2026\/\" target=\"_blank\" rel=\"nofollow\">linked<\/a> the April 18 KelpDAO attack to North Korea\u2019s Lazarus Group. Its investigation found that attackers compromised internal RPC nodes and disrupted external nodes, causing a single-verifier system to accept a false burn event. The Ethereum-side bridge then released rsETH even though no corresponding tokens had been destroyed on the source chain.<\/p>\n<p>As crypto.news reported, KelpDAO completed the operational phase of its recovery plan on May 25 after transferring a final 20,373.72 rsETH tranche into its bridge adapter. Minting, redemptions and rewards resumed, although litigation and disputed claims involving frozen funds remained unresolved.<\/p>\n<p>Drift suffered a separate privileged-access attack on April 1. Chainalysis said attackers used months of social engineering and pre-signed durable-nonce transactions to gain administrative control. Drift\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.drift.trade\/updates\/incident-recovery-update-april-16-2026-now\" target=\"_blank\" rel=\"nofollow\">April 16 recovery update<\/a> valued stolen assets at $295.7 million, above the roughly $285 million early estimate used by Blockaid and several investigators.<\/p>\n<p>In related coverage, crypto.news reported that Step Finance shut down after attackers compromised executive devices and drained up to $40 million from treasury-controlled assets. The company recovered about $4.7 million but said financing and acquisition talks did not produce a sustainable path forward.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Recovery continues while stolen funds remain active<\/strong><\/h2>\n<p>Drift proposed a recovery pool supported by exchange revenue, Tether and other partners. Its plan included up to $127.5 million of proposed support from Tether, $20 million from other partners and a separate transferable recovery token. The protocol said its restart would require audits by OtterSec and Asymmetric, dedicated signing devices, timelocks and a redesigned multisig.<\/p>\n<p>The theft remains an active on-chain case. As previously reported, a wallet tied to the Drift exploiter moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash between July 23 and July 24 after roughly three months of inactivity.<\/p>\n<p>Blockaid expects teams to focus more heavily on transaction-intent checks, isolated signing devices, key segregation and monitoring across bridges and infrastructure. Those measures are company recommendations, not guarantees.<\/p>\n<p>The next verified updates will come from Drift\u2019s recovery-token terms and relaunch schedule, Step Finance\u2019s remaining claims process, court proceedings tied to frozen KelpDAO funds and any asset seizures announced by law-enforcement agencies.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Crypto security losses reached $1.1 billion across 212 verified incidents during the first half of 2026, according to an H1 report published by Blockaid on July 28.\u00a0 Summary 212 verified&hellip;<\/p>\n","protected":false},"author":1,"featured_media":13174,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35731","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35731"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35731\/revisions"}],"predecessor-version":[{"id":35732,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35731\/revisions\/35732"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/13174"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}