Alisa Davidson
Revealed: July 29, 2026 at 4:07 am Up to date: July 29, 2026 at 4:07 am
Edited and fact-checked:
July 29, 2026 at 4:07 am
In Temporary
H1 2026 blockchain exploits hit document 212 incidents, $1.1B misplaced; DPRK actors prompted 55% and personal key compromises drove 74% of whole harm.

The primary half of 2026 marked essentially the most exploited interval in blockchain historical past, with onchain safety agency Blockaid verifying 212 incidents totalling $1.1 billion in losses — representing 3.4 instances the variety of high-threshold exploits recorded throughout all of 2025. Whereas whole greenback losses fell wanting 2025’s figures, largely as a result of no single occasion rivalled the $1.5 billion Bybit breach, the sheer quantity and class of assaults sign a structural escalation within the menace panorama.


Loss focus remained pronounced. The 4 largest incidents — KelpDAO at $292M, Drift Protocol at $285M, Resolv at $80M, and CowSwap at $50.4M — collectively accounted for roughly 64% of all H1 losses. Two of those, KelpDAO and Drift, are instantly attributed to TraderTraitor, a sub-group of North Korea’s Lazarus Group. Mixed with the individually attributed Humanity Protocol breach of $32M, DPRK-linked actors have been answerable for roughly $609 million, or 55% of the half-year whole.
Compromised personal keys emerged because the dominant loss driver by a large margin, answerable for practically $789 million — round 74% of all H1 harm — throughout roughly ten incidents. Each top-tier assaults started not with a contract vulnerability however with social engineering: DPRK operators focused staff at Drift and KelpDAO by way of LinkedIn-style manipulation, finally gaining management over multisig signers and bridge verifier infrastructure. The KelpDAO breach, specifically, exploited a single-DVN configuration within the LayerZero bridge to forge a cross-chain attestation and drain $292 million from an Ethereum escrow.
Legacy Blind Spots and Novel Vectors Broaden the Assault Floor
Code exploits, whereas far more cost effective in mixture at $203 million, dominated by incident depend, comprising practically 80% of all circumstances. Resolv’s $80 million unbacked mint was the biggest on this class. A smaller however recurring sample concerned legacy or deprecated contracts that groups had migrated away from however not absolutely decommissioned. 5 such incidents in Could and June — together with two separate assaults on the Aztec Join rollup and a validation exploit on Raydium’s deprecated AMM V3 — totalled roughly $5.7 million, underscoring that migration timelines should not equal to sunsets.

Three novel assault vectors made their first appearances in H1. EIP-7702 pockets delegation, launched by a brand new Ethereum commonplace, was abused throughout 4 incidents. An AI immediate injection assault on the Bankr agent in Could — the primary of its type — extracted $216,000 by tricking an autonomous system into authorising an unauthorised transaction. Off-chain bridge prover infrastructure was additionally newly focused, with KelpDAO and Taiko each breached by way of cast proofs accepted by vacation spot chains.
Restoration outcomes proved sharply uneven. Code exploits typically yielded partial fund restoration by way of emergency pause features or onchain coordination. Key compromises, in contrast, noticed near-zero retrieval, with stolen property usually routed by way of mixers inside hours. Probably the most profitable containment of the interval occurred on Stellar, the place real-time pockets clustering by Blockaid enabled validators to quarantine $7.3 million — 73% of a $10.2 million oracle manipulation drain — inside minutes of the assault.
Disclaimer
In keeping with the Belief Challenge tips, please notice that the data supplied on this web page isn’t meant to be and shouldn’t be interpreted as authorized, tax, funding, monetary, or every other type of recommendation. You will need to solely make investments what you possibly can afford to lose and to hunt impartial monetary recommendation in case you have any doubts. For additional data, we advise referring to the phrases and situations in addition to the assistance and assist pages supplied by the issuer or advertiser. MetaversePost is dedicated to correct, unbiased reporting, however market situations are topic to vary with out discover.
About The Writer
Alisa, a devoted journalist on the MPost, makes a speciality of crypto, AI, investments, and the expansive realm of Web3. With a eager eye for rising tendencies and applied sciences, she delivers complete protection to tell and interact readers within the ever-evolving panorama of digital finance.
Extra articles

Alisa, a devoted journalist on the MPost, makes a speciality of crypto, AI, investments, and the expansive realm of Web3. With a eager eye for rising tendencies and applied sciences, she delivers complete protection to tell and interact readers within the ever-evolving panorama of digital finance.

