0x6fb036616fb0…6fb03664
H1 2026 Crypto Hacks Totaled $972M Across 207 Incidents
Crypto hacks drained $972 million across 207 incidents in H1 2026, with North Korea-linked groups taking roughly $643 million. Drift Protocol and KelpDAO accounted for nearly 60% of total losses.
Outputs
207 crypto exploits stole $972 million in H1 2026, down from roughly $2.3 billion in H1 2025
Drift Protocol lost $295 million on April 1, the largest single incident, attributed to the Lazarus Group
North Korea-linked groups accounted for about $643 million, or 66% of total H1 2026 losses
April 2026 alone generated roughly $631 million in losses, nearly 68% of the half-year figure
Only THORChain fully compensated users after a top-tier exploit; more than $620 million remained effectively lost across the listed incidents
Crypto exploits drained $972 million across 207 separate incidents in the first half of 2026, according to a security compilation tracking on-chain thefts through June 30.
The figure marks a sharp decline from H1 2025, when industry losses totaled roughly $2.3 billion, even as attack frequency rose. Researchers tracking the data attributed the shift to a longer tail of smaller and medium-sized exploits rather than any meaningful hardening of smart contract code.
What did the largest incidents look like?
Two exploits accounted for roughly 60% of all H1 2026 losses.
On April 1, attackers drained approximately $295 million from Drift Protocol on Solana by compromising privileged access and manipulating collateral pricing. Investigators linked the attack to the North Korea-linked Lazarus Group. Most stolen assets bridged across networks and remain unrecovered; investigators froze only $3.36 million.
Seventeen days later, on April 18, a separate exploit on KelpDAO's LayerZero OFT bridge minted unbacked assets and stole nearly $293 million across Ethereum and Arbitrum. Security researchers attributed the attack to North Korean-backed hackers. About $71 million was frozen on Arbitrum, but most funds were laundered quickly.
How concentrated were the losses with state-backed actors?
North Korea-linked threat groups accounted for roughly $643 million, or around 66% of all crypto funds stolen during H1 2026, according to the compilation. Nearly all of that figure came from the Drift Protocol and KelpDAO attacks. Researchers wrote that the data "shows a clear difference between ordinary hackers and highly organized state-backed hacking groups carrying out much bigger attacks."
Which blockchains absorbed the most attacks?
Ethereum recorded 56 incidents, the highest of any network, followed by BNB Chain, Base, and Arbitrum. Researchers cited Ethereum's dominant DeFi ecosystem and the value of assets secured on the network as the primary drivers. Solana absorbed far fewer incidents but hosted the single largest exploit at Drift Protocol.
What attack vectors drove the largest losses?
Smart-contract flaws stayed the most frequent method, yet compromised private keys and administrator credentials drove roughly 40% of the largest individual losses. Incidents at Drift Protocol, Humanity Protocol, Resolv, Wasabi Protocol, Gravity Bridge, Fluid, StablR, and Polymarket all traced back to keys backed up on developer machines compromised through targeted malware.
Oracle manipulation remained a persistent threat, hitting Blend Pools V2, Aave V3, Sharwa Finance, Edel, and Ploutos Money. Several had passed audits before being drained through faulty price feeds.
How much was actually recovered?
Of the largest hacks, only one protocol — THORChain, following a $10.7 million GG20 TSS vulnerability exploit on May 15 — fully compensated users.
Two others, Drift Protocol and KelpDAO, froze just over $74 million combined.
More than $620 million remained effectively lost across the listed incidents, a reflection of how quickly attackers now move funds across chains and mixers.
What's driving the rise of AI-enabled theft?
AI-powered scams are scaling rapidly. According to the Chainalysis 2026 Crypto Crime Report cited in the compilation, these scams generate about 4.5 times more revenue than traditional crypto fraud.
Attackers now use AI-generated video and voice to bypass exchange KYC checks, impersonate executives to authorize large transfers, and run always-on bot campaigns targeting individual users.
What's the structural risk heading into H2?
Attack frequency rose each month through H1 2026, peaking at 41 incidents in May and 36 in June.
April caused the largest dollar losses at roughly $631 million, nearly 68% of the half-year figure.
With private-key compromises now outpacing code exploits among the largest losses, operational hygiene around developer credentials has emerged as the structural risk for H2.
via Google News - Crypto Hack Exploit (Source)