Crypto Hacks 2026 opened with a hard number. Blockaid, the onchain security firm verified 212 exploits between January and June 2026. Total losses hit $1.1 billion, making Crypto Hacks 2026 the busiest six-month stretch Blockaid has tracked.

Incident volume in this crypto hack news today shows a 3.4 times the incidents tracked in 2025, a jump Blockaid ties to AI-assisted attackers and steady pressure from North Korean hackers.
The data shows that DPRK-linked attacks, bridge exploits, and stolen keys once again drove the largest share of crypto hacks 2026.
Four incidents that drove most of the losses
KelpDAO — $292M. A forged cross-chain verifier message drained the protocol's Ethereum escrow, no contract bug needed.
Drift Protocol — $285M. Weeks of social engineering against multisig signers handed attackers admin control of Solana's largest perpetuals DEX in under 12 minutes.
Resolv — $80M minted, about $25M extracted. A compromised key minted unbacked stablecoins before the token price collapsed.
CowSwap — $50.4M. One institutional trader approved a single bad signature, the only user-mistake incident among the four largest.
Together these four incidents totaled roughly $707M, or 64% of the full H1 total. That concentration nearly matches 2025, when three incidents alone made up 72% of losses.
North Korean hackers tied to Lazarus Group sub-unit TraderTraitor sit behind the two biggest hits. Drift and KelpDAO, the two largest incidents, are both attributed to TraderTraitor, a Lazarus Group sub-unit.
Adding Humanity Protocol's $32M, the DPRK-linked cluster reaches about $609M, roughly 55% of every dollar lost in H1 2026.
Bridges produced the single largest loss of the half. Seven bridge incidents occurred, led by KelpDAO, after attackers stole a LayerZero developer's login through social engineering.
April was the costliest month by far: $635M lost, against $112M in January, $21M in February, $140M in March, $76M in May, and $68M in June.
New attack methods showed up for the first time: the first EIP-7702 wallet-delegation drain hit Arbitrum in January, Aztec took two ZK proof-boundary exploits in June, and an AI agent at Bankr lost $216K to prompt injection in May.
Recovery split by cause: code bugs often ended in partial recovery, like Verus's $8.5M return, while funds taken through stolen keys rarely came back and usually moved through mixers within hours.

Major Root Causes
Ethereum: led losses among EVM networks, driven by high-value DeFi and stablecoin protocols.
Solana: losses came almost entirely from key theft, with Drift and Step Finance making up over 98% of the chain's total.
Cross-chain bridges: lost close to $330M combined, the worst dollar exposure of any category.
EVM Layer-2s (Arbitrum, Aztec, others): carried small dollar totals but hosted nearly every new attack method of the Crypto Hacks 2026 period, making them the leading indicator for what scales up next.

2026 vs 2025 Crypto Hack Trends: How This Year Compares So Far Now
Chainalysis 2025 Crypto Crime Report, covering full-year 2024, found $2.2 billion stolen from platforms that year, up 21.07% from 2023, across 303 incidents. North Korean hackers took 61% ($1.34 billion) of the yearly total.
Set against Crypto Hacks 2026 report figures, that pattern held steady.
Root cause: Compromised private keys caused $789M, or 74.3%, of Crypto Hacks 2026 losses, an even higher share than 2024's 43.8%. Key theft, not code bugs, is now the dominant cause on both timelines.
DPRK's share: North Korean hackers took 55% of H1 2026 dollars, close to their 61% share of full-year 2024. The same actor keeps driving the biggest single losses year after year.
Incident volume: H1 2026 alone produced 3.4 times the incidents Blockaid tracked in all of 2025, a far steeper pace than the 303-incident total Chainalysis logged for 2024.
Dollar totals: H1 2025 actually lost more than H1 2026 in dollar terms, purely because no 2026 incident has matched the $1.5B Bybit theft from February 2025.
The clearest read on 2026 vs 2025 cryptocurrency theft trends: incident count and DPRK involvement kept climbing, but no single mega-hack in 2026 matched Bybit's scale, so total dollars look smaller even as the attack count exploded.
Use hardware signers and multi-party approval for wallets holding real funds.
Treat unexpected job offers or urgent credential requests as a red flag; this is how North Korean hackers get in.
Read EIP-7702 delegation prompts carefully before approving; a bad upgrade can hand over full wallet control.
Avoid deprecated or "legacy" contract versions, even if old funds are still sitting there.
Match every signature request against the exact transaction intended; one wrong signature cost CowSwap $50.4M.
Confirm any transaction an AI agent suggests before approving it.
Two things stand out. Code audits are losing ground as the main defense: compromised keys, not contract bugs, caused three out of every four cryptocurrency hack dollars lost, and both Drift and KelpDAO began with a person getting fooled.
Second, every new attack method this year, wallet delegation abuse, AI prompt injection, off-chain bridge verification, hit a boundary nobody audited in 2025. Attackers shifted from breaking code to breaking trust between systems and the people running them, and that shift will likely keep shaping crypto-hack news through the second half of the year.
Blockaid expects EIP-7702 losses to reach seven figures in H2 2026 and bridge exploits to continue, since many projects share KelpDAO's single-verifier design. None of this calls for new defenses, just faster use of the ones that already work: multi-party signing, real-time screening, and equal monitoring for old code nobody switched off.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.
3 hours ago
I responded to an advertisement involving a Dutch model, and shortly afterward I was contacted by Mark Grams, who claimed to be a professional investment adviser. After six weeks of building trust with me, he convinced me to convert both my investment and my father's portfolio into crypto. In total, I transferred €1.6 million worth of crypto to what I believed was a legitimate investment platform. When I later asked to access my funds, I was told that my account had been blocked and that I needed to transfer more money to unlock it. That was when I realized I had been scammed. After filing a police report with little progress, I hired a legal team, who then contacted Morphohack Cyber Service via email (MORPHOHACK@CYBERSERVICES.COM). They used blockchain analysis to trace the stolen crypto, and the trail led to several crypto exchanges, including HTX. However, Morphohack was able to recover all the crypto that had been funnelled through their network. Recovering my funds also helped uncover a broader network of alleged crypto-related crimes. After I lost my funds, I felt like the ground beneath me was about to explode, Morphohack brought me back to life with their professional help. I highly recommend Morphohack and their incredibly helpful team.