
Cryptocurrency security incidents experienced a dramatic 50% increase in the first half of 2026, according to a mid-year report from blockchain security firm SlowMist. The firm recorded 182 incidents worth approximately $956 million between January and June, compared to 121 incidents causing around $2.373 billion in losses during the same period in 2025. This data reveals a fundamental shift in the threat landscape, with attack frequency rising significantly while total losses decreased substantially, indicating that larger sums are now concentrated in fewer, higher-value targets.
Contract and logic vulnerabilities dominated the incident landscape, accounting for 85 cases and representing the most common security issue. Private key and credential compromise ranked second with 17 incidents, followed by supply chain attacks with 12 cases. By value, the picture shifted significantly, with supply chain attacks causing the largest losses at approximately $298 million, primarily due to a single major exploit. The Kelp DAO exploit alone resulted in nearly $292 million in losses, which researchers attributed to a subgroup of North Korea's Lazarus Group.
Ethereum emerged as the most targeted cryptocurrency ecosystem, with approximately $134 million in related losses during the first half of 2026. Contract and logic flaws accounted for roughly $152 million in total losses, while private key and credential compromises added about $130 million in damages. This concentration on Ethereum highlights the continued vulnerability of the network despite its market dominance in the cryptocurrency space.
Artificial intelligence has emerged as a significant threat vector, with SlowMist reporting that AI has lowered barriers to social engineering and automated attacks. In one notable example from April, researchers identified that HexagonalRodent, a Lazarus subgroup, used AI tools including ChatGPT and Cursor to assist in code generation, craft communication content, and optimize social engineering narratives. The firm also documented an 'AI agent trust chain' attack in May 2026, where an attacker exploited a chatbot to move approximately $175,000 on-chain through a series of automated transfers.