
Cryptocurrency security incidents caused $1.1 billion in losses across 212+ verified cases during the first half of 2026, according to comprehensive analysis by Blockaid. This represents a record-breaking six-month period for the digital asset industry, with 54.6% of all value lost in 2024-2025 window traced to centralized exchange compromises - the keys, custody and signing that sit above the contract. The data reveals a significant shift in attack patterns, with 74% of stolen funds resulting from operational security failures rather than exploited smart contract code. A single DPRK-linked cluster accounted for 55% of losses alone, highlighting the growing threat from state-sponsored actors in the cryptocurrency ecosystem. The incident count reached 3.4 times the previous full-year level, suggesting attackers are exploiting vulnerabilities faster than projects can address them.
April 2026 alone accounted for over $600 million in losses across DeFi, representing more than 50% of total H1 2026 losses. The Kelp DAO exploit resulted in $292 million in losses after attackers forged a LayerZero cross-chain message by compromising the protocol's single message verifier - one checkpoint, no backup. Drift Protocol lost $285 million in the same period when operatives linked to North Korea spent months socially engineering their way to admin keys. These incidents demonstrated how a single breach can erase significant value within hours, with the $5.4 million average loss and $213,000 median loss showing that smaller attacks remained persistent across the ecosystem. The $292 million KelpDAO exploit specifically targeted cross-chain bridge infrastructure, demonstrating how bridge infrastructure continues to attract sophisticated attacks despite improved security measures.
Ethereum recorded the largest losses at $332 million, while Solana trailed closely behind at $326 million, making the two largest blockchain ecosystems the primary targets for attackers. Ethereum's concentration of high-value protocols made smart contracts and protocol code the preferred targets, while Solana's signer-heavy multisig ecosystem meant compromised private keys and signing infrastructure accounted for more than 98% of losses. The $292 million KelpDAO exploit showcased how cross-chain bridges remained the largest source of dollar exposure, with attackers specifically targeting bridge infrastructure architecture specific to each blockchain rather than merely focusing on larger ecosystems. Notable victims included Step Finance ($40 million), Humanity Protocol ($32 million), and Resolv's USR stablecoin ($24.5 million) - all drained through compromised private keys and signing infrastructure.
A separate comprehensive H1 2026 security report by Ack3 reveals a fundamental flaw in Web3 security evaluation, with $939.86 million lost across 135 verified security incidents during the same period. The most troubling finding is that more than half of exploited projects carried completed security audits, yet 94.4% of those cases involved attack paths through terrain auditors never touched: compromised private keys, hijacked front-end scripts, leaky cloud infrastructure, and unreviewed off-chain relayers. As Ack3 Founder Josef Gattermayer explains, "An audit is a timestamp and a boundary, not a lifetime warranty." The research demonstrates that 46 out of 68 audited protocol breaches resulted in $680.97 million in losses, while only 20 in-scope exploits netted just $35.21 million, highlighting the critical gap between audited code and operational security. The pattern repeated across major platforms, with Polymarket hit twice - a $700k internal wallet drain in May, then a $3.1m front-end supply-chain attack in June that turned its own website into a wallet drainer.
Despite improved auditing, bug bounty programs, and real-time monitoring having reduced the time to respond to attacks, recovery remains inconsistent, especially after key compromises. The industry's expanding security infrastructure is effective at limiting damage rather than stopping attacks entirely. As Ack3 CEO Josef Gattermayer warns, "Audited" is a marketing word until you ask three questions: what exactly was reviewed, how long ago, and who controls the keys today. The honest answers were too often: not this bit, over a year ago, and one compromised key from a catastrophe." The unaudited crowd fared no better, with Truebit coughing up $26.4 million to a schoolboy integer-overflow error in its mint pricing. Until recovery improves alongside prevention, the industry's expanding security infrastructure will remain effective at limiting damage rather than stopping attacks entirely.