Crypto Security Losses Hit $1.1B as Operational Failures Drive H1 2026 Hacks

Daily Feed
Crypto Security Losses Hit $1.1B as Operational Failures Drive H1 2026 Hacks

[Crypto security losses hit $1.1 billion in the first half of 2026, and Blockaid says most of the damage came from broken operations, not flashy smart-contract bugs.](https://crypto.news/crypto-security-losses-hit-1-1b-in-h1-2026-blockaid-report/)

  • $1.1 billion lost across 212 verified incidents
  • 74% tied to operational security failures
  • One DPRK-linked cluster accounted for 55% of losses
  • Ethereum and Solana took almost the same hit on paper

That is the part the industry keeps trying not to say out loud: audits help, but they are not a magic shield. If a team mishandles private keys, admin access, signing devices, or bridge verification infrastructure, attackers can still walk away with the bag while the code itself looks fine.

[Blockaid published its H1 2026 report](https://crypto.news/?p=14475054) on July 28 and said it verified more exploits in the first half of the year than throughout 2025. The firm also said the incident count was 3.4 times its 2025 total, which is a brutal way of saying the bad actors were very much in the office this year.

The main trend is clear enough. According to Blockaid, operational security attacks caused 74% of the stolen value. In plain English, the weak point was often not the blockchain logic itself, but the machinery around it: private keys, signing systems, access controls, RPC infrastructure, and the people operating all of the above.

For newer readers, an operational security failure is when attackers bypass the code and go after the setup: a stolen key, a compromised laptop, a signer tricked into approving the wrong thing, or an admin system left too exposed. A smart-contract vulnerability is different. That is a bug in the on-chain code itself. Both are dangerous. One is just a lot more embarrassing for the team because the failure often sits in the boring stuff they thought was already covered.

Blockaid also says one cluster associated with the Democratic People’s Republic of Korea accounted for 55% of losses. That is a staggering concentration, and it reinforces a point the crypto sector still hates admitting: major theft is often organized, persistent, and strategically motivated, not random keyboard chaos from a guy in a hoodie.

The report’s network split is also telling. Ethereum-related projects lost about $332 million, while Solana-related projects lost about $326 million. Those numbers do not mean the base chains are equally secure in some simple ranking. They more likely reflect where attackers found weak apps, weak operations, and weak assumptions.

Blockaid said more than 98% of Solana-related losses came from compromised keys and signing infrastructure. That is a harsh reminder that chain debates often miss the real danger. You can argue about throughput and fees all day, but if the signer gets popped, the treasury is still toast.

The biggest Ethereum-linked case in the available data was KelpDAO, and it is a clean example of why “we passed an audit” is not the same thing as “we are safe.” [Chainalysis linked the April 18 exploit](https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/) to North Korea’s Lazarus Group and said the attack did not rely on a classic smart-contract bug.

Instead, the exploit hit the off-chain verification layer behind the bridge setup. In simpler terms, the system trusted signals from outside the chain to decide when assets should move. Chainalysis said attackers compromised internal RPC nodes used by the verifier, also DDoSed an external RPC node, and then used a false burn event to fool the bridge logic into releasing assets.

An public-key cryptography is basically the interface apps and wallets use to talk to a blockchain. If that infrastructure is compromised, the rest of the system can be fed bad information. In KelpDAO’s case, the real design smell was the reliance on a single verifier. That is the sort of setup that looks neat on a diagram right up until someone kicks the legs out from under it.

The result was the release of 116, 500 rsETH, worth roughly $292 million. [Chainalysis said the Arbitrum Security Council moved to freeze a significant portion of downstream funds](https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/) three days later, and KelpDAO paused the contract, blacklisted attacker addresses, and engaged SEAL-911. That helped contain further damage, but it did not erase the theft. In crypto, stopping the drain and getting the money back are two very different hobbies.

This is why bridge security keeps coming back as a problem. Bridges are attractive targets because they sit at the junction between chains and often rely on trust assumptions that are easy to break if the verification layer is weak. A bridge can have clean on-chain code and still be brittle if its off-chain plumbing is sloppy or over-trusted.

Blockaid says the threat picture is not cooling off either. Its report points to new attack vectors emerging in H1 and warns that some could expand in the second half of the year. The defenses it expects to matter more are not glamorous, but they are real: transaction-intent checks, isolated signing devices, key segregation, and better monitoring across bridges and infrastructure.

Transaction-intent checks sound fancy, but the idea is simple: make sure a signer is approving exactly what they meant to approve, not a subtly altered transaction buried inside a nasty little trap. Key segregation means keeping sensitive keys separated so one compromise does not open the entire vault. Isolated signing devices are dedicated systems used only for signing sensitive transactions, not for checking email like a dope and inviting malware in for tea.

The lesson here is not that crypto is uniquely doomed. It is that attackers keep finding the easiest money in the parts teams treat as background noise. That is the boring, humiliating truth of security. The code can be elegant, the branding can be slick, and the audits can be framed on the wall, and then one exposed key or one bad verification assumption turns the whole thing into a crime scene.

Recovery, where it happens, is usually messy and incomplete. Some funds are frozen downstream, some wallets keep moving, legal claims drag on, and teams are left trying to rebuild trust while everyone counts the damage. The blockchain may be permanent, but restitution is still very much a human problem.

Key questions and takeaways

  • What caused most of the losses?
    Blockaid says operational security failures caused 74% of stolen value. That points to compromised keys, signing systems, devices, and infrastructure rather than pure smart-contract bugs.

  • Was KelpDAO hacked through a smart-contract flaw?
    Not according to Chainalysis. Its analysis points to the off-chain verification layer behind the bridge setup, including compromised RPC infrastructure and a single-verifier design.

  • Why does the DPRK attribution matter?
    Blockaid says one DPRK-linked cluster accounted for 55% of losses. That shows major crypto theft remains concentrated and organized, not just opportunistic fraud.

  • Are audits enough to keep protocols safe?
    No. Audits help, but they do not protect against stolen keys, compromised signers, broken bridge assumptions, or weak off-chain infrastructure.

  • What should protocols prioritize next?
    Blockaid points toward transaction-intent checks, isolated signing devices, key segregation, and stronger monitoring across bridges and infrastructure. In short: shrink the blast radius before someone else does it for you.

The real story of H1 2026 is not just the dollar total. It is the shift in where attackers are winning. The chain is often not the soft spot anymore. The soft spot is everything around it.

Further reading

A few related pieces that add more color to the security mess crypto keeps stepping in.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog