
SlowMist and Immunefi both reported rising attack counts in the first half of 2026, while estimated losses ranged from about $956 million to $972 million and reached $1.32 billion in CertiK data cited by Cointelegraph.
Crypto security incidents increased sharply in the first half of 2026, though loss estimates differed by source, indicating more frequent attacks alongside changing attack patterns. SlowMist recorded 182 incidents worth about $956 million from January through June, up from 121 incidents and roughly $2.373 billion in losses a year earlier, while Immunefi reported a record 207 incidents and about $972 million in losses, and Cointelegraph cited CertiK data putting H1 2026 losses at $1.32 billion. Across the reports, researchers said attackers are increasingly exploiting operational and infrastructure weaknesses such as supply chain breaches, private key compromise, privileged access and cross-chain configuration errors, even as contract and logic flaws remain common. They also said AI tools are accelerating social-engineering campaigns and vulnerability discovery, increasing pressure on crypto projects to adopt continuous monitoring, bug bounty programs and broader security coverage, including for inactive DeFi codebases such as Aztec Connect and mySwap.