Crypto security incidents jump in H1 2026 as losses vary by report

Crypto security incidents jump in H1 2026 as losses vary by report

SlowMist and Immunefi both reported rising attack counts in the first half of 2026, while estimated losses ranged from about $956 million to $972 million and reached $1.32 billion in CertiK data cited by Cointelegraph.

Fact Check
All numerical and directional claims are corroborated by primary and syndicated sources. The Block confirms Immunefi's ~$972M across a record 207 hacks. BeInCrypto confirms SlowMist's ~$956M across 182 incidents with a ~50% rise in attack counts. The Cointelegraph/CertiK article confirms $1.32B in H1 2026 losses. The reported loss range of ~$956M to ~$972M and the $1.32B CertiK figure all match, as does the narrative of rising attack counts amid varying loss estimates by report.
    Reference123
Summary

Crypto security incidents increased sharply in the first half of 2026, though loss estimates differed by source, indicating more frequent attacks alongside changing attack patterns. SlowMist recorded 182 incidents worth about $956 million from January through June, up from 121 incidents and roughly $2.373 billion in losses a year earlier, while Immunefi reported a record 207 incidents and about $972 million in losses, and Cointelegraph cited CertiK data putting H1 2026 losses at $1.32 billion. Across the reports, researchers said attackers are increasingly exploiting operational and infrastructure weaknesses such as supply chain breaches, private key compromise, privileged access and cross-chain configuration errors, even as contract and logic flaws remain common. They also said AI tools are accelerating social-engineering campaigns and vulnerability discovery, increasing pressure on crypto projects to adopt continuous monitoring, bug bounty programs and broader security coverage, including for inactive DeFi codebases such as Aztec Connect and mySwap.

Terms & Concepts
  • Supply chain attacks: Breaches that exploit software providers or dependencies to reach downstream targets.
  • smart contract: Self-executing blockchain code that runs predefined rules.
  • bug bounty programs: Programs that pay researchers to report vulnerabilities before attackers exploit them.