DPRK-linked attackers accounted for $609 million of losses, while privileged key misuse emerged as the costliest attack type in Blockaid’s review of 212 incidents.
Crypto exploits produced their most active six-month stretch on record in the first half of 2026, with hackers stealing $1.1 billion across 212 incidents, Blockaid said in a new report. Four major cases involving KelpDAO, Drift, Resolv, and CoW Swap accounted for roughly $707 million of losses. KelpDAO lost $292 million after attackers faked a cross-chain message that drained its Ethereum reserves, while Drift Protocol, a perpetuals exchange (crypto venue for leveraged futures-like bets) on Solana, lost $285 million in 12 minutes. Blockaid linked those two attacks, along with Humanity Protocol’s $32 million loss, to TraderTraitor, a state-sponsored North Korean subset of the Lazarus Group, putting DPRK-linked thefts at $609 million, or about 55% of the total. Attack frequency accelerated through the period, rising from 18 incidents in January to 57 in June, and April was the worst month after the KelpDAO and Drift hacks helped drive $635 million in losses. Privileged key misuse (abuse of wallet or admin keys) was the most expensive attack category at about $790 million, while unbacked mint exploits ranked second in value, led by the $80 million Resolve breach. Code-level exploits were the most common by count, making up nearly four out of five incidents. The report also pointed to newer pressure points, including a May prompt injection attack (manipulated AI input attack) that led Bankr’s AI agent to approve an unauthorized transaction worth about $216,000, four incidents tied to EIP-7702 wallet delegation, and repeated weaknesses in legacy smart contracts, including cases involving Aztec Connect and Raydium’s AMM V3. Outside the report period, separate attacks on AFX Trade, BSquaredNetwork, and Verus on July 23 caused more than $35 million in losses, extending what Blockaid described as continued pressure on crypto infrastructure. Recovery prospects differed by attack type, with some code-related incidents allowing freezes or negotiated returns, while stolen-key cases usually saw funds routed through mixers or cross-chain bridges.