The headline loss figure is large, but the cleaner market signal is frequency. Blockaid’s new security readout points to a threat environment where exploit attempts are becoming more common, even when headline dollar damage is distorted by one-off mega incidents.
What did Blockaid’s H1 2026 crypto hack report show?
Blockaid’s H1 2026 crypto hack report showed more than $1 billion in losses across 212 verified incidents, making the period the most-hacked half-year in Blockaid’s dataset by incident count . The report was published on July 28, 2026 , and its core message is that exploit frequency, not only stolen value, is now the sharper risk signal for crypto traders.
Quick Answer: Blockaid reported $1.1 billion lost across 212 verified crypto hack incidents in H1 2026, with incident count reaching 3.4 times its full-year 2025 total . The larger signal is attack frequency, not the headline loss figure alone.
The accessible Blockaid report page says the firm verified more exploit incidents in H1 2026 than in all of 2025 . Supporting coverage from The Block, Crypto.news, and Cointelegraph all frame the same point: the market is seeing more verified exploit events, not just larger isolated losses.
"Most-hacked half-year on record," — Blockaid, H1 2026 Security Report (source: Blockaid)
The dollar comparison needs care. Losses topped $1 billion in H1 2026 , but The Block notes they were still below H1 2025 because that period was skewed by the $1.5 billion Bybit exploit . For traders, that distinction matters because risk is spreading across more events rather than sitting in a single outlier.
| Metric | What Blockaid’s H1 2026 readout showed | Why traders should care |
|---|---|---|
| Reported losses | $1.1 billion in H1 2026 losses | Large enough to affect protocol trust, liquidity behavior, and exchange-risk pricing. |
| Verified incidents | 212 verified incidents in H1 2026 | Frequency suggests broader attack surface pressure across crypto infrastructure. |
| Year comparison | Incident count was 3.4 times Blockaid’s full-year 2025 total | The risk signal is not just bigger hacks; it is more repeated exploitation. |
That is the setup for the rest of the market brief: the $1.1 billion figure is the headline , but the count is the warning light. A market can absorb isolated shocks; repeated incidents pressure custody assumptions, protocol due diligence, insurance pricing, and how quickly traders discount security news into token risk.
Why does the hack count matter more than the dollar total?
The hack count matters more than the dollar total because it shows security risk spreading across more targets, not just concentrating in one headline exploit. Blockaid counted $1.1 billion in losses across 212 verified incidents in H1 2026 , a pattern that points to wider attack surfaces across apps, wallets, bridges, signing systems, and operational workflows.
That distinction matters for traders. A single giant loss can dominate market psychology for a few sessions, but a high incident count can keep pressure on many smaller venues of risk at once: liquidity pools, bridge routes, app-specific tokens, market-maker balances, and confidence in protocol teams. According to The Block, H1 2026 losses were below H1 2025 because the earlier period was inflated by Bybit’s $1.5 billion exploit . The cleaner signal is frequency, not just size.
- Blockaid: $1.1 billion across 212 verified incidents in H1 2026, with the count reported as 3.4 times its full-year 2025 total .
- Immunefi: about $972 million across 207 incidents in H1 2026, also described as record attack volume by The Block .
- QuillAudits: $935.3 million across 87 DeFi hacks in H1 2026, with key compromise and bridge exploits driving 82.7% of losses .
The figures should not be blended into one master total. Each provider uses different inclusion rules, thresholds, and classifications, so the practical reading is directional: multiple independent datasets show elevated incident volume in H1 2026 . For active traders, that means security news deserves position-level risk checks even when the aggregate dollar figure looks less severe than the prior year.
Where did the losses come from: code bugs or operational security failures?
The main source of H1 2026 crypto losses was operational security failure, not traditional smart-contract bugs: Blockaid found that compromised devices, privileged credentials, private keys, signing systems, and off-chain infrastructure accounted for 74% of stolen value . That shifts protocol risk analysis from “was the code audited?” toward “who can sign, upgrade, bridge, pause, or move funds under pressure?”
According to Crypto.news, citing Blockaid, DPRK-linked actors accounted for 55% of measured losses in H1 2026 . The Block reported that North Korea-linked hackers were tied to nearly $600 million in stolen funds, including Blockaid attribution of the Drift and KelpDAO incidents to DPRK-linked actors .
"The LinkedIn social-engineering-to-multisig-compromise pattern produced two of the four largest H1 incidents and has no obvious structural reason to stop," according to Blockaid’s warning as reported by The Block .
For traders, the practical due-diligence checklist now has to include operational controls alongside audit badges. A protocol can pass code review and still be vulnerable if admin wallets, multisig participants, RPC infrastructure, or signer devices are weak points. That matters most for bridges, restaking systems, perps venues, and protocols with upgrade authority over large user balances.
- Check whether privileged keys use hardware-backed signing, timelocks, and clear emergency procedures.
- Look for real-time monitoring, public incident-response playbooks, and independent post-incident audits.
- Treat unexplained signer changes, rushed upgrades, or vague “maintenance” notices as position-risk signals.
Which chains and incidents explain the market signal?
Ethereum and Solana explain the market signal because they were nearly tied by reported loss value, but exposed different weaknesses: about $332 million was tied to Ethereum-related incidents and about $326 million to Solana-related incidents in Blockaid’s H1 2026 dataset . For traders, that split matters because chain-level risk is not just about TVL or user activity; it is about where privileged access, bridges, signers, and high-value applications concentrate.
Ethereum’s loss profile was linked to high-value infrastructure: restaking, stablecoin, bridge, and DEX systems where a single failure can move a large balance. The KelpDAO case shows why. Chainalysis said attackers linked by LayerZero to North Korea’s Lazarus Group stole about $292 million, equal to 116,500 rsETH, from KelpDAO’s LayerZero bridge on April 18, 2026 .
The KelpDAO exploit was not described as a classic smart-contract bug. Chainalysis said attackers compromised internal RPC nodes and disrupted external RPC nodes, causing a 1-of-1 DVN to accept a false source-chain burn and release rsETH on Ethereum without the matching upstream burn . Kelp later paused contracts, blocked a second forged packet worth about $95 million, and the Arbitrum Security Council froze more than 30,000 ETH of downstream funds .
Solana’s signal was different: Cointelegraph reported that compromised keys accounted for more than 98% of Solana losses in Blockaid’s H1 2026 analysis . Drift’s own recovery update said its April 1 exploit left $295.7 million in outstanding user losses, including $159.3 million in JLP and $71.4 million in USDC .
- For Ethereum exposure, watch bridge verification design, admin authority, restaking dependencies, and emergency pause controls.
- For Solana exposure, watch signer hygiene, hardware-backed key custody, durable nonce controls, and real-time alerting.
- For both ecosystems, treat a protocol’s recovery plan as market data: Drift cited independent audits by OtterSec and Asymmetric, dedicated signing devices, timelocks, and disabling durable nonces for all signers after the incident .
What should traders watch next after the Blockaid report?
Traders should watch whether protocols turn incident reports into verifiable security changes: dedicated signing devices, timelocks, real-time alerts, independent audits, and signer-policy updates. Drift’s recovery update after its April exploit listed independent audits by OtterSec and Asymmetric, dedicated signing devices, timelocks, real-time alerts, and disabling durable nonces for all signers . For active traders, those controls now matter as much as TVL, yield, or token unlocks.
- Signer controls: Look for hardware-backed signing, separated duties, timelocks on privileged actions, and public post-incident audit scopes. A recovery plan that names the control changes is more useful than a generic “security review.”
- Bridge and restaking infrastructure: Track whether protocols harden off-chain verification, RPC dependencies, and message-validation paths. In the KelpDAO case, Chainalysis said attackers compromised internal RPC nodes and disrupted external RPC nodes, causing a false source-chain burn to release rsETH on Ethereum without a matching upstream burn .
- Privileged-access risk: Monitor hiring workflows, LinkedIn outreach, multisig signer compromise, private-key handling, and admin-device exposure. The Block reported that Blockaid tied the largest share of stolen funds to North Korea-linked actors, including the Drift and KelpDAO incidents .
Policy headlines are a separate signal, not part of the exploit dataset. A July Thinking Crypto video reported that U.S. lawmakers were still negotiating the CLARITY Act, with a possible vote during the week of August 3 . That debate may shape custody, enforcement, and market-structure rules, but it should not be blended into Blockaid’s hack-loss count.
The practical takeaway is simple: treat security architecture as tradable information. Protocols that cannot explain signer hygiene, bridge verification, incident response, and audit follow-through deserve a higher risk discount, even when headline losses look contained.
Frequently asked questions
How much was lost to crypto hacks in H1 2026?
Blockaid reported $1.1 billion in crypto hack losses across 212 verified incidents in the first six months of 2026 . The key point is that the loss total was large, but the incident count was the stronger market signal because it showed a broader attack surface across protocols, wallets, bridges, signing systems, and off-chain infrastructure.
Why is Blockaid calling H1 2026 a record period?
Blockaid called H1 2026 the most-hacked half-year on record because the record was based on verified incident count, not dollar value. Its report landing page says Blockaid verified more exploit incidents in H1 2026 than in all of 2025 . Reporting based on the report put H1 2026 at 212 verified incidents, or 3.4 times Blockaid’s full-year 2025 total .
Were Ethereum or Solana hit harder in H1 2026?
Ethereum and Solana were nearly tied by reported H1 2026 loss value. Cointelegraph, citing Blockaid, reported about $332 million in Ethereum-related losses and about $326 million in Solana-related losses . The difference was in attack pattern: Ethereum losses were more tied to high-value applications and bridge or code-related weaknesses, while Solana losses were mainly tied to compromised keys and signing infrastructure.
What caused most H1 2026 crypto losses?
Operational-security failures caused most H1 2026 crypto losses. Crypto.news, citing Blockaid, reported that 74% of stolen value came from compromised devices, privileged credentials, private keys, signing systems, and off-chain infrastructure . That means traders should look beyond audits and ask how a protocol protects admin access, multisig signers, bridge verification, monitoring, and emergency response.
What is the main trader takeaway from the Blockaid report?
The main trader takeaway is that protocol risk is no longer just smart-contract risk. Blockaid’s H1 2026 findings show that signer controls, bridge design, admin keys, monitoring, and recovery plans can matter as much as audited code. The KelpDAO case is a clear example: Chainalysis said attackers exploited off-chain verification around a LayerZero bridge and stole about $292 million on April 18, 2026 .
Enjoyed this article? Subscribe to get new stories by email whenever they're published.