Skip to content
  • Blockaid recorded more than $1 billion in crypto losses across 212 security incidents during the first half of 2026.
  • Ethereum losses mainly stemmed from smart contract flaws, while Solana attacks largely targeted compromised keys and infrastructure.
  • Operational security failures caused most losses, prompting projects to strengthen key management and transaction security.

Crypto security breaches surpassed $1 billion during the first half of 2026 after attackers struck projects across multiple blockchains, according to Blockaid. The on-chain security firm reported 212 verified incidents through June, the highest six-month total on record, with Ethereum and Solana posting the largest losses and KelpDAO recording the biggest single exploit.

Ethereum And Solana Face Different Attack Patterns

According to Blockaid’s H1 2026 Onchain Security Report, Ethereum-related projects lost about $332 million during the period. Most losses came from code vulnerabilities, while KelpDAO accounted for roughly $292 million after attackers exploited a bridge contract.

Meanwhile, Solana-related projects lost about $326 million. However, more than 98% of those losses resulted from compromised keys and signing infrastructure rather than smart contract flaws.

Blockaid identified Drift Protocol and Step Finance as the largest contributors to Solana’s losses. Smaller code-related incidents also affected Raydium and Volo during the reporting period.

Operational Security Drives Most Losses

Blockaid reported that operational security failures caused 74% of the total value stolen. Additionally, one attack cluster associated with North Korea accounted for 55% of all recorded losses.

EliteFXLabs Banner

According to the report, attackers increasingly targeted devices, private keys, privileged credentials, and signing systems. As a result, compromised infrastructure produced transactions that appeared legitimate because authorized credentials approved them.

The firm said traditional smart contract audits cannot prevent administrators from approving malicious transactions after attackers compromise their systems.

Recovery Efforts Continue Across Major Incidents

Several affected projects continued recovery work after the attacks. KelpDAO completed the operational phase of its recovery plan on May 25 after transferring the final tranche of rsETH into its bridge adapter.

Meanwhile, Drift proposed a recovery pool backed by exchange revenue, Tether, and other partners. The protocol also outlined new security measures, including dedicated signing devices, timelocks, redesigned multisig controls, and additional audits before restarting operations.

Separately, Blockaid expects infrastructure teams to strengthen transaction monitoring, isolated signing devices, key segregation, and bridge security as investigations into several major incidents continue.

Share this article

© 2026 Cryptofrontnews. All rights reserved.