Security firm Blockaid confirmed 212 major onchain exploits during the first half of 2026, marking a 3.4-fold increase compared to the entire previous year. These attacks resulted in $1.1 billion in stolen funds, driven largely by sophisticated social engineering and state-sponsored hackers.
June was the peak month with 57 confirmed incidents, while just four major breaches made up 64% of the total losses. North Korea’s notorious Trader Traitor group, linked to the Lazarus hacking collective, was behind roughly $609 million of the thefts. Their targets included the restaking protocol KelpDAO which lost $292 million, and the Solana-based Drift Protocol, hit for $285 million. Rather than exploiting smart contract bugs, these attacks focused on operational weaknesses and human error. In Drift’s case, weeks of social engineering granted hackers multisig control, enabling them to drain funds in under 12 minutes. The KelpDAO breach involved manipulating a developer to compromise cross-chain bridge attestations.
Emerging threats and future outlook
Blockaid’s report highlights new attack vectors gaining traction such as EIP-7702 wallet delegation exploits and AI prompt injection hacks. These methods fall outside traditional audit scopes, signaling a shift in how attackers approach crypto security. The trend shows growing risks for decentralized finance platforms and wallet providers as AI-assisted attacks become more common.
This information is for educational purposes and does not constitute financial advice.



