The cryptocurrency industry witnessed a historic escalation in cyber attacks during the first half of 2026, recording 212 confirmed exploits that resulted in a staggering $1 billion in total financial losses. Security metrics indicate that this represents the highest single-period incident count ever recorded in Web3 history. Across all verified breaches during the six-month timeframe, the average loss per incident stood at $5.4 million. More than half of the total dollar losses were concentrated in just two massive exploits that exploited critical vulnerabilities in decentralized finance protocols.
The Massive April Breaches: KelpDAO and Drift Protocol
The total losses recorded in the first half of 2026 were predominantly driven by two major security breaches affecting KelpDAO and Drift Protocol, which collectively suffered $577 million in drained assets. Remarkably, both incidents occurred within a narrow 17-day window in April. KelpDAO represented the single largest exploit of the half, incurring $292 million in losses after a compromised bridge compromise led to a critical failure in its cross-chain messaging architecture. Shortly thereafter, Drift Protocol suffered the second-largest attack of the period, losing $285 million through a multisig authorization compromise executed in less than 12 minutes.
From a historical standpoint, these two April incidents represent the largest exploits of H1 2026. Within the broader history of crypto security breaches, they are surpassed only by the Bybit security breach of February 2025, which saw $1.5 billion stolen. According to analysis by Blockaid, the proximity of the Drift ($285M) and KelpDAO ($292M) attacks resulted in a combined $577 million loss, representing over 50 percent of all value stolen across the entire cryptocurrency ecosystem during the first six months of the year.
Privileged Key Exploitation and AI-Powered Sophistication
Privileged key misuse emerged as the single most damaging vector across multiple protocol breaches, accounting for $790 million of the total H1 loss figure. Simultaneously, malicious actors demonstrated an increasing focus on targeting autonomous AI agents, marking this area as the fastest-growing attack vector in the current threat landscape.
Data compiled by Blockaid highlights that H1 2026 produced 3.4 times the total number of verified security incidents recorded throughout the entirety of 2025. This sharp rise in malicious activity has been attributed to a combination of AI-fueled attacker sophistication and heightened efforts by state-sanctioned threat groups, with particular activity noted from DPRK-linked cyber units.
Target Vectors: On-Chain Protocols, Bridges, and Smart Contract Code
On-chain protocols remained the primary target for attackers in terms of overall capital drained, accounting for $524 million in exploits. Cross-chain bridge infrastructure also experienced severe disruption, with malicious actors siphoning $372 million across various bridge architectures during the first half of the year.
The bridge security incidents involved a combination of private key compromises, as seen in the KelpDAO breach, alongside smart contract code exploits targeting protocols such as Verus, Taiko, Alephium, Secret/Axelar, Swapnet, and Syscoin. Threat actors systematically identified and exploited logic flaws within these complex cross-chain contracts.
Loss Distribution Across EVM and Non-EVM Blockchains
When categorized by specific blockchain networks, Ethereum and Solana sustained the highest individual exploit totals, suffering $332 million and $326 million in losses, respectively. However, Ethereum Virtual Machine (EVM) Layer-1 chains led overall losses, with Ethereum, BNB Chain, and Avalanche (AVAX) experiencing the highest frequency of security breaches.
Non-EVM networks ranked second overall in terms of value lost, driven primarily by activity on Solana. Meanwhile, EVM Layer-2 (L2) networks sustained approximately $10 million in native direct losses, though their share of overall incident frequency continues to rise as cross-chain attacks touch multiple execution layers.
Future Threat Outlook and Evolving Risk Factors
Looking ahead, security researchers at Blockaid anticipate that attempts to compromise multisig signers will persist, given that key compromises accounted for two of the four largest exploits during H1 2026. Furthermore, industry analysts warn of a potential rise in exploits involving EIP-7702 implementations, continued targeting of cross-chain bridges, and expanding attack surfaces surrounding Web3 AI agents.


















