POPULAR ARTICLES

- Crypto projects suffered 212 confirmed exploits in H1 2026, resulting in $1 billion in losses and the highest incident count on record.
- KelpDAO and Drift suffered the two largest exploits, losing a combined $577 million in the first half of the year.
- Privileged key misuse caused $790 million in losses, while attackers increasingly targeted AI agents, cross-chain bridges and on-chain protocols.
Crypto exploits hit a record high in H1 2026, with 212 incidents confirmed across several crypto projects, according to a Tuesday report from Blockaid.
KelpDAO, Drift protocol account for more than half of H1 losses
Average losses stood at $5.4 million, with a total of $1 billion in exploits in the first six months. The largest incident came from KelpDAO, which recorded $292 million in losses after a compromised bridge triggered a breach in its cross-chain messaging. The Drift protocol saw the second-largest attack of the period, with $285 million drained via a multisig compromise in under 12 minutes.
The two largest losses — both in April — accounted for the largest exploits in H1 '26, totaling $577 million. Only Bybit's February 2025 exploit, which totaled $1.5 billion, surpassed the record.
“Drift ($285M) and KelpDAO ($292M) occurred 17 days apart, and together they accounted for roughly $577M, more than half of all H1 dollar losses,” Blockaid wrote.
Privileged keys, AI agents emerge as major threats
Privileged key misuse was the most common cause of exploits across several protocols in H1, accounting for a total of $790 million. At the same time, attackers increasingly targeted AI agents, making it the top emerging vector so far.
“H1 2026 alone produced 3.4x the verified incidents Blockaid recorded in all of last year. AI-fueled attacker sophistication and high-intent sanctioned threat actors, DPRK in particular, drove the increase,” the report stated.
Onchain protocols were the major targets for hackers, with $524 million in exploits recorded in H1. Cross-chain bridges also faced numerous attacks, with $372 million drained in H1.
“H1 bridge incidents mixed a key compromise at KelpDAO with code exploits at Verus, Taiko, Alephium, Secret/Axelar, Swapnet and Syscoin,” Blockaid stated.
Ethereum (ETH) and Solana (SOL) saw the highest successful exploits by chains, with $332 million and $326 million, respectively.
However, Blockaid noted that Ethereum Virtual Machine (EVM) Layer-1 (L1) chains led dollar losses, with Ethereum, BNB and Avalanche (AVAX) seeing the most attacks. Non-EVM chains ranked second, driven notably by Solana.
“L2 bars appear large because cross-chain incidents are counted on every chain they touch; measured by where losses natively occurred, EVM L2s accounted for roughly $10M but a rising share of incidents,” the report added.
Moving forward, Blockaid stated that it expects multisig signer compromise attempts to continue, arguing that they produced two of the four largest losses of the half. The firm also pointed to a potential rise in EIP-7702 incidents, bridge exploits and AI agent attacks.












