The first half of 2026 demonstrated a unique dynamic in the cybersecurity landscape of the crypto industry. The number of recorded incidents rose sharply — by approximately 50% compared to the same period last year. However, the total financial losses, on the contrary, decreased by almost 60%. This statistics, based on my in-depth analysis of blockchain security data, points to fundamental changes in the threat landscape.

During the period from January to June 2026, 182 attack cases were recorded. Total losses amounted to about $956 million. For comparison: a year earlier, there were 121 attacks, but losses reached $2.373 billion. The key takeaway here is the gap between the frequency of attacks and their financial effectiveness. Attackers have become more active, but their "successes" in monetary terms have become less significant, with the exception of isolated, very large targets.

Threat Structure: Smart Contracts and Supply Chain Attacks

The most common attack vector remains vulnerabilities in smart contracts and protocol logic — 85 incidents. In second place is the compromise of private keys and access data (17 episodes), and the top three is rounded out by supply chain attacks with 12 cases. However, when looking at the distribution of losses, the picture changes dramatically.

The main financial damage was inflicted precisely through supply chain attacks — about $298 million. The lion's share of this amount comes from one incident: the hack of the Kelp DAO protocol, which led to one-time losses of almost $292 million. My analysis links this attack to the activities of the North Korean Lazarus group.

Vulnerabilities in smart contracts led to losses of approximately $152 million, and compromise of keys and credentials accounted for another $130 million. Among ecosystems, Ethereum (ETH) suffered the most, with total losses of about $134 million. This confirms ETH's status as a primary target for attacks, given its dominance in DeFi.

Artificial Intelligence as a New Attack Tool

Special attention should be paid to the growing role of artificial intelligence (AI) in cyber threats. AI not only simplifies phishing and automated attacks but also changes the very mechanics. Attackers actively use tools such as ChatGPT and Cursor to generate malicious code, craft convincing messages, and develop social engineering scenarios.

For example, in May 2026, an attack on an AI agent was recorded. The attacker first conducted an NFT airdrop granting extended rights, then sent a message in Morse code to the Grok chatbot. The bot perceived this as a hidden command to transfer funds. The BankrBot trading agent involved in this chain deemed the outcome safe and transferred about $175,000 to on-chain addresses. This is a classic example of an attack on the trust chain of an AI agent.

Expert opinion from Cryptalist: Security teams today face a dual challenge. On one hand, it is necessary to reduce the overall number of attacks, which is steadily increasing. On the other hand, they must adapt to new methods where AI is used not only for defense but also for offense. The Grok incident is a wake-up call, showing that even the most advanced AI systems are vulnerable to non-trivial manipulations. The industry urgently needs new security standards for interacting with AI agents.