The first half of 2026 demonstrated a curious trend in the cybersecurity of the crypto industry. The number of recorded incidents rose sharply — by approximately 50% compared to the same period last year. However, contrary to expectations, the total financial losses actually decreased by nearly 60%. This divergence requires close analysis.
Figures and Facts: Quantitative Growth with Reduced Losses
From January to June 2026, blockchain security specialists recorded 182 attack incidents totaling about $956 million. For comparison: a year earlier, there were 121 incidents, with losses reaching a staggering $2.373 billion. The key takeaway is clear: attacks have become more frequent but less "lucrative" in monetary terms.
Threat Structure: Smart Contracts and Key Leaks
The main attack vector has shifted toward vulnerabilities in smart contracts and protocol logic — accounting for 85 incidents. In second place is the compromise of private keys and access data (17 episodes). Supply chain attacks round out the top three with 12 cases. However, when looking at the distribution of losses, the picture changes dramatically.
The lion's share of the damage — about $298 million — came precisely from supply chain attacks. And here, a single but massive incident played a key role. The hack of the Kelp DAO protocol, linked to the North Korean Lazarus group, led to one-time losses of nearly $292 million. This was the largest theft of the half-year.
Vulnerabilities in contracts and protocol logic cost the industry approximately $152 million, while key and credential compromises added another $130 million. Among ecosystems, Ethereum (ETH) suffered the most — losses in this network amounted to about $134 million.
New Threat: Artificial Intelligence in the Hands of Attackers
Beyond quantitative changes, analysts note a qualitative transformation of the attacks themselves. Artificial intelligence (AI) is increasingly being used by hackers at all stages — from generating phishing emails to writing malicious code. Attackers actively employ solutions like ChatGPT and Cursor to automate and enhance the effectiveness of their actions.
Particularly alarming is the emergence of a new type of threat — attacks on the trust chain of AI agents. In one incident in May 2026, a hacker first conducted an NFT airdrop granting enhanced transfer rights, then sent the Grok chatbot a message encrypted in Morse code, which it interpreted as a hidden command to transfer funds. The BankrBot trading agent involved in this chain considered the transaction safe and transferred about $175,000 to the attacker's on-chain addresses.
Cryptalist Analysis
We are witnessing a classic paradigm shift. The reduction in total losses amid an increase in the number of attacks suggests that the industry is becoming more resilient to "minor" threats but remains vulnerable to targeted, highly organized strikes. The use of AI is turning cybersecurity from an arms race into a chess game, where attackers learn to use defense tools against the systems themselves. Security teams now need to solve two problems simultaneously: combat the growing flow of attacks and adapt to the new, AI-mediated mechanics of their execution.