The digital asset market faced a unique trend in the first half of 2026. From January to June, monitoring systems recorded 182 security-related incidents. This is a 50% increase compared to the previous year, when 122 cases were noted. However, the total amount of losses, on the contrary, sharply decreased — from $2.373 billion to $956 million, a drop of nearly 60%.
This data indicates a fundamental shift in the structure of cyber threats. The number of attacks is growing, but they are becoming less large-scale. A key factor is the shift in attackers' focus from single, devastating strikes to more frequent but targeted operations.
Main Attack Vectors and Vulnerabilities
Analysis of incidents shows a clear distribution by threat type. The largest number of hacks — 85 cases — is associated with vulnerabilities in smart contracts and protocol logic. In second place is the compromise of private keys and access data (17 episodes). Attacks on supply chains round out the top three (12 incidents).
However, when looking at financial damage, the picture changes dramatically. The largest losses — about $298 million — came precisely from supply chain attacks. The main driver of this amount was a single but large-scale hack of the Kelp DAO platform, which led to the loss of nearly $292 million. According to the investigation, this incident was linked to the activities of the North Korean Lazarus group.
Smart contract vulnerabilities caused $152 million in damage, while key and credential compromises accounted for another $130 million. Notably, among ecosystems, Ethereum (ETH) suffered the most: losses in this network amounted to about $134 million.
A New Era: AI as a Weapon and Target
The growing role of artificial intelligence in cyberattacks deserves special attention. AI significantly simplifies conducting phishing campaigns and automated hacks. Attackers actively use tools like ChatGPT and Cursor to generate malicious code, compose convincing messages, and develop social engineering scenarios.
Moreover, AI agents themselves are becoming targets. A case was recorded where a hacker first conducted an NFT airdrop granting extended rights, then sent a message in Morse code to the Grok chatbot. The bot perceived it as a hidden command to transfer funds. The trading agent BankrBot, involved in this chain, considered the transaction safe and transferred about $175,000 to the attacker's on-chain addresses. This is a classic example of an attack on an AI agent's chain of trust.
My professional opinion: Security teams today face a dual threat. On one hand, the number of attacks is not decreasing, and on the other, artificial intelligence is fundamentally changing the mechanics of their execution. The market is transitioning from defending against a "sledgehammer" to defending against a "swarm of needles," and old methods no longer work here. A fundamentally new approach to auditing and monitoring is required, taking into account the AI vector.