The first half of 2026 delivered a paradoxical lesson to the industry: the number of security incidents soared by 50% compared to the same period last year, yet total losses decreased by nearly 60%. From January to June, 182 cases of hacks and thefts were recorded, totaling approximately $956 million. In comparison, the previous year saw 121 incidents with losses reaching $2.373 billion.
This gap between attack frequency and damage scale is a key signal for the market. We are observing a shift in attackers' tactics: they have moved from "carpet bombing" to targeted, but highly effective operations. The main blow targeted vulnerabilities in smart contracts and protocol logic — 85 incidents. Private key compromises took second place (17 episodes), and supply chain attacks ranked third (12 cases).
One hack — nearly a third of all losses
Looking at the distribution of losses, the picture changes dramatically. The largest incident of the half-year was the hack of the Kelp DAO protocol, which led to a one-time loss of nearly $292 million. The investigation linked this attack to the North Korean Lazarus group. Thus, a single hack accounted for more than 30% of all losses for the half-year.
Contract vulnerabilities cost the industry $152 million, and key compromises added another $130 million. Among ecosystems, Ethereum suffered the most: losses on this network amounted to about $134 million. It is clear that the concentration of capital in large protocols makes them prime targets, and security must be built with this risk in mind.
AI is changing the game
Special attention should be paid to the growing role of artificial intelligence in cyber threats. Attackers are actively using AI tools, such as ChatGPT and Cursor, to generate malicious code, compose phishing messages, and automate social engineering. The HexagonalRodent group (a Lazarus unit) lured developers with fake high-paying job offers to inject malicious code, bypassing security measures.
Moreover, attacks are now also targeting AI agents themselves. In May 2026, a hacker conducted an NFT airdrop granting access to transfers with extended rights, then sent a Morse code message to the Grok chatbot. The bot interpreted it as a hidden command to transfer funds, and the trading agent BankrBot, considering the transaction safe, transferred about $175,000 to the attacker's on-chain addresses. This is a classic example of an attack on an AI agent's chain of trust.
Expert commentary from Cryptalist: The increase in attacks with a decrease in losses is not a reason for complacency. We see that attackers are becoming smarter and more selective. AI not only simplifies hacks — it transforms the very mechanics of attacks. Security teams now need to solve two tasks simultaneously: contain the quantitative pressure and adapt to qualitatively new threats, where a "trusted" AI agent can become a weak link.