The first half of 2026 brought a paradoxical surprise to the industry. On one hand, the number of security incidents soared by 50% compared to the same period last year. On the other hand, the total financial damage actually decreased by nearly 60%. This is not just statistics, but a clear signal of structural changes in the cyber threat landscape.
My analysis of data from January to June 2026 shows that 182 attack cases were recorded, totaling approximately $956 million. For comparison: a year earlier, 121 attacks occurred, but losses exceeded $2.37 billion. The key takeaway: attackers have become more active, but their "haul" is concentrated on a narrow range of large targets, rather than being spread across many small ones.
Shift in Priorities: From Mass Attacks to Precision
The largest number of incidents (85 cases) is related to vulnerabilities in smart contracts and protocol logic. In second place is the compromise of private keys and access data (17 episodes), and in third place are supply chain attacks (12 cases). However, when looking at financial losses, the picture changes dramatically. The biggest damage—about $298 million—came precisely from supply chain attacks. And here, a single, albeit large-scale, incident played a key role.
The hack of the Kelp DAO protocol, which I associate with the activities of the North Korean Lazarus group, led to an immediate loss of nearly $292 million. This is the largest theft of the half-year. Vulnerabilities in contracts caused $152 million in damage, and key compromises accounted for another $130 million. Notably, the network that suffered the greatest losses was Ethereum—about $134 million.
Artificial Intelligence as a New Weapon for Hackers
Special attention should be paid to the growing role of artificial intelligence (AI) in cyberattacks. My sources confirm that attackers are actively using AI solutions, such as ChatGPT and Cursor, to generate malicious code, compose phishing messages, and develop social engineering scenarios. The HexagonalRodent group (a Lazarus unit) has already lured developers with fake high-paying job offers to inject malicious code, bypassing security systems.
Moreover, AI agents themselves are becoming targets. In May 2026, a case was recorded where a hacker first conducted an NFT airdrop with extended permissions, then sent a Morse code message to the Grok chatbot, which it interpreted as a hidden command to transfer funds. The BankrBot trading agent deemed the transaction safe and transferred about $175,000 to the attacker's on-chain addresses. This is a classic attack on the trust chain of an AI agent.
My professional opinion: The increase in the number of attacks alongside a decrease in damage is not a reason for complacency. We are witnessing a shift from "firing all guns" to surgically precise strikes, enhanced by AI. Security teams now need to solve two tasks simultaneously: counter the quantitative onslaught and defend against qualitatively new, intelligent attack vectors, where machines manipulate machines. This requires a complete overhaul of all DeFi security approaches.