The digital asset market faced a unique phenomenon in the first half of 2026. The number of security-related incidents surged by nearly 50% compared to the same period last year. However, the total amount of losses in monetary terms, on the contrary, decreased by almost 60%. This data, collected by leading blockchain security analysts, paints a complex and multifaceted picture of the evolving threat landscape.
From January to June 2026, 182 cases of hacks and thefts were recorded, totaling approximately $956 million. For comparison, a year earlier, the number of incidents was 121, and the damage reached an astronomical $2.373 billion. The key takeaway here is that the increase in the number of attacks does not correlate with an increase in damage. Major financial losses are now concentrated in a narrow circle of large, carefully planned targets.
Shift in Vector: From Mass Attacks to Targeted Strikes
The most common cause of incidents was vulnerabilities in smart contracts and protocol logic — 85 cases. Compromised private keys and access data took second place (17 episodes), and supply chain attacks took third (12 cases). However, looking at the distribution of losses, the picture changes dramatically.
The most funds were lost precisely due to supply chain attacks — about $298 million. The main catalyst was a single, but massive incident: the hack of the Kelp DAO protocol, which led to one-time losses of nearly $292 million. The investigation links this attack to the Lazarus group from North Korea. Contract vulnerabilities led to losses of $152 million, and key compromises to another $130 million. Among ecosystems, Ethereum (ETH) suffered the most, with total damages amounting to about $134 million.
Artificial Intelligence as a New Weapon
Analysts also note the rapid growth of the role of artificial intelligence in cyber threats. AI simplifies phishing and automated attacks, and attackers actively use it at all stages — from code generation to crafting social engineering scenarios.
One of the most striking examples is an attack on an AI agent's chain of trust. In May 2026, a hacker conducted an NFT airdrop that granted access to transfers with extended rights, and then sent a message in Morse code to the Grok chatbot. The bot perceived it as a hidden command to transfer funds. The BankrBot trading agent, involved in this chain, deemed the result safe and transferred about $175,000 to off-chain addresses. This is classified as an attack on an AI agent's chain of trust, where a malicious command passes through links that trust each other.
My expert opinion: We are witnessing a fundamental shift. The number of attacks is growing, but the average loss is decreasing — this suggests that security is becoming more effective for small and medium-sized projects. However, the main threat now comes from professional, well-funded groups that use AI for targeted strikes on large protocols and infrastructure elements. Security teams face a dual challenge: curbing the flow of small attacks while simultaneously building defenses against complex, multi-stage attacks using AI.