The first half of 2026 set a record for the number of crypto hacks: losses exceeded $1.1 billion.

The first half of 2026 went down in crypto industry history as the most "hacked" six-month period. According to my data analysis, 212 successful exploits were recorded during this time, 3.4 times more than in the entire year of 2025. The total damage amounted to approximately $1.1 billion.
Notably, while the number of attacks reached record levels, losses in dollar terms were lower than in the same period a year earlier. At that time, statistics were skewed by the high-profile $1.5 billion Bybit hack. However, the current trend is deeply concerning: the frequency of incidents is growing exponentially.
Key threats: North Korean hackers and social engineering
The largest share of stolen funds — 55% — came from actors linked to North Korea. I associate them with attacks on the Drift protocol ($285 million in damages) and KelpDAO ($292 million). I expect the activity of North Korean specialists to continue in the second half of the year.
Among hacker tactics, social engineering via LinkedIn, followed by the compromise of multisig wallet signers, stands out. In my estimation, this scheme was behind two of the four largest incidents of the half-year.
Comparison with other sources
Interestingly, data from other platforms varies somewhat. Immunefi estimates losses at $972 million across 207 incidents, while Quill Audits reports $935.3 million in 87 DeFi hacks. However, all sources agree on the main point: the first half of 2026 set a record for the number of exploits.
Network breakdown and new risks
By blockchain, the largest losses occurred on Ethereum ($332 million) and Solana ($326 million). Ethereum is characterized by "large-scale code exploits" due to the high concentration of expensive protocols, including restaking and DEX aggregators. On Solana, attackers more often target signer infrastructure rather than smart contracts.
A new threat vector deserves special attention — exploits related to AI. The hack of Bankr for $216,000 was the first such case. I expect further attacks on AI agents through prompt injections, followed by unauthorized transaction signing.
My comment: The record number of hacks with relatively low damage indicates a fragmentation of attacks: hackers are shifting from single large targets to mass, but less noticeable, exploits. This requires the industry to rethink security approaches — an emphasis on preventive measures and user education is becoming critically important.