The industry built better smart contracts but forgot to lock the back door.
The Summary
- Crypto suffered $1.1 billion in losses across 212 separate exploits in H1 2026, the highest incident count ever recorded for a six-month period, according to security firm Blockaid.
- Compromised keys and signer infrastructure accounted for 74% of stolen funds, not smart contract bugs. The attack surface shifted from code to credentials.
- North Korea-linked actors drove the two largest single incidents: $292M from KelpDAO and $285M from Drift, both attributed to DPRK groups.
- Ethereum remained the most-targeted chain while Solana jumped to second place, displacing Arbitrum and highlighting the cost of rising adoption.
The Signal
The numbers tell a story the industry doesn't want to hear. H1 2026 saw 212 exploits drain $1.1 billion, making it what Blockaid calls "the most-hacked half-year on record." That's not just a new high. It's a pattern that reveals where crypto's actual vulnerability lives.
The surprise isn't in the total dollar amount. Previous years saw bigger single heists. The shock is in the attack vector. Three-quarters of the stolen funds came from compromised keys and signer infrastructure, not the smart contract exploits that dominated headlines in 2021 and 2022. The code got better. The humans operating it did not.
"The industry built better smart contracts but forgot to lock the back door."
Here's what that 74% figure means in practice:
- Attackers stopped hunting for obscure reentrancy bugs and Solidity edge cases
- They started phishing signers, compromising admin keys, and exploiting weak operational security
- The "trustless" infrastructure still runs on trusted keypairs held by people who click links
North Korea's fingerprints showed up on the two biggest single incidents. The $292 million KelpDAO exploit and the $285 million Drift hack both trace back to DPRK-linked groups. That's $577 million, more than half the total H1 losses, from a nation-state actor with a decade of crypto theft experience and zero reputational risk to manage.
The chain-level breakdown tells its own story. Ethereum stayed at the top of the target list, with Solana climbing to second place, pushing Arbitrum down. Solana's rise in the hack rankings isn't a bug. It's a feature of success. More value on-chain, more apps, more signers with access, more surface area to attack.
Blockaid's data shows the incident count climbing even as individual exploit sizes vary. 212 separate events in six months averages to more than one exploit per day. Some were six-figure rug pulls. Others were nine-figure infrastructure compromises. The long tail matters because it shows how normalized the threat has become. Hacking crypto protocols isn't a rare event anymore. It's Tuesday.
The Implication
If you're building in crypto, your threat model needs to change. Smart contract audits still matter, but they're not where the money's walking out the door. Key management, signer security, and operational hygiene now define whether your protocol survives contact with motivated attackers. Multisigs aren't enough if the signers use the same laptop they browse Twitter on.
For investors and users, this data argues for skepticism about custody claims. Protocols love to talk about decentralization and trustlessness, but the hacks tell you where centralization actually lives: in the admin keys, the treasury multisigs, the bridge operators. Ask about key storage, signer opsec, and incident response plans before you ask about total value locked. The $1.1 billion that disappeared in H1 sat in protocols that probably passed smart contract audits.