The industry built better smart contracts but forgot to lock the back door.

The Summary

The Signal

The numbers tell a story the industry doesn't want to hear. H1 2026 saw 212 exploits drain $1.1 billion, making it what Blockaid calls "the most-hacked half-year on record." That's not just a new high. It's a pattern that reveals where crypto's actual vulnerability lives.

The surprise isn't in the total dollar amount. Previous years saw bigger single heists. The shock is in the attack vector. Three-quarters of the stolen funds came from compromised keys and signer infrastructure, not the smart contract exploits that dominated headlines in 2021 and 2022. The code got better. The humans operating it did not.

"The industry built better smart contracts but forgot to lock the back door."

Here's what that 74% figure means in practice:

  • Attackers stopped hunting for obscure reentrancy bugs and Solidity edge cases
  • They started phishing signers, compromising admin keys, and exploiting weak operational security
  • The "trustless" infrastructure still runs on trusted keypairs held by people who click links

North Korea's fingerprints showed up on the two biggest single incidents. The $292 million KelpDAO exploit and the $285 million Drift hack both trace back to DPRK-linked groups. That's $577 million, more than half the total H1 losses, from a nation-state actor with a decade of crypto theft experience and zero reputational risk to manage.

The chain-level breakdown tells its own story. Ethereum stayed at the top of the target list, with Solana climbing to second place, pushing Arbitrum down. Solana's rise in the hack rankings isn't a bug. It's a feature of success. More value on-chain, more apps, more signers with access, more surface area to attack.

Blockaid's data shows the incident count climbing even as individual exploit sizes vary. 212 separate events in six months averages to more than one exploit per day. Some were six-figure rug pulls. Others were nine-figure infrastructure compromises. The long tail matters because it shows how normalized the threat has become. Hacking crypto protocols isn't a rare event anymore. It's Tuesday.

The Implication

If you're building in crypto, your threat model needs to change. Smart contract audits still matter, but they're not where the money's walking out the door. Key management, signer security, and operational hygiene now define whether your protocol survives contact with motivated attackers. Multisigs aren't enough if the signers use the same laptop they browse Twitter on.

For investors and users, this data argues for skepticism about custody claims. Protocols love to talk about decentralization and trustlessness, but the hacks tell you where centralization actually lives: in the admin keys, the treasury multisigs, the bridge operators. Ask about key storage, signer opsec, and incident response plans before you ask about total value locked. The $1.1 billion that disappeared in H1 sat in protocols that probably passed smart contract audits.

Sources

The Defiant | Unchained Crypto | CoinTelegraph