Crypto Losses Hit $1.1B in H1 2026 as DPRK Actors Drive Exploit Surge

DRIFT-2.06%
RESOLV-2.84%
H8.01%
AZTEC6.80%
RAY-0.42%
Key Takeaways
  • Blockaid verified 212 blockchain exploits in H1 2026, totaling $1.1 billion in losses, 3.4 times 2025's annual figure.
  • DPRK-linked TraderTraitor actors caused $609 million in damage, 55% of H1 total, through social engineering targeting protocol employees.
  • Compromised private keys drove $789 million in losses, 74% of H1 damage, with three novel attack vectors emerging including EIP-7702 wallet delegation.

Onchain security firm Blockaid verified 212 blockchain exploits in the first half of 2026, totaling $1.1 billion in losses. The incident count represented 3.4 times the number of high-threshold exploits recorded across all of 2025. DPRK-linked actors, primarily the TraderTraitor sub-group of North Korea's Lazarus Group, caused approximately $609 million in damage — 55% of the half-year total. Compromised private keys drove the majority of losses, accounting for nearly $789 million or 74% of all H1 damage across roughly ten incidents. The escalation reflects a structural shift in the threat landscape, with social engineering campaigns targeting employees at protocols including Drift and KelpDAO to gain control over multisig signers and bridge verifier infrastructure.

Four Incidents Account for 64% of H1 2026 Losses

The four largest incidents collectively accounted for roughly 64% of all H1 losses. KelpDAO recorded $292 million in losses, Drift Protocol $285 million, Resolv $80 million, and CowSwap $50.4 million. Two of these — KelpDAO and Drift — are directly attributed to TraderTraitor, a sub-group of North Korea's Lazarus Group. Combined with the separately attributed Humanity Protocol breach of $32 million, DPRK-linked actors were responsible for approximately $609 million. Both top-tier attacks began with social engineering: DPRK operators targeted employees at Drift and KelpDAO through LinkedIn-style manipulation, ultimately gaining control over multisig signers and bridge verifier infrastructure. The KelpDAO breach exploited a single-DVN configuration in the LayerZero bridge to forge a cross-chain attestation and drain $292 million from an Ethereum escrow.

Private Key Compromises Drive 74% of Total Damage

Compromised private keys emerged as the dominant loss driver by a wide margin, responsible for nearly $789 million — around 74% of all H1 damage — across roughly ten incidents. Code exploits, while far less costly in aggregate at $203 million, dominated by incident count, comprising nearly 80% of all cases. Resolv's $80 million unbacked mint was the largest in the code exploit category. Recovery outcomes proved sharply asymmetric: code exploits sometimes yielded partial fund recovery through emergency pause functions or onchain coordination, while key compromises saw near-zero retrieval, with stolen assets typically routed through mixers within hours.

Legacy Contracts and Three Novel Attack Vectors Expand Threat Surface

A recurring pattern involved legacy or deprecated contracts that teams had migrated away from but not fully decommissioned. Five such incidents in May and June — including two separate attacks on the Aztec Connect rollup and a validation exploit on Raydium's deprecated AMM V3 — totalled approximately $5.7 million. Three novel attack vectors made their first appearances in H1. EIP-7702 wallet delegation, introduced by a new Ethereum standard, was abused across four incidents. An AI prompt injection attack on the Bankr agent in May — the first of its kind — extracted $216,000 by tricking an autonomous system into authorising an unauthorised transaction. Off-chain bridge prover infrastructure was also newly targeted, with KelpDAO and Taiko both breached through forged proofs accepted by destination chains.

Recovery Outcomes Show Sharp Asymmetry Between Attack Types

The most successful containment of the period occurred on Stellar, where real-time wallet clustering by Blockaid enabled validators to quarantine $7.3 million — 73% of a $10.2 million oracle manipulation drain — within minutes of the attack. Code exploits sometimes yielded partial fund recovery through emergency pause functions or onchain coordination. Key compromises, by contrast, saw near-zero retrieval, with stolen assets typically routed through mixers within hours.

FAQ

What happened in the first half of 2026 in blockchain security?

Onchain security firm Blockaid verified 212 blockchain exploits in the first half of 2026, totaling $1.1 billion in losses. The incident count represented 3.4 times the number of high-threshold exploits recorded across all of 2025.

Why did DPRK-linked actors cause most of the damage in H1 2026?

DPRK-linked actors, primarily the TraderTraitor sub-group of North Korea's Lazarus Group, caused approximately $609 million in damage — 55% of the half-year total. Both top-tier attacks on KelpDAO and Drift began with social engineering campaigns targeting employees through LinkedIn-style manipulation, ultimately gaining control over multisig signers and bridge verifier infrastructure.

What new attack vectors emerged in H1 2026?

Three novel attack vectors made their first appearances in H1 2026: EIP-7702 wallet delegation was abused across four incidents, an AI prompt injection attack on the Bankr agent extracted $216,000, and off-chain bridge prover infrastructure was targeted, with KelpDAO and Taiko both breached through forged proofs accepted by destination chains.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments