Blockaid's first-half report, released on July 28, shows that the crypto industry experienced 212 confirmed security incidents in the first six months of 2026, resulting in a total loss of $1.1 billion. The report states that this number of incidents already exceeds the total for 2025, indicating that the frequency of attacks is still rising.
Most losses stem from operational safety errors.
The report shows that 74% of stolen funds did not originate from smart contract code vulnerabilities, but rather from compromised devices, private keys, signature systems, administrator privileges, and off-chain infrastructure. These types of attacks often initiate seemingly valid on-chain transactions because the operations utilize authorized credentials.
This also means that code auditing alone is no longer sufficient to cover major risks. Audits can uncover contract flaws, but they cannot prevent administrator accounts from being compromised and signing malicious transactions, nor can they prevent cross-chain validator nodes from relying on contaminated infrastructure.
North Korean-related clusters accounted for more than half of the losses.
Blockaid stated that a North Korean-linked attack cluster accounted for 55% of total losses in the first half of the year. However, different security companies do not entirely agree on their statistical methods and coverage, so there may be discrepancies in industry loss data.
The report also noted that Ethereum and Solana exhibited different attack patterns in the first half of the year. This reflects more the types of applications attacked and how project teams manage high-privilege access, and does not directly indicate which chain is inherently more secure.
KelpDAO and Drift disclose progress in recovery.
In specific cases, KelpDAO and Drift were two of the biggest losers in the first half of the year. Chainalysis previously linked the April 18 KelpDAO attack to North Korea's Lazarus Group. The investigation stated that the attackers compromised internal RPC nodes and interfered with external nodes, causing the single-validation system to accept a fake burn event, which subsequently led to the Ethereum sidebridge erroneously releasing rsETH.
KelpDAO completed the operational phase of its recovery plan on May 25, restoring minting, redemption, and reward functions after transferring the final 20,373.72 rsETH to the bridge adapter. However, lawsuits and disputes related to the frozen funds remain unresolved.
Drift proposed a recovery pool solution, with funding sources including exchange revenue, Tether, and other partners. The plan includes up to $127.5 million in support from Tether, $20 million from other partners, and transferable recovery tokens. The agreement states that OtterSec and Asymmetric audits will be completed before the restart, and dedicated signature devices, time locks, and a redesigned multi-signature mechanism will be introduced.
The stolen funds are still flowing on the blockchain.
The Drift incident is still ongoing. Previous reports indicated that a wallet associated with the attacker transferred 23,095.1 ETH to Tornado Cash between July 23rd and 24th, equivalent to approximately $44.4 million at the time. This address had been inactive for about three months prior to the transfer.
Blockaid anticipates that in the second half of the year, the project team will place greater emphasis on transaction intent verification, independent signing devices, key isolation, and continuous monitoring of cross-chain bridges and infrastructure. Going forward, the market will also focus on Drift's token recovery terms and restart timeline, Step Finance's remaining claims process, and court proceedings related to KelpDAO's frozen funds.











