Blockaid published its H1 2026 on-chain security report on 28 July 2026, counting 212 verified security incidents and more than $1 billion in stolen funds across the first half of the year. That is the highest six-month incident count the firm has recorded.

Cointelegraph and FXStreet matched the same core figures within a day. Some outlets put the dollar total near $1.1 billion; the shared headline is a record count of verified exploits, with losses still clustered in a few catastrophic infrastructure breaches.

What Blockaid measured

Blockaid is an on-chain security platform that verifies exploit incidents and maps stolen-fund flows. Its half-year report covers confirmed hacks and operational compromises against protocols, bridges, wallets, and related infrastructure. Phishing and pure social-engineering scams outside that verified set sit outside the tally, so this is a security-incident ledger, not a full picture of all crypto crime.

The firm called H1 2026 the most-hacked half-year on record by incident count. It also said H1 alone produced 3.4 times as many verified exploits as Blockaid recorded across all of 2025. Average loss per incident landed near $5.4 million, according to FXStreet’s write-up of the report, a mean pulled hard by a handful of nine-figure events.

This is a second major firm view of the same half. In early July we covered TRM Labs’ H1 dataset (207 hacks, about $972 million). Different scopes and thresholds produce different totals; both point the same direction: more incidents than ever, dollars still dominated by a few operational failures rather than a flood of mid-size code bugs.

Ethereum and Solana took most of the damage

Ethereum led network losses at roughly $332 million. Solana was close behind at about $326 million, per Cointelegraph’s summary of the report. That Solana figure is a sharp step up from the roughly $127 million Blockaid attributed to Solana for full-year 2025.

The attack patterns diverged by chain. On Ethereum, code exploits drove the incident count: bugs in bridges and contracts, unauthorized access to privileged accounts, and market-manipulation techniques against high-value applications such as restaking platforms, stablecoins, and decentralized exchanges. Major key-compromise cases (including incidents involving Humanity Protocol and StablR) still added large dollar losses on Ethereum, but the volume of attacks looked like application-layer risk.

On Solana, compromised keys and signing infrastructure accounted for more than 98% of losses. Blockaid tied the bulk of that damage to incidents involving Drift Protocol and Step Finance, which it linked to North Korea–associated cyber groups. A smaller set of code exploits (including Raydium and Volo) made up the remainder. Same industry, different failure modes: Ethereum took more code-level hits; Solana’s dollar damage came almost entirely from who controlled the keys.

April still owned the half

Two April incidents again explain most of the money. KelpDAO lost about $292 million after a compromised bridge path in its cross-chain messaging stack, the single largest event in Blockaid’s half. Drift Protocol lost about $285 million through a multisig compromise that drained funds in under 12 minutes. Together those two events totaled roughly $577 million, more than half of H1 dollar losses, and they landed only 17 days apart.

FXStreet’s report summary also sizes the half by attack vector: privileged key misuse around $790 million, on-chain protocols about $524 million, and cross-chain bridges about $372 million. Those buckets overlap rather than partition the total — which is why they add up to more than the half’s headline figure. KelpDAO’s bridge compromise, for instance, counts as both a privileged-key failure and a bridge incident. Bridge incidents mixed that key compromise with code exploits at venues including Verus, Taiko, Alephium, Secret/Axelar, Swapnet, and Syscoin. Blockaid also flagged AI agents as a rising attack surface. That vector is not yet the main dollar driver; the firm still put it at the top of its emerging-threat list.

Attribution still runs through state-linked operators. CryptoBriefing and TechTimes put the Lazarus-linked cluster at roughly $609 million, or about 55% of losses against the $1.1 billion reading of the half. That sits in the same ballpark as TRM’s earlier ~66% North Korea share for H1; different firms, different labels, same concentration story.

Takeaway

The H1 2026 security picture is no longer “DeFi is full of buggy contracts” as the main dollar problem. Audits still matter, but the expensive failures were privileged keys, multisigs, bridge messaging, and organizational signing workflows (the human and ops layer around on-chain systems).

If you self-custody, treat seed phrases, hardware signers, and approval hygiene as the real perimeter. If you leave funds on an exchange or in a protocol-controlled vault, you are underwriting that operator’s key management as much as its smart-contract audit PDF. Watch for multisig and privileged-role design the next time a product asks for large deposits. This is operational security reporting, not a market call. Not financial advice.