# Blockaid: 212 exploits, $1B+ lost in H1 2026

> Blockaid verified 212 crypto security incidents and more than $1B in H1 2026 losses. Ethereum and Solana led the dollar damage, mostly from keys, not code bugs.

- **Source:** https://ptycoin.com/en/posts/2026-07-30-blockaid-h1-2026-crypto-security-1b/
- **Published:** 2026-07-30
- **Category:** News
- **Author:** Mateo
- **Tags:** security, defi, exchanges, self-custody, ethereum
- **Also published in:** [Español](https://ptycoin.com/es/posts/2026-07-30-blockaid-h1-2026-crypto-security-1b/)

---


**Blockaid** published its [H1 2026 on-chain security report](https://www.blockaid.io/h1-report-2026) on **28 July 2026**, counting **212 verified security incidents** and more than **$1 billion** in stolen funds across the first half of the year. That is the highest six-month incident count the firm has recorded.

[Cointelegraph](https://www.tradingview.com/news/cointelegraph:b5b0378c6094b:0-ethereum-solana-led-crypto-hack-losses-in-h1-2026-blockaid/) and [FXStreet](https://www.fxstreet.com/cryptocurrencies/news/crypto-hacks-hit-record-high-with-212-exploits-in-h1-2026-202607290212) matched the same core figures within a day. Some outlets put the dollar total near **$1.1 billion**; the shared headline is a record *count* of verified exploits, with losses still clustered in a few catastrophic infrastructure breaches.

## What Blockaid measured

Blockaid is an on-chain security platform that verifies exploit incidents and maps stolen-fund flows. Its half-year report covers confirmed hacks and operational compromises against protocols, bridges, wallets, and related infrastructure. Phishing and pure social-engineering scams outside that verified set sit outside the tally, so this is a security-incident ledger, not a full picture of all crypto crime.

The firm called H1 2026 the most-hacked half-year on record by incident count. It also said H1 alone produced **3.4 times** as many verified exploits as Blockaid recorded across **all of 2025**. Average loss per incident landed near **$5.4 million**, according to FXStreet's write-up of the report, a mean pulled hard by a handful of nine-figure events.

This is a second major firm view of the same half. In early July we covered [TRM Labs' H1 dataset](/en/posts/2026-07-08-trm-labs-h1-2026-crypto-hacks-record/) (207 hacks, about **$972 million**). Different scopes and thresholds produce different totals; both point the same direction: more incidents than ever, dollars still dominated by a few operational failures rather than a flood of mid-size code bugs.

## Ethereum and Solana took most of the damage

**Ethereum** led network losses at roughly **$332 million**. **Solana** was close behind at about **$326 million**, per Cointelegraph's summary of the report. That Solana figure is a sharp step up from the roughly **$127 million** Blockaid attributed to Solana for full-year **2025**.

The attack patterns diverged by chain. On Ethereum, **code exploits** drove the incident count: bugs in bridges and contracts, unauthorized access to privileged accounts, and market-manipulation techniques against high-value applications such as restaking platforms, stablecoins, and decentralized exchanges. Major key-compromise cases (including incidents involving Humanity Protocol and StablR) still added large dollar losses on Ethereum, but the volume of attacks looked like application-layer risk.

On Solana, **compromised keys and signing infrastructure** accounted for more than **98%** of losses. Blockaid tied the bulk of that damage to incidents involving **Drift Protocol** and **Step Finance**, which it linked to North Korea–associated cyber groups. A smaller set of code exploits (including Raydium and Volo) made up the remainder. Same industry, different failure modes: Ethereum took more code-level hits; Solana's dollar damage came almost entirely from who controlled the keys.

## April still owned the half

Two April incidents again explain most of the money. **KelpDAO** lost about **$292 million** after a compromised bridge path in its cross-chain messaging stack, the single largest event in Blockaid's half. **Drift Protocol** lost about **$285 million** through a multisig compromise that drained funds in under 12 minutes. Together those two events totaled roughly **$577 million**, more than half of H1 dollar losses, and they landed only **17 days** apart.

FXStreet's report summary also sizes the half by attack vector: **privileged key misuse** around **$790 million**, on-chain protocols about **$524 million**, and **cross-chain bridges** about **$372 million**. Those buckets overlap rather than partition the total — which is why they add up to more than the half's headline figure. KelpDAO's bridge compromise, for instance, counts as both a privileged-key failure and a bridge incident. Bridge incidents mixed that key compromise with code exploits at venues including Verus, Taiko, Alephium, Secret/Axelar, Swapnet, and Syscoin. Blockaid also flagged **AI agents** as a rising attack surface. That vector is not yet the main dollar driver; the firm still put it at the top of its emerging-threat list.

Attribution still runs through state-linked operators. [CryptoBriefing](https://cryptobriefing.com/crypto-most-hacked-half-year-1b-stolen/) and [TechTimes](https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm) put the Lazarus-linked cluster at roughly **$609 million**, or about **55%** of losses against the **$1.1 billion** reading of the half. That sits in the same ballpark as TRM's earlier **~66%** North Korea share for H1; different firms, different labels, same concentration story.

## Takeaway

The H1 2026 security picture is no longer "DeFi is full of buggy contracts" as the main dollar problem. Audits still matter, but the expensive failures were privileged keys, multisigs, bridge messaging, and organizational signing workflows (the human and ops layer around on-chain systems).

If you self-custody, treat seed phrases, hardware signers, and approval hygiene as the real perimeter. If you leave funds on an exchange or in a protocol-controlled vault, you are underwriting that operator's key management as much as its smart-contract audit PDF. Watch for multisig and privileged-role design the next time a product asks for large deposits. This is operational security reporting, not a market call. Not financial advice.

---

## Keep reading

- [How to plan gas so your stablecoins stay spendable](https://ptycoin.com/en/posts/2026-07-28-gas-planning-native-fees-stablecoins/index.md): USDT can land in a wallet and still be unspendable. You need the chain's own coin for fees. This guide shows how to keep TRX, ETH, SOL, and similar gas ready before you need it.
- [How to pick the right network for USDT and USDC](https://ptycoin.com/en/posts/2026-07-21-pick-right-network-usdt-usdc/index.md): USDT and USDC exist on many chains. Wrong-network sends are a top permanent-loss risk. Use this checklist to match asset, network, fees, and wallet support before you transfer.
- [How to receive crypto safely into a self-custody wallet](https://ptycoin.com/en/posts/2026-07-14-receive-crypto-safely-self-custody/index.md): Receiving is safer than sending, but the wrong network or a shared address still loses funds. This checklist shows how to generate, verify, and share a receive address correctly.

---

Source: PTYcoin — https://ptycoin.com/en/posts/2026-07-30-blockaid-h1-2026-crypto-security-1b/. Free to read and cite with attribution to ptycoin.com. AI-usage terms: https://ptycoin.com/en/ai-usage/
