North Korea-linked attackers stole over half of all crypto funds lost in the first half of 2026, according to a new report from Blockaid. Hackers siphoned $1.1 billion across 212 incidents, making it the most active six-month period for crypto exploits on record. Four major breaches—targeting KelpDAO, Drift, Resolv, and CoW Swap—accounted for roughly $707 million of the total. State-sponsored groups tied to North Korea were responsible for $609 million in losses, or about 55% of all stolen funds. Privileged key misuse was the costliest attack vector, while AI agents emerged as a new target.
The first half of 2026 was the most active six months for crypto exploits on record. This is according to a new report from Blockaid, which shows hackers stole $1.1 billion across 212 incidents.
Four major incidents involving KelpDAO, Drift, Resolv, and CoW Swap made up roughly $707 million of the total losses. KelpDAO suffered the largest loss after hackers stole $292 million worth of crypto by faking a cross-chain message that siphoned off the protocol’s Ethereum reserves. Drift Protocol, a perpetuals exchange on Solana, was exploited for $285 million within 12 minutes.
Blockaid linked both cases to TraderTraitor, a state-sponsored North Korean subset of the larger Lazarus Group. Humanity Protocol’s $32 million loss was also connected to the same attacker cluster, bringing DPRK-linked losses to $609 million, about 55% of all funds stolen.
The pace of attacks increased through the year, with monthly incidents rising from 18 in January to 57 in June. April proved the most painful month, as the KelpDAO and Drift Protocol hacks wiped out a combined $577 million, pushing total losses that month to $635 million.
Privileged key misuse was the most costly attack type, with losses of approximately $790 million, or close to three-quarters of all funds stolen. Unbacked mint exploits came second, led by the $80 million Resolve breach. However, code-level hacks caused the most casualties, accounting for nearly four out of five attacks by count.
The report named AI agents as a new target after hackers used a prompt injection attack to fool Bankr’s AI agent into approving an unauthorized transaction for about $216,000. Cross-chain bridges also took a major hit, with attackers breaching the verification systems of KelpDAO and Taiko through forged proofs and attestations.
Security teams faced newer attack methods in 2026, with Blockaid identifying four incidents involving EIP-7702 wallet delegation attacks. Legacy smart contracts remain a common vulnerability, with around five cases in May and June, including two involving Aztec Connect and one targeting Raydium’s AMM V3.
Recent incidents outside the report period showed similar pressure. On July 23, AFX Trade, BSquaredNetwork, and Verus were hit in separate attacks on the same day, collectively causing more than $35 million in losses. Verus had already suffered another exploit about two months earlier, and Blockaid linked both incidents to the same bridge contract and bug class.
Recovery results varied depending on the attack type. Code-related incidents sometimes allowed teams to freeze funds or negotiate returns, while attacks involving stolen keys usually ended with the money moving through mixers or cross-chain routes.
