Crypto projects lost $1.1 billion to hackers over the past six months — and that's actually less than a year earlier. The reason is simple: 2025 had one catastrophic hit, the $1.5 billion Bybit theft, while 2026's losses are spread across 212 separate incidents, a record count for a half-year, according to security firm Blockaid.
Nearly two-thirds of the total came from just four cases: KelpDAO lost $292 million, Drift Protocol $285 million, with Resolv and CowSwap adding to the tally. Together that's roughly $707 million out of the $1.1 billion total.
North Korea is the story running through the whole report. Hackers linked to the Lazarus Group are responsible for about 55% of all losses — roughly $600 million — including the KelpDAO and Drift hits. And they don't work the way most people picture crypto hacks. Instead of hunting for smart contract bugs, DPRK operators go after people: a fake recruiter reaches out on LinkedIn, sends a “coding test” laced with malware, and eventually a multisig signer hands over access without realizing it. Blockaid says 74% of everything stolen this half-year came from this kind of operational failure, not broken code.
Ethereum ($332 million) and Solana ($326 million) took the biggest hits, but through different playbooks: on Ethereum, attackers cracked large restaking, stablecoin and DEX-aggregator protocols through code exploits, while on Solana the target was usually signer infrastructure rather than contracts themselves.
Blockaid also flags a new front to watch — a $216,000 exploit against the Bankr trading bot, which it calls the first-ever hack of an AI agent, at a time when the number of such agents in crypto is roughly tenfold every year.



