Visit the new website The new BestChange website is live — take a look and tell us what you think!
Exchange rates:
1089315
Exchangers:
461
Updated:
18:17:19

More than $1 billion in six months: crypto projects are losing money to hacks more frequently

Scale and key causes of hacker attacks

During the first six months of 2026, crypto projects lost approximately $1.1 billion as a result of hacker attacks. A total of 212 incidents were recorded during this period — the highest number ever observed in a single six-month period, according to a report by Blockaid.

If the total amount of losses is divided by the number of recorded incidents, the average damage amounts to approximately $5.2 million per attack. However, this figure does not reflect the actual distribution of losses: most of the funds were stolen during several major hacks. In contrast, the damage caused by most other incidents was significantly lower.

Experts described January–June 2026 as the six months with the highest number of hacker attacks. This refers specifically to the number of hacks rather than the total value of stolen assets.

The increase in the number of incidents shows that attacks are becoming more widespread, but not necessarily more profitable for criminals. At the same time, losses remain highly concentrated: a single hack of a major service may be comparable in scale to dozens of attacks on smaller projects.

The main cause of financial losses was the human factor. Approximately 74% of the stolen funds, or $789 million, resulted from attacks in which criminals gained access to private keys or administrative privileges within crypto projects.

There were relatively few such incidents, but each of them could result in losses amounting to hundreds of millions of dollars. In particular, $285 million was stolen in the hack of Drift, a decentralised exchange for trading futures* on the Solana network. At the same time, KelpDAO, a protocol for the liquid restaking* of Ethereum-based assets, suffered losses of $292 million.

The combined damage caused by these two attacks reached $577 million — more than half of all losses recorded during the six months. This clearly demonstrates why a small number of successful attacks on critical infrastructure can have a greater impact on overall statistics than numerous hacks targeting smaller services.

* Futures are derivative financial instruments representing an agreement between parties to buy or sell an underlying asset at a predetermined price. Settlement under such a contract takes place at a specified point in the future or continuously in the case of perpetual futures. In the crypto industry, futures are used to profit from changes in the value of digital assets, hedge price risks, and trade with leverage.

* Liquid restaking is a mechanism for reusing digital assets that have already been locked in staking to support the security of an underlying blockchain network. The user transfers such assets to a specialized protocol, which uses them to secure additional services, applications, or infrastructure components. In return, the user receives a liquid token representing their share of the deposited assets and their right to accumulated rewards. This token can be transferred, exchanged, used as collateral, or deposited in other DeFi protocols.

In terms of the number of attacks, vulnerabilities and errors in smart-contract code ranked first. However, the combined damage caused by such incidents was significantly lower. This was because criminals more frequently targeted smaller protocols holding limited volumes of assets.

Typical smart-contract vulnerabilities include access-control errors, incorrect calculations, manipulation of price oracles*, re-entrancy attacks, and the use of flash loans to alter the state of a protocol.

* An oracle is a service that provides a smart contract with information from the external world that is not directly available within a blockchain. This may include asset prices, exchange rates, event results, payment information, weather data, and other information. After receiving this data, the smart contract automatically performs the specified action. The reliability of the oracle is critically important: if the transmitted data is incorrect or intentionally manipulated, the contract may perform an incorrect calculation, unjustifiably liquidate collateral, or transfer funds to a criminal.

A smart-contract audit reduces the likelihood of a hack but does not guarantee complete security. An audit usually covers a specific version of the code and a particular set of scenarios. Vulnerabilities that were not present during the initial audit may appear after the contract is updated, integrated with a third-party protocol, or subjected to changes in its administrative settings.

Who is behind the largest hacks

According to Blockaid, the largest share of stolen funds was attributed to hacker groups linked to North Korea. Experts reached this conclusion based on an analysis of the methods used by the attackers, the movement of stolen assets, and other digital traces. In particular, North Korean groups were blamed for the two largest attacks of the first half of the year — the Drift and KelpDAO hacks, which together accounted for more than half of the total losses.

According to estimates by UN experts and US law-enforcement and financial authorities, hacker groups linked to North Korea use the theft of digital assets as one method of obtaining foreign currency and circumventing international financial restrictions. It is believed that some of the proceeds are used to support North Korean state programs, including the development of nuclear weapons and ballistic missiles.

Two of the four largest incidents during the first half of the year involved a similar social-engineering* scheme conducted through LinkedIn, a business-focused social network designed for job searches, recruitment, and professional communication. The attackers posed as employers, partners, or other industry representatives, contacted employees of crypto projects, and attempted to gain access to private keys and internal systems using malicious files or links.

* Social engineering is a set of psychological manipulation techniques through which a criminal gains access to information, assets, or protected systems not by directly hacking technical infrastructure, but by manipulating a person. To do this, the criminal may impersonate an acquaintance, relative, bank employee, company representative, support-service worker, government official, or another person whom the victim is likely to trust. Attackers create fake accounts and websites, distribute malicious links and files, request confidential information, or use various pretexts to persuade a person to transfer money, disclose a verification code, or provide access to a device. Unlike mass phishing, which targets a broad audience, sophisticated social-engineering attacks are prepared individually, taking into account the personal data, interests, social circle, habits, and current circumstances of a specific person.

Which blockchains suffered the biggest losses

Among blockchain networks, projects operating on Ethereum and Solana suffered the greatest losses. Within the Ethereum ecosystem, which remains the largest platform for decentralized applications and smart contracts, attackers stole approximately $332 million. Projects based on Solana, which is popular because of its high transaction-processing speed and low fees, lost another $326 million. The significant damage suffered by projects on these networks was not caused by vulnerabilities in the blockchains themselves, but by the large number of DeFi protocols, exchanges, wallets, and other services operating on them and storing or processing substantial volumes of user assets.

Artificial intelligence as a new target for attacks

One of the key trends in cybersecurity has been the emergence of attacks targeting artificial-intelligence systems. These attacks primarily involve AI agents — programs capable of independently analyzing information, interacting with other services, and performing operations, including approving transactions. Attackers attempt to deceive such systems using specially formulated commands, malicious messages, or falsified data to force them to perform actions that their developers did not intend.

One such method is known as prompt injection. A malicious instruction may be embedded not only in a direct message from a user, but also within a website, document, email, or result received from another service. The AI agent processes this data as part of its working context and may mistakenly interpret a hidden command as an authorized instruction.

Blockaid classified such attacks as a separate and fundamentally new threat vector because traditional security assessments generally focus on software-code vulnerabilities and user actions, but do not consider the possibility of manipulating decisions made by artificial intelligence.

One example cited is an incident involving Bankr, a platform that allows users to manage digital assets through ordinary text commands. Its AI agents can independently interact with crypto wallets, execute swaps, launch tokens, manage DeFi positions, and carry out blockchain transactions on behalf of users. In the Bankr incident, attackers deceived an AI agent and caused it to approve an unauthorized transaction worth $216,000.

Experts note that such scenarios were virtually never considered during standard security audits as recently as 2025. As a result, vulnerabilities in AI agents may pose an especially serious threat to crypto projects.

Against the backdrop of the growing number of attacks, specialists are also drawing attention to the role of modern artificial-intelligence models in identifying vulnerabilities. In their view, AI is already capable of detecting weaknesses in software code more effectively than humans, creating additional risks for the entire decentralized-finance industry.

© BestChange.com – , updated 07/30/2026
Reprints are allowed only with permission of BestChange

See also