Crypto theft and fraud losses exceeded $1 billion in the first half of 2026, according to Blockaid’s H1 2026 security report released Tuesday. The period also featured the highest number of hacks in any six-month stretch recorded by the onchain security firm.
Ethereum and Solana accounted for the largest portions of stolen funds, with approximately $332 million and $326 million respectively. Blockaid tracked 212 security incidents during the six-month period, including a standout single exploit tied to KelpDAO, which Blockaid reported at $292 million.
Key takeaways
- Blockaid estimates total crypto losses above $1 billion in H1 2026, alongside the highest six-month hack count in its historical data.
- Ethereum led by stolen-fund impact (about $332 million), largely driven by code and application-layer exploits.
- Solana’s losses were similarly high (about $326 million) but were overwhelmingly linked to compromised keys and signing infrastructure.
- The largest single incident in the report involved KelpDAO, with losses of $292 million.
- Blockaid reports high-threshold exploit verification increased sharply in H1 2026 compared with all of 2025.
Ethereum’s losses underline application-layer risk
Blockaid said Ethereum incurred the highest losses from incidents in H1 2026, with attackers primarily focusing on vulnerabilities in applications built on the network. By count, code exploits were the dominant driver of Ethereum incidents, and Blockaid also highlighted that several major loss events involved compromised keys.
Among the notable incidents cited in the report were the Humanity Protocol and StablR attacks. CoWSwap was singled out as the only major Ethereum incident categorized as a user mistake, rather than a protocol or code vulnerability.
Blockaid described recurring techniques behind Ethereum-related breaches, including flaws in bridges and smart contracts, unauthorized access to privileged accounts, and market manipulation methods. While these categories differ in mechanics, they share a common theme: high-value Ethereum apps present a dense target surface for attackers seeking direct exploitation paths and privileged access.
The report also emphasized Ethereum’s role as a hub for major crypto primitives—restaking platforms, stablecoins, and decentralized exchanges—where substantial capital and complex integrations can concentrate both the value at risk and the probability of exploitable edge cases.
Solana’s stolen funds spiked with a shift toward key compromises
Solana’s losses in the first half of 2026 nearly matched Ethereum’s. Blockaid estimated stolen funds around $326 million for the period, a clear jump from roughly $127 million recorded in 2025.
In an observation carried in the report, Blockaid CEO Ido Ben-Natan told Cointelegraph that 2025 totaled $2.58 billion lost across 63 incidents, with activity concentrated in Q1 and with Ethereum and Arbitrum topping stolen-fund flow at the time.
However, Blockaid said Solana’s deterioration in H1 2026 did not come from a surge in smart contract exploits. Instead, compromised keys accounted for more than 98% of Solana’s losses, which Blockaid linked largely to incidents involving Drift Protocol and Step Finance. Blockaid also attributed those events to North Korea-linked cyber groups.
This matters because it reframes the operational priorities for Solana-related infrastructure. While Ethereum incidents in the report were more closely tied to vulnerabilities in protocol code, Blockaid said Solana-related losses were primarily associated with signer infrastructure and organizational security failures. In other words, the dominant threat vector in this period was not “bugs in execution,” but failures in control systems and signing operations.
Blockaid noted that only a small fraction of Solana losses were tied to code exploits—citing Raydium and Volo as examples—underscoring how heavily the report’s Solana narrative depends on key and signing security rather than on-chain contract defects alone.
What’s changed in the threat landscape
Two shifts stand out across Blockaid’s findings for H1 2026. First, Ethereum’s risk profile remained oriented around smart contract and application-layer weaknesses, where bridges, contract logic, and privileged account access can be exploited. Second, Solana’s losses, despite being comparable in size to Ethereum’s, were driven overwhelmingly by compromised keys and signing infrastructure—an operational and security governance problem rather than a pure software vulnerability issue.
Blockaid also reported that it verified 3.4 times as many high-threshold exploits in H1 2026 as it did across all of 2025. That suggests either that attackers pursued more severe, high-confidence exploitation paths during the period, or that the environment—across targets and integrations—supported higher-impact outcomes. In practice, for teams defending networks and protocols, it raises the likelihood of facing fewer “small” issues and more attacks with direct paths to material loss.
Finally, the report’s largest single exploit—KelpDAO at $292 million—fits the broader pattern of high-value targets attracting concentrated attacks. Even when overall incident counts vary, a small number of high-impact events can dominate the stolen-fund totals, which is precisely what appears in Blockaid’s H1 2026 breakdown.
Closing perspective
As H1 2026’s losses show, the most consequential threats are not uniform across chains: Ethereum-focused defenses should emphasize application and privileged access security, while Solana stakeholders should treat key management and signing infrastructure resilience as top priority. Readers should watch whether the disparity between code-driven incidents and key-driven incidents persists in the second half of 2026, and whether incident counts remain elevated alongside high-threshold exploit activity.





Be the first to comment