H1 2026 broke all-time exploit records with 212 incidents and $1.1B stolen — North Korea's Lazarus Group claimed 66% via two DeFi infrastructure breaches.
The first six months of 2026 were the most-attacked period in cryptocurrency history. Security firms Blockaid and TRM Labs published their H1 2026 retrospectives in late July, tallying between 207 and 212 verified incidents — the highest volume ever recorded in any six-month window — and between $972 million and $1.1 billion drained from protocols, wallets, and infrastructure. The headline finding cuts through the noise: North Korea's Lazarus Group alone was responsible for 66 cents of every dollar stolen.
By the Numbers: Record Attack Volume, Smaller Individual Losses
The headline contrast in every H1 2026 security report is incident frequency versus catastrophic scale. TRM Labs counted 207 incidents and $972 million in total losses, with Q2 alone setting a single-quarter record at 123 attacks. Blockaid's H1 2026 report, published July 28, counted 212 verified incidents and $1.1 billion in total losses, calling it "the most-hacked half-year on record." The discrepancy between the two figures reflects methodology — Blockaid includes wallet-level phishing and certain infrastructure exploits that TRM's framework categorizes separately.
Both totals land well below H1 2025's $2.3 billion, but that comparison requires context. The 2025 figure was dominated by February's $1.5 billion Bybit exchange breach — a single event that inflated the entire annual tally. Strip it out, and 2026 represents a genuine escalation in attack frequency even as the largest individual events were smaller in scale.
TRM's median loss per incident came in at $219,000, while the mean reached $4.7 million — a gap that reflects a two-speed landscape: hundreds of small smart-contract exploits running alongside a handful of nine-figure infrastructure heists. The industry averaged more than one breach per day during the first six months of the year.
North Korea Accounts for 66% of H1 2026 Losses
The most alarming finding across every H1 2026 security report is consistent: state-sponsored attackers linked to the Democratic People's Republic of Korea (DPRK) dominated the period. TRM Labs attributes $643 million — 66% of its $972 million total — to North Korean operatives. Blockaid links Lazarus Group's TraderTraitor subunit to approximately 55% of its $1.1 billion total, encompassing three major operations.
The two defining operations in April 2026 followed a now-recognizable pattern:
- KelpDAO breach: $292 million drained via compromised multisig signing infrastructure
- Drift Protocol breach: $285 million stolen through what Blockaid described as "LinkedIn social engineering leading to multisig signer compromise"
Combined, those two incidents account for $577 million — nearly 60% of all H1 losses concentrated in a single month. A third North Korea-linked event, the Humanity Protocol breach in June, contributed approximately $32 million more to the total.
The attack vector is what makes these incidents so difficult to address through conventional security measures. These are not smart contract bugs discoverable through fuzzing or formal verification. They are sophisticated multi-month social engineering campaigns where operatives identify high-value signing authorities on LinkedIn, build rapport under false identities, and ultimately deliver malware payloads that exfiltrate signing credentials. Once keys are compromised, the fund drain is swift and technically irreversible.
For perspective on Lazarus Group's scale: the unit is estimated to have stolen over $3 billion from the cryptocurrency industry since 2016. Those proceeds directly fund North Korea's ballistic missile and nuclear programs, giving the state an effectively unlimited incentive structure for continued operations. The $643 million from H1 2026 alone represents a significant fraction of North Korea's estimated annual military budget.
Ethereum and Solana Absorb 60% of Total Losses
Breaking down by blockchain, Ethereum-linked projects suffered $332 million in H1 2026 losses — primarily through smart contract vulnerabilities in restaking protocols and DEX aggregators. Solana-linked projects came in close behind at $326 million, but with a structurally different profile: over 98% of Solana losses derived from compromised private keys and signing infrastructure, not from bugs in the protocol's programs.
Together, the two ecosystems absorbed approximately $658 million — roughly 60% of all tracked H1 losses. The divergence in attack vectors carries practical implications for builders. Ethereum's exposure points to continued risk at the application contract layer, where the complexity of restaking integrations and multi-protocol composability introduces new attack surfaces with each release. Solana's exposure, by contrast, signals a systemic weakness in key management practices among high-value protocols.
Blockaid documented at least seven cross-chain bridge incidents during H1 2026, targeting bridge validation logic and cross-chain message passing mechanisms. EVM Layer-2 networks were also affected, with attackers probing rollup fraud windows and proof systems in multiple documented cases.
Smart Contracts vs. Infrastructure: Where the Money Actually Goes
The incident-level breakdown reveals a structural inversion:
- Smart contract exploits: 125 of 207 incidents (61%) — the most common attack type by frequency
- Infrastructure and operational compromises: approximately 15% of incidents, but approximately 76% of total dollar value stolen
That inversion explains the North Korea pattern precisely. Lazarus Group's TraderTraitor unit does not depend on finding zero-days in production Solidity code. It runs targeted multi-month campaigns against the humans who control signing authority over protocol treasuries. When it wins, it wins at scale.
Other notable attack vectors from H1 2026 include at least one documented physical coercion incident — a so-called "wrench attack" resulting in approximately $24 million stolen — alongside recurring risk from cross-chain bridge exploits and EVM L2 proof system vulnerabilities. The $50.4 million CowSwap incident, the period's fourth-largest loss, demonstrated that even well-audited DEX aggregator infrastructure carries residual smart contract risk.
AI-Powered Threats: The Warning Signal for H2 2026
Both Blockaid and TRM Labs identified artificial intelligence as the next significant attack surface for H2 2026. Prompt injection attacks — where malicious inputs cause AI agents to take unintended actions — are specifically cited as the leading emerging concern for autonomous DeFi protocols. As more protocols deploy AI agents to automate yield strategies, rebalancing, and liquidity management, those agents hold signing credentials and can execute significant transactions without human review. A successful prompt injection campaign targeting an AI vault agent could produce losses at a scale comparable to the infrastructure compromises that defined H1.
Blockaid noted it tracked 3.4 times more high-threshold exploits in H1 2026 than throughout all of 2025, suggesting the attack surface is expanding faster than defenses. A flash loan attack against an AI-automated yield vault in July cost $6 million and previewed how adversarial inputs can manipulate autonomous agents managing live DeFi positions. As AI agent frameworks mature and control larger asset pools, the potential loss magnitudes scale alongside them.
What This Means for Investors
The North Korea threat is structural, not episodic. The $577 million spring campaign is not an isolated incident — it is part of a decade-long state-backed operation that has consistently scaled its ambition as the crypto industry has scaled its liquidity. Investors should treat DPRK exposure as a systemic risk across high-TVL infrastructure protocols, particularly those using multisig arrangements managed by small signer sets.
Audits are necessary but not sufficient. The KelpDAO and Drift Protocol breaches bypassed every conventional security review because the attack surface was human, not technical. Protocols controlling significant value need operations security programs — vetting contractors, restricting key access, rotating signing credentials, and monitoring for social engineering approaches — applied with the same rigor as smart contract audits. The absence of published OpSec practices is itself a risk signal.
Bridge and cross-chain infrastructure remains the highest-risk category. Seven or more documented bridge incidents in a single half-year reflects a pattern: the multi-chain ecosystem's interconnective infrastructure has not kept pace with its complexity and the value it routes. Investors with significant cross-chain exposure should closely monitor the security practices and any on-chain insurance coverage of the bridges they rely on.
DeFi's long-term security trajectory is improving. Despite the headlines, DeFi-specific losses have fallen 74% from their 2022 peak of $2.62 billion to an estimated $680 million in H1 2026. On-chain security practices — formal verification, real-time monitoring, and rising bug bounties — are demonstrably working at the contract layer. The open question for H2 2026 is whether the same discipline can be applied to the off-chain infrastructure and human trust layers where most of the actual money is now being lost.