Cryptocurrency Security Breaches in 2026
In the first half of 2026, reported security breaches within the cryptocurrency sector caused losses totaling a staggering $1.1 billion across 212 confirmed incidents, as detailed in a report released by Blockaid on July 28. This figure marks a significant increase, with the number of verified incidents being 3.4 times higher than that of the entire year of 2025.
Nature of the Breaches
Notably, a considerable portion—74%—of these losses stemmed from operational security breaches, while a specific group linked to North Korea reportedly accounted for 55% of the total amount stolen.
The data suggests a concerning trend where the majority of losses came not from flaws in smart contract code, but from compromised devices and unauthorized access to privileged credentials, private keys, and infrastructure used outside the blockchain. These incidents allow attackers to create seemingly legitimate blockchain transactions because they exploit approved access. As a result, traditional code audits, which are designed to detect vulnerabilities in smart contracts, fall short in preventing such exploits, underscoring the need for enhanced security measures.
Impact on Blockchain Projects
Concretely focusing on blockchain projects, Ethereum-related ventures reported losses nearing $332 million, largely due to vulnerabilities in code. The most severe incident involved KelpDAO, which saw attackers manipulate a bridge contract to abscond with 116,500 rsETH, valued at approximately $292 million after falsifying messages from the source chain.
Meanwhile, projects on the Solana network also faced significant setbacks, losing around $326 million, predominantly due to compromised signing infrastructure rather than coding errors, with major financial impacts felt by Drift Protocol and Step Finance.
Investigations and Recovery Efforts
Investigations by Chainalysis indicated that the KelpDAO breach was linked to North Korea’s Lazarus Group. Their analysis revealed that attackers infiltrated internal RPC nodes, thereby skewing the system perception to authorize false transactions without any corresponding destruction of tokens on the original chain.
Following the incident, KelpDAO successfully executed a recovery plan by late May but continues to deal with ongoing litigation regarding frozen funds. In a separate breach, Drift encountered an operational security failure on April 1, where social engineering tactics were employed to take control of administrative privileges, leading to losses of nearly $295.7 million. Their recovery strategies included commitments from multiple partners, including Tether, to establish a support fund to aid in recovery efforts.
Step Finance, on the other hand, succumbed to a similar attack that drained up to $40 million due to compromised executive devices. Despite some recovery efforts, they were unable to find a viable path forward and subsequently shut down.
Looking Ahead
As we look ahead, Blockaid suggests that cryptocurrency teams should enhance their focus on security protocols, particularly transaction-intent checks, secure signing mechanisms, and robust monitoring of bridges and other infrastructure layers. Future updates relating to ongoing recovery efforts and legal proceedings concerning these breaches are anticipated as affected entities navigate the aftermath of these significant security challenges.