Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$63,097.4 -0.95%
ETH Ethereum
$1,867.41 -0.50%
SOL Solana
$72.94 -0.78%
BNB BNB Chain
$579.6 -1.85%
XRP XRP Ledger
$1.06 -0.72%
DOGE Dogecoin
$0.0698 +0.50%
ADA Cardano
$0.1732 +2.55%
AVAX Avalanche
$6.36 -1.10%
DOT Polkadot
$0.7693 +1.42%
LINK Chainlink
$8.1 -1.71%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,097.4
1
Ethereum
ETH
$1,867.41
1
Solana
SOL
$72.94
1
BNB Chain
BNB
$579.6
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0698
1
Cardano
ADA
$0.1732
1
Avalanche
AVAX
$6.36
1
Polkadot
DOT
$0.7693
1
Chainlink
LINK
$8.1

🐋 Whale Tracker

🔵
0x97a1...4b30
12m ago
Stake
5,659 SOL
🔵
0x1750...51e1
30m ago
Stake
4,629 BNB
🔵
0x0609...36e5
12h ago
Stake
121,606 USDC

💡 Smart Money

0x52ec...0bc9
Arbitrage Bot
+$3.0M
69%
0xe4ec...53be
Market Maker
+$1.7M
70%
0x0842...f7f1
Early Investor
+$1.3M
78%

🧮 Tools

All →
Price Analysis

The H1 2026 On-Chain Body Count: 212 Exploits, $1.1 Billion Gone, and the Industry Is Still Auditing the Wrong Thing

Cobietoshi

212.

That is the number that should make every DeFi founder pause before bragging about the next audit. In the first six months of 2026, Blockaid counted 212 separate crypto security incidents, with total losses of approximately $1.1 billion. More than one exploit per day. Not a single Bybit-style headline heist dominating the chart, but a drumbeat of smaller, faster, more surgical strikes. The record incident count is not a random spike. It is a signal.

The market may be a bear, but somebody forgot to tell the attackers. While retail traders obsess over Bitcoin dominance and Layer 2 throughput, a parallel economy has been running on stolen private keys, compromised multisig signers, and forged cross-chain messages. Volatility isn't a bug; it's the dance. But this dance floor is on fire.

The H1 2026 On-Chain Body Count: 212 Exploits, $1.1 Billion Gone, and the Industry Is Still Auditing the Wrong Thing

This is not an ordinary security report. It is a mapping of how crypto actually breaks in 2026. And the pattern is uncomfortable: the biggest losses are no longer coming from clever smart contract bugs. They are coming from the oldest vulnerability in the world — the human being holding the keys.

I've been in this industry long enough to remember when a single exploit could be dismissed as an anomaly. 2017 taught me to read whitepapers at 2 a.m. and trust my gut when the community whisper network started buzzing. DeFi Summer taught me that hype is a leading indicator. But the 2026 security crisis is teaching me something harder: audits are not insurance. They are receipts.

The Context: A Security Crisis Hiding in Plain Sight

Blockaid, the on-chain security firm that has become the industry's first responder, published the data covering H1 2026. The headline numbers are stark enough: 212 incidents, $1.1 billion in losses, and an all-time record for incident count. But the deeper story is in the composition of those losses.

A year earlier, the H1 2025 numbers were warped by one gigantic event — the Bybit exploit. That single incident pushed the total dollar figure higher than this year's H1 number, creating a false sense that the industry was somehow improving. It wasn't. When you strip away the tail risk, the frequency of attacks has exploded. In H1 2026, the ratio of incidents to lost dollars inverted: more events, lower average value per event, but far more sustained destruction.

This is a classic attack pattern in hostile environments. Instead of one perfect strike on a heavily fortified target, adversaries run a campaign of attrition. Small-to-mid-size protocols become the target-rich environment. They have enough TVL to make the hack worthwhile, but not enough security budget to defend against a professional state-sponsored threat actor.

The current cycle matters too. In a bear market, survival matters more than gains. Protocols bleeding stablecoins face an even harsher reckoning because the exit liquidity is thinner, the lending platforms are more conservative, and users are already jumpy. A $20 million exploit in a bull market gets absorbed by the market's euphoria. The same exploit in a bear market starts a bank run. The 212 incidents are not a static statistic; they are a rolling confidence shock for every protocol that shares a chain, an ecosystem, or a similar architecture.

The other context is regulatory. In Brussels, the conversation has shifted from “which tokens are securities” to “when the next North Korean exploit occurs, how do we freeze the funds?” That shift matters. Institutional capital is watching these security reports more closely than any technical audit. The 2025 institutional convergence that I documented from a high-level Brussels summit was built on the assumption that regulated, compliant venues could house crypto safely. A 212-incident first half threatens that assumption.

Core Analysis: The Breakdown of $1.1 Billion in Losses

The most important number in the Blockaid report is not the total. It is 74%. That is the share of losses attributed to operational security attacks — credential leaks, private key theft, signer infrastructure compromises, bridge infrastructure breaches, and backend system infiltrations. Only about a quarter of the losses came from smart contract vulnerabilities in the traditional sense. That is a massive inversion of the old DeFi security narrative.

For years, the standard crypto security playbook was simple: hire a prestigious audit firm, publish the report, and hope the market rewards you. The audit was the sine qua non of legitimacy. But the 2026 data shows that audits are not stopping the bleeding. DeFi's center of gravity has shifted from “make the code safe” to “make the operations safe.” And the industry is not adapting.

Let me be blunt about what this means in practice. An attacker no longer needs to find a reentrancy bug in a staking contract. They need to find a finance person who reuses passwords, or a signer who clicks a LinkedIn message from a fake recruiter, or a multisig quorum with five signers all using similar cold wallets stored in the same office. The code can be perfectly sound. The backdoor is the person who has the signing key.

Based on my audit experience — and I have read more “fully audited” contracts than I care to count — the phrase “fully audited” has become the sector's most dangerous four syllables. It creates a false sense of operational immunity. The H1 2026 data exposes that complacency.

Ethereum and Solana: Two Chains, Two Failure Modes

One of the report's most revealing details is the divergence between Ethereum and Solana. Ethereum-based projects lost roughly $332 million, most of which came from code-level vulnerabilities. Solana, by contrast, saw more than 98% of its losses attributed to private keys and signing infrastructure being compromised.

That divergence tells a story about ecosystem maturity and security culture. Ethereum's DeFi protocols have been through multiple bear markets. They have battle-tested libraries, mature audit ecosystems, and a protocol architecture that encourages defensive layering. Even with those defenses, Ethereum still lost hundreds of millions to code bugs. The attackers are simply getting better at finding edge cases in complex contract interactions.

Solana's story is different. The ecosystem grew explosively during the NFT and DeFi cycles, with emphasis on speed, execution, and low fees. Security often came second. If 98% of Solana's losses are from private key or signing infrastructure compromises, that is a systemic indictment of the developer tooling, the wallet ecosystem, and the operational practices across the ecosystem. It suggests a generation of founders and developers entered the space with minimal security hygiene, built products rapidly, and became easy prey.

I do not want to single out Solana unfairly — Ethereum has had terrible operational compromises too. But the statistical pattern is brutal. The ecosystem that relied most heavily on centralized signer infrastructure, admin keys, and fast-moving developer workflows paid the price. This is not a failure of one protocol. It is a failure of a security model that treats private keys as the last line of defense instead of the first thing to protect.

KelpDAO and the Single-Validator Disaster

A major event in the H1 2026 tally is the KelpDAO attack, with losses around $292 million. KelpDAO is a restaking protocol, meaning its value proposition is built on trust — users lock assets into the protocol to secure other networks, earning yield in exchange for security services. When I say that the protocol lost $292 million, I am not just talking about a smart contract losing funds. I am talking about a fundamental breach of the restaking social contract.

What makes the KelpDAO case even more alarming is LayerZero's attribution: the cross-chain message forgery was enabled by a single-validator configuration. In other words, the system that was supposed to verify cross-chain messages was actually running with one effective validator. It represented a “nominal multisig, actual single validator” structural flaw.

This is the hidden danger of cross-chain infrastructure. Most users assume that bridges and message-passing protocols have decentralized validation baked in. The KelpDAO event strips that assumption bare. If a single compromised validator can forge a cross-chain message, then the entire security model is a façade. The protocol may have had audited contracts, decentralized governance, and a fancy UI, but the cryptographic trust layer was a paper tiger.

The operational security failure here is profound. A bridge is only as strong as the weakest validator. And a single-validator misconfiguration is not a code vulnerability that a formal verification tool will catch. It is a deployment and governance choice. It is the kind of thing that gets missed when security teams focus exclusively on code and not on the actual runtime configuration.

Drift Protocol: Six Months of Quiet Espionage

The Drift Protocol incident, with roughly $285 million in total compromise, is another case study in operational security. Drift is a derivatives protocol. It holds user margin, open positions, and collateral. An attacker who breaches a derivatives protocol is not just stealing yield; they are breaking the market infrastructure that traders rely on for hedging and speculation.

The Blockaid report connects Drift, KelpDAO, and Humanity Protocol into the same North Korea-linked threat cluster. And the Drift attack description is chilling: a six-month spy operation, using LinkedIn social engineering, targeted infiltration, and physical offline espionage to compromise multisig signers.

Let me slow down on this. Six months. That is not a flash hack. That is a sophisticated intelligence operation. The attackers did not exploit a vulnerability; they nurtured a relationship. They messaged a team member on LinkedIn, posed as a recruiter or investor, sent documents containing malware, mapped the team's internal structure, and eventually got close enough to a signer to infiltrate the signing process.

As someone who has watched the industry oscillate between euphoria and terror for years, I find this deeply personal. The bright-eyed founders in 2017 thought they were building an alternative to the old financial system. They did not expect nation-state adversaries with intelligence agency methodologies. But that is the reality of crypto in 2026. The same accessibility and borderless nature that makes DeFi beautiful also makes it a battleground for hostile states.

This is not a bug that a new smart contract language can fix. No amount of Solidity fuzzing protects against a compromised laptop belonging to the finance lead. The Drift attack is a reminder that protocols need physical security, penetration testing of their people, background checks, hardware security modules, and airtight signing procedures.

Resolv and CowSwap: The Top Four Are Everything

The Blockaid data shows that the top four events accounted for $707 million — or about 64% of all losses. KelpDAO and Drift are two of the names. Resolv and CowSwap are the other two, and while the report's public breakdown does not give them the same level of detail, their inclusion in the top four is meaningful.

Resolv is a stablecoin-focused protocol. Stablecoin security breaches strike at the heart of crypto's promise — that a token will maintain its peg and that a user can exit at any time. When a stablecoin-related protocol loses hundreds of millions, the damage is not just limited to the protocol's treasury. It cascades into DEX liquidity, lending markets, and borrowing positions.

CowSwap, a DEX aggregator, occupies a different position. Aggregators route user orders to the best available liquidity. A security event at a DEX aggregator can damage user trust in the entire aggregation layer, especially if the compromise affects routing logic or settlement contracts. Even if the direct loss is smaller than KelpDAO's, the reputational damage is amplified by the protocol's role as a connective tissue in the DeFi ecosystem.

The concentration of losses in the top four is actually a clue. It tells me that attackers are optimizing for large single hits, not just spraying small exploits. The 212 incident count may suggest a fragmented attack landscape, but the dollar concentration says otherwise. At least one threat actor — the North Korean cluster — is systematically targeting high-impact protocols with deep pools of user funds. Frequency is the cover; concentration is the strategy.

The New Frontier: AI Agents and EIP-7702

Every security report in 2026 has to address the new attack surfaces. Blockaid's report does not shy away from them. For the first time, an AI agent was manipulated into approving unauthorized transactions, leading to a loss of roughly $216,000 at Bankr. And EIP-7702 wallet delegation functionality has already been abused.

The H1 2026 On-Chain Body Count: 212 Exploits, $1.1 Billion Gone, and the Industry Is Still Auditing the Wrong Thing

These numbers are tiny compared to the $292 million loss at KelpDAO, but they are the canary in the coal mine. AI agents are being trained to sign transactions, move funds, and manage portfolios autonomously. The deeper their autonomy, the more dangerous a manipulated prompt or a poisoned dataset can become. If an AI agent can be socially engineered into approving a malicious transaction, then we are not just fighting attackers who target humans; we are fighting attackers who target the software we delegate our authority to.

EIP-7702 adds another layer of complexity. It allows a wallet to delegate its transaction execution to another contract, which is a powerful feature for account abstraction. But it also creates a new phishing surface. If a user is tricked into delegating their wallet to a malicious contract, the attacker can execute transactions on their behalf. The user may think they are still in control when they are not.

I remember when account abstraction was framed as a breakthrough that would onboard the next billion users. It still might. But the H1 2026 data shows that the adoption curve is racing ahead of the security curve. Every new authority delegation mechanism, every automated agent, and every session key is a potential exploit in the hands of a patient adversary. The solution is not to abandon innovation. It is to build in mandatory safeguards: transaction simulation, approval limits, human-in-the-loop checkpoints, and kill switches.

North Korea and the New Threat Intelligence Economy

The Blockaid data attributes about 55% of all stolen losses to North Korean-linked actors. That is an extraordinary number. It means that a single state actor was responsible for more than half of all crypto losses in the first half of 2026. This is not a disparate crowd of cybercriminals. It is a coordinated effort by a regime that has found crypto to be a reliable source of funding.

Blockaid's ability to cluster KelpDAO, Drift, and Humanity Protocol into the same North Korea-linked group is a breakthrough in attack attribution. It suggests that the security industry is moving from reactive exploit announcements toward proactive threat intelligence — clustering on-chain behaviors, wallet fingerprints, infrastructure patterns, and traditional intelligence cross-referencing. I assign moderate confidence to this because the exact methodology is private, but the pattern is visible. The same addresses, the same laundering strategies, the same operational rhythms tie these events together.

This creates a sobering realization: crypto security is now an intelligence contest. The attackers have intelligence agencies behind them. The defenders are still mostly deploying smart contract audits and bug bounties. That is an asymmetric war.

The Stellar Blend case offers a rare positive counter-example. When an exploit occurred, blockchain tracking helped isolate approximately $7.3 million in frozen assets. This shows that the defense is not entirely toothless. Real-time monitoring, attack attribution, and rapid asset freezing are becoming the new security triad. But of the $1.1 billion lost, only $7.3 million being isolated is a drop in the ocean. We are still losing the war.

Contrarian Angle: Audits Are the New Legacy Risk

Here is the contrarian take that will not be popular with the audit industry: the very practice of “safe, audited, verified” smart contracts is creating a false meta-risk. When a protocol is fully audited, it gets a higher TVL, which attracts more sophisticated attackers. The audit becomes a vulnerability magnet instead of a shield.

This is not an argument against audits. I still want every contract reviewed. But the security narrative must shift from “the code is safe” to “the system is resilient.” Resilience means the code has fault tolerance. It means the few vulnerabilities that still exist cannot be turned into a 100% treasury drain because of admin delays, upgrade permissions, or automated circuit breakers.

Take the KelpDAO single-validator case. A thorough audit of the smart contracts might never catch a single-validator configuration issue because it is a deployment-level concern. It only appears when you audit the actual infrastructure — the validator set, the signing schedule, the trust assumptions. Traditional security vendors are not set up for this. They are code-focused, not operations-focused.

Another contrarian angle: the community's obsession with “self-custody” is also incomplete. Self-custody prevents exchange hacks, but it does not prevent private key compromise. In H1 2026, the private key was the favorite attack vector. Telling users to self-custody without teaching them operational security is like telling them to swim across a shark-infested river because swimming pools are dangerous.

And there is a deeper institutional blind spot. When I talk to policymakers, they often say “we need more standards” as if standards alone will solve the problem. But the Drift attack shows that standards can be bypassed by a well-resourced adversary with a six-month espionage campaign. The real answer is layered defense: hardware security modules, strict key ceremonies, decentralized validation, real-time anomaly detection, and cross-exchange cooperation to freeze funds before they are laundered.

Tokenomic Aftershocks

Every exploit has a tokenomic shadow. When KelpDAO loses $292 million, the token of the underlying protocol takes a hit that no audit can repair. The restaking narrative — “deposit your LSD, secure other networks, earn yield” — relies on trust in the protocol's security. A massive exploit destroys that trust at its root.

Users of Drift Protocol are not just losing exposure to a token. They are losing margin, collateral, and the credibility of an entire trading venue. The threat of unstaking, unpooling, and withdrawal cascades becomes real. In a bear market, these cascades are more violent because there is less fresh capital to absorb the shock.

There is also the broader tokenomic question of where the stolen funds go. If the North Korean-linked actors stole around $605 million (55% of $1.1 billion), they will attempt to launder that money through mixers, cross-chain bridges, and OTC desks. Some of it may eventually hit centralized exchanges and be sold. That creates potential sell pressure on major assets like Bitcoin and Ethereum. I assign low confidence to any specific market forecast, but the directional risk is obvious: stolen crypto does not stay still.

The frequency of exploits will also raise the cost of capital for all DeFi protocols. Insurance premiums will increase. Security teams will need to be funded from token treasuries. Smaller protocols may not be able to afford the same level of defensive infrastructure as major players. This creates a winner-take-all dynamic in which only the most secure protocols can attract liquidity. In the long run, that might be good for the industry. But in the short run, it is brutal for small teams.

Market Implications: Risk Premium Repricing

The market may not have fully repriced DeFi risk. If H1 2026 had a $1.1 billion loss, an annual run rate of $2.2 billion is a massive tax on the ecosystem. Investors are still treating TVL as the primary health metric, but the correct metric should be “sustainable TVL after attack risk.” A protocol with $1 billion in TVL and a 30% annual attack probability is not worth the same as a protocol with $1 billion and a 2% attack probability.

Security is now a valuation factor. Protocols with robust operational security, multisig oversight, validators with high decentralization, and real-time monitoring deserve a premium. Protocols that rely on the outdated “one audit then ship” model are trading at a discount that they do not yet realize.

The broader market cycle matters as well. In a bear market, stablecoins and blue-chip assets get a flight to safety. But the H1 2026 exploit data includes stablecoin-related losses and sophisticated cross-chain attacks. When even “safe” assets are vulnerable, the market can become irrational about risk. We may see demand for self-custody hardware wallets rise again, as well as demand for zero-knowledge proofs that can prove a transaction before signing.

The one bright spot is the emergence of security as a service. Firms like Blockaid are becoming critical infrastructure. Their ability to attribute attacks to specific threat actor clusters is a kind of early warning system. If this data can be shared in real time across protocols, exchanges, and regulators, the industry can start to defend itself without waiting for a multi-million-dollar loss to occur.

The Road Ahead: What Actually Needs to Change

I have been in this industry long enough to stop believing in silver bullets. There is no single solution to a 212-incident half-year. But there are three priorities that would have materially reduced the damage.

First, operational security audits must become as common as smart contract audits. This means examining key management procedures, the physical security of signers, the rotation of credentials, and the governance of validators. It means testing the human layer. I am not talking about multiple-choice security awareness training. I am talking about live simulation phishing attacks, hardware security module mandates, and procedural separation between different signers.

Second, cross-chain infrastructure needs decentralization or high-integrity verification. If a bridge can be exploited by a single validator, that bridge is not a bridge; it is a honeypot. The industry needs to mandate minimum validator thresholds, cryptographic threshold signatures, and formalized response protocols when anomalous cross-chain activity is detected.

Third, the industry needs a global fund-freezing network. The Stellar Blend case showed that tracking can help isolate funds. But $7.3 million out of $1.1 billion is not enough. We need protocols, stablecoin issuers, exchanges, and law enforcement to cooperate at the speed of a Telegram message. When an exploit is detected, the stolen assets should be blacklisted across all major bridges and exchanges within minutes. This will not stop all attacks, but it will dry up the exit liquidity that makes massive hacks profitable.

For the human side, I want to emphasize something I learned in 2022 during the Terra collapse. Panic spreads differently in tight-knit communities than it does in public forums. The same is true for security. A protocol's community knows when the operations are sloppy. Users can ask hard questions: Who controls the admin keys? How many signers are required? Are signers geographically separated? What happens if a signer goes rogue? Asking those questions is not paranoia; it is diligence.

The regulators I spoke with in Brussels are increasingly focused on “key management accountability.” They do not want to ban DeFi. They want to know that the operators have procedures that resemble what the traditional financial system demands of custodians. If crypto cannot demonstrate that, the political pressure will only intensify.

In the end, the H1 2026 numbers are not a reason to abandon the crypto experiment. They are a reason to grow up. The early internet had a similarly chaotic period when malware, phishing, and security breaches were rampant. The internet survived because the industry invested in infrastructure: certificate authorities, operating system sandboxes, spam filters, and security teams. Crypto now has to invest in its own equivalent.

I don't regret the dance. I have seen the sprint of 2017, the liquidity trap of DeFi Summer, the isolation of the 2022 crash, and the institutional convergence of 2025. Each phase taught me something. The lesson of H1 2026 is this: code can be static and still be unsafe. Security is an operation, not a label.

Volatility isn't a bug; it's the dance. But too many protocols are dancing without knowing who is leading. The good news is that the data exists. Blockaid has given the industry a map. Now the question is whether founders will read it before the next exploit, or after.

Don't regret the dance. Learn the choreography.