First half of 2026 saw $1.1B stolen across 212 crypto exploits, with privileged key misuse and AI agents emerging as primary attack vectors.
Security & Exploits ·
The first half of 2026 marked a record period for crypto exploits, with hackers stealing $1.1 billion across 212 incidents. Four major breaches—KelpDAO, Drift Protocol, Resolv, and CoW Swap—accounted for roughly $707 million of total losses. KelpDAO suffered $292 million after attackers faked a cross-chain message to drain Ethereum reserves, while Drift Protocol lost $285 million within 12 minutes. Both incidents were linked to TraderTraitor, a North Korean state-sponsored group tied to the Lazarus Group, which was responsible for approximately $609 million—or 55 percent—of all stolen funds in the period.
Privileged key misuse emerged as the costliest attack vector, accounting for approximately $790 million in losses. AI agents and cross-chain bridges also became prominent targets, with hackers using prompt injection to manipulate Bankr's AI agent into approving unauthorized transactions and exploiting verification systems through forged proofs. The frequency of attacks intensified throughout the period, rising from 18 monthly incidents in January to 57 in June.
Recovery outcomes varied significantly depending on attack type. Code-level exploits sometimes allowed teams to freeze funds or negotiate returns, whereas incidents involving stolen private keys typically resulted in funds flowing through mixers or cross-chain routes, making recovery unlikely.