212 on-chain exploits stole $1.1B in H1 2026, Blockaid reports
Blockaid verified 212 on-chain exploits in H1 2026 that stole $1.1 billion and warned EIP-7702 wallet delegation and AI prompt-injection attacks will rise in H2.
Security firm Blockaid reported 212 verified on-chain exploits in the first half of 2026 that together resulted in $1.1 billion in losses. The firm said the number of high-threshold exploits was 3.4 times higher than all of 2025, making the period the most active six months on record. Incidents peaked in June with 57 exploits recorded.
Four large breaches accounted for $707 million, about 64% of the total funds taken. Blockaid attributed roughly $609 million of the losses to activity by the Trader Traitor cluster, linked to the Lazarus Group and associated with North Korean state-sponsored operations.
Two of the largest incidents were the restaking protocol KelpDAO, which lost $292 million, and the Solana perpetual DEX Drift Protocol, which lost $285 million. Both breaches targeted human and operational weaknesses rather than exploiting smart-contract code. In the Drift incident, weeks of targeted social engineering reportedly gave attackers administrative multisig control and allowed them to drain $285 million in under 12 minutes. The KelpDAO breach involved social engineering of a LayerZero developer, which compromised RPC infrastructure and enabled forged cross-chain bridge attestations.
Blockaid found that operational security failures and key theft accounted for about 74% of losses. High-value funds often moved quickly into coin mixers and across cross-chain bridges after theft, limiting recovery options.
The report highlighted three security areas outside the scope of traditional audits: wallet delegation under EIP-7702, AI prompt-injection, and off-chain bridge infrastructure. To illustrate AI risk, the report cited a May incident in which an attacker used prompt injection to trick an autonomous AI agent at Bankr into approving an unauthorized transaction that took $216,000.
Recovery outcomes varied by attack type. Funds taken through key compromise were frequently lost permanently. Some protocol bugs allowed partial or full recovery after rapid responses by white-hat teams or pauses to contract functions. The report noted that coordinated responses and built-in circuit breakers can enable asset recovery when vulnerabilities are in code rather than in user accounts.
Looking ahead, Blockaid expects continued state-sponsored social engineering campaigns, an increase in exploits that leverage EIP-7702 wallet delegation as more wallets adopt delegation features, and a rise in prompt-injection attacks against autonomous AI trading agents as decentralized finance tools add AI-driven automation. Security teams and protocol maintainers were advised to expand threat models to include off-chain systems and human vectors in addition to traditional smart-contract audits.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








