Crypto Breaches Surpass $1 Billion in H1 2026 as Attack Vectors Split Between Ethereum and Solana
A record 212 security incidents saw Ethereum protocols plagued by code exploits while Solana lost over $300 million to private key compromises.
Frequency of security breaches across the digital asset sector hit an all-time high in the first six months of 2026, pushing total illicit drains beyond $1 billion across 212 distinct incidents, according to new research from onchain security firm Blockaid.
The surge reflects a notable structural shift in crypto security, with malicious actors employing starkly different tactics depending on the underlying blockchain architecture. While Ethereum application layers suffered primarily from complex logic flaws and smart contract exploits, Solana ecosystems were severely impacted by infrastructure breaches and credential theft.
Stolen funds were overwhelmingly concentrated on the two major smart contract networks. Ethereum recorded $332 million in losses, closely followed by Solana at $326 million. The single largest incident of the half-year took place on liquid restaking platform KelpDAO, which lost $292 million in an exploit.
Blockaid verified 3.4 times as many high-threshold exploits during H1 2026 as it did throughout all of 2025, pointing to an increasing scale of capital flight during successful intrusions.
Ethereum remained a prime target due to its vast collection of high-value applications, including liquid restaking protocols, cross-chain bridges, and decentralized finance primitives. Smart contract exploits and execution bugs dominated the network’s incident count. Other notable Ethereum breaches involved key compromise at Humanity Protocol and StablR, while decentralized exchange CoWSwap suffered losses classified as user operational error rather than a protocol flaw.
In contrast, Solana experienced a massive spike in losses compared to 2025, when total drained capital on the network stood at approximately $127 million. However, code vulnerabilities played a minimal role in Solana’s security breakdown.
Compromised credentials and key compromise accounted for more than 98% of all funds stolen from Solana, led by major key management breaches at Drift Protocol and Step Finance. Blockaid attributed much of this activity to cyber syndicates linked to North Korea, which frequently utilize spear-phishing, developer machine compromise, and stolen signing keys rather than auditing smart contract code for execution flaws. Isolated protocol exploits on Solana were limited to smaller incidents at Raydium and Volo.
The threat dynamics diverge from 2025, when total annual losses reached $2.58 billion across 63 incidents. That year’s figures were largely driven by a single $1.5 billion exploit of exchange Bybit in the first quarter, with stolen asset flows primarily routed through Ethereum and Arbitrum, according to Blockaid Chief Executive Officer Ido Ben-Natan, citing broader research also monitored by cybersecurity and infrastructure security agencies.








