Crypto losses surpassed $1 billion in the first six months of 2026, marking the highest number of hacks recorded in any single half-year period, according to onchain security platform Blockaid’s H1 2026 security report published Tuesday.
Ethereum led all networks with approximately $332 million in stolen funds, while Solana came in second with roughly $326 million, displacing Arbitrum from its prior ranking. Blockaid tracked 212 separate security incidents across the period, with the single largest exploit targeting KelpDAO at $292 million. The platform also noted it verified 3.4 times as many high-threshold exploits in H1 2026 as it did across the entirety of 2025.
Ethereum: Code Exploits Dominated
Ethereum attracted the heaviest losses because it hosts the crypto industry’s most valuable applications, including restaking platforms, stablecoins, and decentralized exchanges. Blockaid identified code exploits as the dominant attack method by incident count on Ethereum, with additional losses tied to key compromises at Humanity Protocol and StablR. The only major Ethereum incident classified as a user mistake involved CoWSwap, an Ethereum-based decentralized exchange.
Common attack vectors on Ethereum included:
- Bugs in bridges and smart contracts
- Unauthorized access to privileged accounts
- Market manipulation techniques
Solana: Compromised Keys Drove Nearly All Losses
Solana’s losses in H1 2026 represented a sharp escalation from the roughly $127 million in stolen funds the network suffered across all of 2025. Unlike Ethereum, where attackers primarily targeted protocol code, Solana incidents focused on signer infrastructure and organizational security.
Compromised private keys accounted for more than 98 percent of Solana’s total losses during the period, driven largely by incidents involving Drift Protocol and Step Finance. Blockaid linked both incidents to North Korea-connected cyber groups. A smaller portion of Solana losses stemmed from code exploits at Raydium and Volo.
A Shift From 2025 Patterns
Blockaid CEO Ido Ben-Natan said the prior year presented a different picture: ‘2025 had $2.58 billion lost across 63 incidents, concentrated in Q1 by Bybit’s $1.5 billion, with Ethereum and Arbitrum the top chains by stolen-fund flow.’
The transition from Arbitrum to Solana as the second-most targeted network reflects attackers pivoting toward weaker operational security at Solana-based protocols rather than seeking out smart contract flaws. The pattern suggests that key management and signing infrastructure are now primary targets alongside traditional code vulnerabilities.


