Crypto's Bloodiest Half-Year: 212 Exploits Stole $1.1B as AI-Powered Attacks Go Mainstream
Blockaid's H1 2026 report reveals 212 onchain exploits draining $1.1B from Web3 protocols. North Korea's Lazarus Group drove over $600M in losses, and AI prompt injection attacks are emerging as the next major threat vector. Here's what every builder needs to know.
The first half of 2026 has been the most active period for onchain security threats on record. Blockaid's H1 2026 Onchain Security Report reveals a staggering 212 verified high-threshold exploits that collectively drained $1.1 billion from Web3 protocols and users — a 3.4-fold increase in incident volume over all of 2025. While the total dollar figure trails H1 2025 due to the absence of a single multibillion-dollar mega-heist, the velocity and technical sophistication of attacks have never been higher.
By the Numbers: H1 2026 in Context
Blockaid verified 212 exploits across the six-month period, peaking in June with 57 separate incidents. Just four major breaches accounted for $707 million — 64% of all stolen funds. The two largest hits were KelpDAO ($292 million) and Drift Protocol ($285 million), both attributed to North Korea's Lazarus Group-linked "Trader Traitor" hacking cluster, which was responsible for approximately $609 million of total losses.
Perhaps the most troubling shift is where the attacks are landing. Operational security failures and private key theft caused 74% of losses, not smart contract bugs. Attackers are increasingly targeting the human layer — social engineering, RPC infrastructure poisoning, and administrative multisig compromises — rather than hunting for reentrancy bugs or flash loan vectors that traditional audits are designed to catch.
How the Biggest Heists Unfolded
The Drift Protocol breach illustrates the new playbook. Attackers spent weeks on a targeted social engineering campaign that ultimately gave them administrative multisig control over the Solana-based perpetual DEX. Once inside, they drained $285 million in under 12 minutes — no smart contract exploit required.
The KelpDAO attack took a different but equally human-centric route. Attackers socially engineered a LayerZero developer, then used that access to poison RPC infrastructure and forge cross-chain bridge attestations, making off with $292 million. Both cases underscore a sobering reality: the attack surface has expanded far beyond Solidity code.
Three New Threat Vectors Every Builder Should Watch
Blockaid's report identifies three attack categories that barely registered on security radars a year ago but now demand urgent attention:
1. EIP-7702 Wallet Delegation Exploits. Ethereum's EIP-7702, which enables EOAs to delegate execution to smart contract code in a single transaction, introduces powerful UX improvements — but also a new class of delegation-based attacks. Blockaid expects these to scale significantly in H2 2026 as adoption grows.
2. AI Prompt Injection Against Autonomous Agents. In May, an attacker used prompt injection to trick Bankr's AI agent into approving an unauthorized transaction, stealing $216,000. As autonomous trading agents and AI-powered DeFi bots proliferate, prompt injection is emerging as a genuinely novel onchain attack vector that traditional security models are not equipped to handle.
3. Off-Chain Bridge Infrastructure. Cross-chain bridges remain the single most targeted infrastructure category. Blockaid highlights that bridge validator sets, relayer networks, and off-chain attestation logic all sit outside the scope of standard smart contract audits — yet they control billions in locked value.
Recovery Rates and the Path to Better Defense
Recovery outcomes split sharply along the attack vector. Funds stolen via key compromises disappeared almost immediately into mixers or cross-chain bridges, with near-zero recovery. Protocol bugs, by contrast, occasionally allowed for partial or full recovery through swift white-hat coordination or contract pauses.
The report's practical takeaway for development teams is clear: expand your security perimeter beyond smart contract audits. Operational security — including multisig key management, RPC endpoint integrity, social engineering training for core contributors, and AI agent input sanitization — now represents the highest-leverage investment a team can make.
What to Expect in the Second Half of 2026
Blockaid warns that the pressure is unlikely to ease. Sanctioned nation-state actors continue to run sophisticated, well-funded social engineering campaigns. EIP-7702 adoption is accelerating, expanding the delegation attack surface. And the rapid rise of autonomous AI agents in DeFi creates an entirely new category of risk that the industry has barely begun to model.
For builders, the message is unambiguous: the era when a single smart contract audit constituted adequate security coverage is over. Teams shipping in 2026 need to think holistically — about their multisig configuration, their RPC provider dependencies, their team's social engineering resilience, and the input boundaries of any AI agents they deploy or interact with.
Building Safer: Where to Start
The Blockaid report is a wake-up call, not a reason to retreat. Web3 continues to ship faster and more ambitiously than any other sector in tech. The protocols that survive and thrive in this environment will be the ones that treat security as a continuous, whole-stack discipline rather than a one-time audit checkbox.
If you're building onchain — whether a DeFi protocol, an AI agent, or a consumer application — thirdweb provides the infrastructure to move fast without cutting corners. From audited smart contracts and secure account abstraction to built-in wallet security, thirdweb's developer platform handles the foundations so you can focus on what makes your product unique. If you're ready to build, thirdweb offers developer plans that scale with your project.