207 Hacks, $972 Million Gone: Crypto’s Record First Half for Attack Volume

A new industry report tracking on-chain security incidents puts a hard number on something the crypto industry has quietly known for a while: attacks are becoming more frequent even as any single attack has gotten less likely to be catastrophic. The first half of 2026 recorded 207 separate hacking incidents against crypto platforms and protocols, the highest figure ever documented in a single six-month window, according to blockchain intelligence firm TRM Labs.
The headline numbers, by themselves, tell a story worth sitting with:
- 207 incidents in H1 2026 — more than double the number recorded in the same period a year earlier, and a record for any six-month stretch on file
- $972 million stolen in total, down roughly 57% from the approximately $2.3 billion lost in H1 2025
- 125 of the 207 incidents — well over half — were smart contract exploits, making it the single most common attack vector by count
- ~$643 million, or about 66% of everything stolen, has been attributed to North Korea-linked threat actors, primarily the Lazarus Group and its TraderTraitor subgroup
- $285 million was drained from Drift Protocol, a Solana-based derivatives exchange, in a single April exploit
- ~$292 million was taken from KelpDAO, a cross-chain liquid restaking protocol, in a separate April incident tied to the same threat cluster
- ~$219,000 was the median loss per incident, underscoring just how many of the 207 attacks were small, opportunistic hits rather than headline-grabbing breaches
The gap between those two top-line figures — a record number of attacks against a sharply lower total dollar loss — is the real finding here. It suggests the center of gravity in crypto hacking has shifted from occasional nine- and ten-figure catastrophes toward a much higher volume of smaller, more automated exploits, many of them targeting smart contract logic rather than custodial infrastructure. Smart contract exploits alone accounted for the majority of incidents by count, even though they contributed a comparatively modest share of total dollars lost, meaning attackers are increasingly running high volumes of smaller-scale extractions rather than betting everything on one large breach.
The two outsized exceptions prove that rule rather than break it. Drift Protocol and KelpDAO together accounted for well over half of all funds stolen industry-wide in the first half of the year, and both have been linked to the same North Korea-affiliated cluster that TRM Labs credits with roughly two-thirds of total losses across the period. State-sponsored actors, in other words, are still the ones capable of pulling off the nine-figure heists; everyone else appears to be working a much higher volume, lower-yield playbook.
For an industry that likes to point to falling total losses as evidence that security is improving, a record incident count is a useful reality check. More platforms getting hit more often, even for smaller amounts each time, still adds up to a security problem that isn’t going away — it’s just changing shape.
Crypto assets carry significant security and volatility risk, and none of the above should be taken as financial advice. For a grounding in wallet security and custody basics, see coin680’s Bitcoin Academy.
