The cryptocurrency industry lost more than $1 billion to hacks and security breaches during the first half of 2026, marking the highest number of hacking incidents ever recorded in a six-month period, according to a new report from blockchain security firm Blockaid.
The report identified 212 security incidents between January and June, with Ethereum and Solana emerging as the two most targeted blockchain networks.
Ethereum Suffers Highest Financial Losses

Ethereum recorded the largest losses, with attackers stealing approximately $332 million from projects built on the network.
According to Blockaid, the majority of Ethereum-related attacks resulted from smart contract vulnerabilities and code exploits, with hackers targeting high-value decentralized finance (DeFi) applications, bridges, stablecoin platforms and restaking protocols.
Some of the biggest Ethereum incidents involved KelpDAO, which suffered a $292 million exploit, along with major security breaches affecting Humanity Protocol and StablR through compromised access credentials.
The report noted that CoWSwap was the only major Ethereum incident caused primarily by user error rather than weaknesses in protocol infrastructure.
Blockaid also identified several common attack methods on Ethereum, including vulnerable smart contracts, bridge exploits, unauthorized access to privileged accounts and market manipulation techniques.
Solana Sees Sharp Rise in Security Losses
Solana ranked second in total losses, with approximately $326 million stolen during the first six months of 2026.
The figure represents a significant increase from the roughly $127 million lost across the network throughout all of 2025, highlighting a major shift in attacker activity.
Unlike Ethereum, where software vulnerabilities remained the primary attack vector, more than 98% of Solana’s losses were attributed to compromised private keys and signing infrastructure rather than flaws in smart contract code.
Blockaid linked several of the largest Solana breaches, including incidents involving Drift Protocol and Step Finance, to cyber groups associated with North Korea.
Only a small portion of Solana’s losses resulted from traditional code exploits, including attacks affecting Raydium and Volo.
Attack Patterns Continue to Evolve
Blockaid CEO Ido Ben-Natan said the threat landscape has shifted considerably from 2025.
While last year’s losses were heavily influenced by a handful of massive exploits, including the $1.5 billion Bybit hack, attackers in 2026 have increasingly focused on compromising organisational infrastructure, access credentials and signing systems alongside exploiting vulnerable protocol code.
The company also reported verifying 3.4 times more major security incidents during the first half of 2026 than it identified throughout all of 2025, underscoring the growing sophistication and frequency of attacks targeting the digital asset industry.
Security Remains a Growing Challenge

The report highlights the continued evolution of cyber threats facing the crypto ecosystem.
While Ethereum remains the primary target because of its concentration of high-value decentralised applications, Solana has become an increasingly attractive target for attackers seeking to compromise operational security rather than exploit smart contract vulnerabilities.
As institutional adoption and on-chain activity continue to expand, Blockaid warned that strengthening wallet security, signing infrastructure and protocol auditing will remain critical to reducing losses across the blockchain industry.
