Crypto Hacks Rose 50% but Losses Fell 60%: Inside the SlowMist H1 2026 Report

Crypto hacks 2026 look worse and better at the same time: SlowMist’s H1 report counted 182 publicly disclosed blockchain security incidents, up from 121 in H1 2025, while reported losses fell to about $956 million from roughly $2.37 billion. The answer is simple but uncomfortable. Attack volume rose, average payouts shrank, and social engineering, supply-chain compromise, and AI-assisted deception became the story.

Crypto hacks 2026: the SlowMist paradox in numbers

The headline figure from SlowMist’s 2026 Mid-year Blockchain Security and AML Report is not just “more hacks.” It’s the split between frequency and damage. Based on secondary coverage of the SlowMist report published in July 2026, incidents rose by about 50% year over year, while losses fell by roughly 60%.

Do the arithmetic and the change becomes clearer. In H1 2025, about $2.37 billion across 121 incidents works out to roughly $19.6 million per disclosed incident. In H1 2026, about $956 million across 182 incidents equals around $5.3 million per incident. That’s a 73% drop in average loss per incident, even before you adjust for recovered or frozen funds.

That average can mislead, because one large exploit can bend a half-year of statistics. SlowMist coverage identified Kelp DAO as the largest attack of H1 2026, with roughly $292 million in losses. Remove a giant outlier like that and the typical victim looks much smaller, but the operational pain remains real.

For anyone tracking why software security keeps falling behind development speed, this is the uncomfortable pattern: attackers don’t need every campaign to be spectacular. They need enough small wins, repeated often, against rushed code, tired maintainers, and distracted users.

How much crypto was stolen in 2026?

The most careful answer is: it depends which security firm’s methodology you use. SlowMist’s H1 2026 figure, as reported in July 2026 coverage, was about $956 million in losses from 182 publicly disclosed blockchain incidents. CertiK’s Hack3D H1 2026 report put the number higher, at $1,315,676,432 across 344 Web3 security incidents.

Those numbers are not necessarily contradictory. Firms classify incidents differently. Some include a broader set of phishing, wallet compromise, off-chain social engineering, or project-level security events. Others focus more tightly on publicly disclosed blockchain security incidents.

Source, H1 2026 Reported incidents Reported losses Notable category or note
SlowMist coverage, July 2026 182 About $956 million Incidents up from 121 in H1 2025; losses down from about $2.37 billion
CertiK Hack3D, July 2026 344 $1,315,676,432 Wallet compromise led losses at $444,531,691 across 33 incidents
CertiK adjusted figure, H1 2026 344 $1,200,364,925 $115,311,507 frozen or returned
SlowMist DeFi breakdown, H1 2026 116 $488.88 million DeFi had the largest number of incidents in its sector breakdown
SlowMist bridge breakdown, H1 2026 20 $346.34 million Fewer incidents, high loss concentration

A useful reader takeaway: don’t compare crypto hacks 2026 figures without checking what each firm counts. CertiK reported 204 code-vulnerability incidents, while SlowMist coverage said smart-contract and logic vulnerabilities made up 48% of its recorded incidents. Same broad problem. Different lens.

See also  Google Introduces Open Protocol for Streamlined AI Agent Transactions

Why losses fell while attacks rose

Smaller losses do not mean safer markets. They may mean attackers are spreading out, protocols are freezing funds faster, and some teams are getting better at incident response. SlowMist coverage said 18 incidents involving about $389 million saw partial or complete recovery or freezing, with about $118 million recovered or frozen, including $5.16 million assisted by SlowMist.

Bridges also show the odd economics of crypto hacks 2026. SlowMist’s reported bridge tally was 20 incidents and $346.34 million in losses. That’s roughly $17.3 million per bridge incident, compared with about $4.2 million per DeFi incident if you divide $488.88 million by 116 incidents. Fewer bridge attacks. Heavier hits.

My read: the easy narrative, “audits fixed DeFi,” is too generous. Attackers still find logic bugs, privileged-key failures, and integration mistakes. What has improved is the response muscle around monitoring, exchange alerts, stablecoin issuer freezes, public tracing, and emergency coordination.

There’s another pitfall people rarely mention. A lower dollar total can reflect asset prices, treasury composition, and attacker timing, not just better defense. If an exploit drains a token after liquidity thins or before a listing event, the headline loss may understate the damage to users who can no longer exit.

Where hackers hit: Ethereum, Solana, DeFi and bridges

Ethereum again appears prominently in the incident count. SlowMist coverage reported 44 Ethereum incidents in H1 2026, while CertiK, using a broader methodology, reported 153 Ethereum incidents. That gap says as much about classification as it does about Ethereum itself.

Solana looked different. Multiple sources identified it as having fewer incidents but outsized losses; CertiK reported $315,069,960 in Solana losses for H1 2026, and SlowMist coverage said Solana recorded the largest ecosystem losses in its breakdown. Fewer events can still hurt more when a single protocol, wallet flow, or liquidity venue becomes a rich target.

DeFi remained the busiest attack surface in SlowMist’s numbers, with 116 incidents and $488.88 million in reported losses. If you’re comparing protocol risk with market risk, articles on crypto futures exchanges in 2026 can help separate trading venue exposure from smart-contract exposure; they are not the same risk, even when the token ticker is identical.

Ethereum’s scale also matters. More users, more assets, more integrations, more copycat deployments. Readers following staking flows and validator behavior may also want the context around the Ethereum validator exit queue, because network-level participation and application-level risk often get wrongly blended in public debate.

How do hackers steal crypto now?

CertiK’s H1 2026 report is blunt: wallet compromise was the largest loss category, with $444,531,691 stolen across 33 incidents. Phishing came second at $366,312,027 across 63 incidents. Code vulnerabilities accounted for 204 incidents, which means they were frequent even when they did not always produce the largest dollar losses.

See also  Understanding the Historical Performance of ICOs

The attack menu has widened. SlowMist coverage said supply-chain attacks caused $297.8 million in losses in H1 2026. The Hacker News reported on April 29, 2026, that DPRK-linked campaigns used AI-inserted npm malware, fake firms, remote-access trojans, and fake job or coding-assessment lures against crypto targets.

By July 17, 2026, The Hacker News had reported another North Korea-linked campaign using fake coding tests and SVG steganography to deliver OtterCookie-aligned malware aimed at developers and crypto wallets. Security Alliance also reported on April 8, 2026, that SEAL attributed 164 blocked domains from Feb. 6 to Apr. 7, 2026, to UNC1069, also known as BlueNoroff, a DPRK-nexus actor focused on cryptocurrency and Web3.

  1. Wallet compromise: seed phrase theft, malicious signing prompts, clipboard malware, remote-access tools, or stolen private keys.
  2. Phishing: fake airdrops, fake support chats, spoofed dashboards, wallet-draining approval pages, and meeting-link traps.
  3. Code and logic flaws: reentrancy, oracle mistakes, access-control errors, accounting bugs, and upgrade mishaps.
  4. Supply-chain attacks: poisoned npm packages, compromised build systems, malicious dependencies, or hijacked developer accounts.
  5. Insider-style access: fake workers, stolen identities, contractor compromise, and social engineering against maintainers.

If you remember one defensive rule, make it this: the riskiest moment is often not the transaction you know is dangerous, but the routine approval you don’t examine. Honestly, hardware wallets only help if you read what you sign and segregate hot wallets from long-term funds.

AI made social engineering cheaper

AI did not magically create crypto hacks 2026. It lowered the cost of looking believable. CSIS said in 2026 that DPRK IT workers used AI for fake profiles, resumes, cover letters, social media manipulation, and deepfake interviews. SlowMist-related coverage also pointed to prompt injection, memory poisoning, excessive-permission risks, and AI-generated phishing.

That matters because Web3 is unusually exposed to informal trust. Developers hire through Discord, Telegram, X, GitHub, freelance boards, and direct messages. A fake recruiter with decent English, a plausible GitHub history, and a polished coding test no longer looks amateur by default.

Nisos reported on June 16, 2026, that a DPRK-linked employment-fraud cell submitted at least 166,893 job applications, took part in more than 21,645 interviews, and secured at least 76 job offers from U.S. companies between December 2024 and September 2025. Those figures are not all crypto-specific, but they show the industrial scale behind fake-worker operations.

Teams experimenting with autonomous tooling should read security claims with caution. A practical primer on AI crypto trading agents is useful here, because agents that can sign, trade, or call contracts create a new question: who can instruct the agent when the prompt is hostile?

How you should change your defenses

For protocols, the main lesson from crypto hacks 2026 is not “buy another audit” and relax. Audits help, but they don’t cover poisoned dependencies, fake hires, admin-key compromise, or a rushed upgrade pushed before a market event. Defense needs boring process.

See also  Unexpected Veterans Day Developments Shake Bitcoin and XRP Markets

Start with signing separation. Treasury wallets, deployment wallets, market-making wallets, and operator wallets should not live in the same browser profile or approval routine. Multisig policies should include human delay for high-value actions, and emergency pause rights should be tested before they’re needed.

Developers need a stricter rule for interviews and coding tests: never run unknown repositories on your main machine, never install packages outside a disposable environment, and never open “meeting” installers from recruiters. That sounds paranoid until you remember that DPRK-linked campaigns repeatedly used fake jobs, coding tests, malicious packages, and fake Zoom or Microsoft Teams lures in 2026 reporting.

Users need fewer wallets, not more dashboards. Keep a small hot wallet for experiments, a separate wallet for DeFi, and cold storage for assets you don’t plan to move. Revoke stale approvals after using new protocols, but don’t treat revocation tools as magic; a stolen seed phrase beats any approval hygiene.

One counter-argument deserves space. Some readers see the 60% loss decline and argue the industry is maturing. They’re partly right. Recovery, freezing, analytics, and public monitoring are better than they were in earlier cycles. But if incident count keeps rising, the cost shifts from headline losses to insurance pricing, developer burnout, user fear, and regulatory pressure, especially as crypto regulation remains politically uneven in markets such as the United States, where lawmakers have warned about lagging behind global rivals.

FAQ

How much was lost to crypto hacks in H1 2026?

SlowMist coverage reported about $956 million lost across 182 publicly disclosed blockchain security incidents in H1 2026. CertiK reported a higher $1,315,676,432 across 344 Web3 incidents because its methodology was broader.

Why did crypto hacks rise but losses fall in 2026?

Incident volume rose, but average losses fell sharply. Faster freezing and recovery, smaller targets, different attacker tactics, and fewer mega-loss events compared with H1 2025 all appear to have contributed.

Which blockchain had the most hacks in 2026?

Ethereum was reported as the ecosystem with the highest incident count in H1 2026. SlowMist coverage cited 44 Ethereum incidents, while CertiK reported 153 under its broader tracking method.

Are AI tools being used in crypto hacks?

Yes. 2026 reporting from CSIS, The Hacker News, and SlowMist-related coverage described AI use in fake profiles, job scams, deepfake interviews, phishing, malicious packages, and new risks around AI agents and permissions.

What is the safest way to protect a crypto wallet in 2026?

Use cold storage for long-term funds, keep a small hot wallet for experiments, verify every signature, avoid unknown coding-test repositories, and separate treasury or savings wallets from DeFi activity.

en_USEN