Hack frequency hit a record in the first half of 2026 even as total losses declined, with Ethereum and Solana accounting for the bulk of stolen funds.
Ethereum suffered roughly $332 million in losses from security incidents in the first half of 2026, the most of any blockchain, while Solana recorded about $326 million — nearly matching Ethereum after posting just $127 million in losses for all of 2025, according to onchain security platform Blockaid's H1 2026 report published Tuesday.
"2025 had $2.58 billion lost across 63 incidents, concentrated in Q1 by Bybit's $1.5 billion, with Ethereum and Arbitrum the top chains by stolen-fund flow," Blockaid CEO Ido Ben-Natan told Cointelegraph.
Blockaid tracked 212 security incidents in the period, with the largest single exploit hitting KelpDAO at $292 million. The platform verified 3.4 times as many high-threshold exploits in H1 2026 as across all of 2025. TRM Labs recorded 207 hacks in the same period, more than double the 83 logged a year earlier, though total losses fell to roughly $972 million from about $2.3 billion — indicating more frequent but smaller individual breaches.
The divergence between Ethereum and Solana's attack surfaces underscores a structural shift in crypto security threats. On Ethereum, attackers primarily exploited vulnerabilities in protocol code — bugs in bridges and smart contracts, unauthorized access to privileged accounts and market manipulation techniques. Ethereum remains a major target because it hosts many of the industry's most valuable applications, including restaking platforms, stablecoins and decentralized exchanges, Blockaid said.
Solana's losses, by contrast, did not stem from a rise in smart contract exploits. Compromised keys accounted for more than 98% of Solana's stolen funds, driven largely by incidents involving Drift Protocol and Step Finance, which Blockaid linked to North Korea-linked cyber groups. Unlike Ethereum, where attackers targeted protocol code, Solana incidents focused on signer infrastructure and organizational security, with a handful of code exploits involving Raydium and Volo accounting for the remaining losses.
The trend continued into late July. On July 26, WEMIX disclosed a contract compromise that led to 5,225,525 unauthorized WEMIX$ minted and converted into 30,736 WEMIX and 724,198.27 USDC.e, which moved through bridges to Ethereum and BSC before reaching centralized exchanges. WEMIX suspended its WEMIX3.0 network, Chainlink CCIP and the PLAY Bridge. Separately, Garden Finance took its app offline after Blockaid flagged about $450,000 in USDT drained across Ethereum, Base, Arbitrum and BSC. Lookonchain counted three additional attacks last week totaling $35.55 million, hitting AFX Trade, the Verus Ethereum bridge and B2 Network.
The shift toward more frequent, smaller attacks — and the growing reliance on key compromises over code exploits — raises the stakes for security infrastructure across both Ethereum and Solana ecosystems. With North Korea-linked groups increasingly targeting Solana's signer infrastructure and Ethereum's high-value protocols remaining prime targets, the cost of inadequate key management and organizational security is rising faster than the industry's ability to patch code.
This article is for informational purposes only and does not constitute investment advice.