Skip to main content

Ethereum and Solana Drive Most Crypto Hack Losses in H1 2026, Blockaid



Crypto security firm Blockaid reports that losses from hacks and other onchain security incidents exceeded $1 billion in the first half of 2026, marking the highest number of security incidents in a six-month period tracked by the platform.


In Blockaid’s H1 2026 security report published Tuesday, Ethereum and Solana led the network-level loss tally, with stolen funds of roughly $332 million and $326 million, respectively.



Key takeaways



  • Over $1B lost: Blockaid recorded total crypto losses above $1 billion across H1 2026.

  • 212 security incidents: The period included 212 incidents, with more high-threshold exploits verified in H1 2026 than in all of 2025.

  • Ethereum dominated by code exploits: The report attributes most Ethereum losses to application and smart-contract vulnerabilities.

  • Solana losses driven by key compromises: More than 98% of Solana’s losses stemmed from compromised keys rather than contract bugs.

  • Biggest single exploit was KelpDAO: Blockaid identified the largest incident as KelpDAO’s exploit at $292 million.



H1 2026: incident volume climbed, and major exploits shaped outcomes


Blockaid’s report covers 212 security incidents from the first six months of 2026. While the number of incidents rose, the distribution of losses was also shaped by a small set of very large events.


The largest single exploit Blockaid highlighted came from KelpDAO, which it linked to losses of $292 million. Blockaid also reported that it verified 3.4 times as many high-threshold exploits in H1 2026 compared with all of 2025, suggesting a higher frequency of severe, high-impact events rather than only a few outliers.


At the network level, Ethereum and Solana were responsible for nearly all of the most significant stolen-funds figures in the report. Blockaid attributes these differences not only to what applications exist on each chain, but also to how attackers executed their operations.



Why Ethereum losses reflected risk in high-value protocols


According to Blockaid, Ethereum saw the largest losses in H1 2026, driven primarily by incidents that stemmed from code exploits—meaning vulnerabilities in applications, smart contracts, or components interacting with them.


Blockaid said Ethereum’s highest-loss events included key compromises involving Humanity Protocol and StablR. In addition, CoWSwap was identified in the report as the only major Ethereum incident classified as a user mistake, rather than an exploit of protocol code.


Looking beyond individual cases, Blockaid outlined recurring Ethereum attack methods that included weaknesses in bridges and smart contracts, unauthorized access to privileged accounts, and market manipulation techniques. The report frames Ethereum as a persistent target partly because it hosts many of the sector’s highest-value building blocks—restaking platforms, stablecoins, and decentralized exchanges.


For investors and operators, the implication is straightforward: as long as the chain continues to concentrate high-value protocols and liquidity, attackers can profit from both direct smart contract vulnerabilities and operational failures (such as privileged account access) that turn code risk into real-world theft.



Solana’s surge: fewer contract bugs, more key and signer compromises


Solana’s H1 2026 losses came in at roughly $326 million, nearly matching Ethereum. Blockaid describes this as a substantial increase versus about $127 million in stolen funds during 2025.


Notably, Blockaid says the increase was not mainly caused by a rise in smart contract exploits. Instead, the report points to compromised keys as the dominant driver: more than 98% of Solana’s losses in the period were tied to key compromises.


Blockaid connected a large portion of those losses to incidents involving Drift Protocol and Step Finance, which the report linked to North Korea-linked cyber groups.


Blockaid also described a different profile for Solana attackers compared with Ethereum. Where Ethereum’s losses were largely associated with vulnerabilities in protocol code, Solana incidents were centered on signer infrastructure and organizational security controls. In Blockaid’s accounting, only a small portion of Solana losses came from code exploits—citing Raydium and Volo as examples of the remaining code-related cases.


For teams building on or around Solana, this is a clear operational reminder: security reviews can’t stop at smart-contract audits. The report’s emphasis on keys, signing infrastructure, and broader security posture suggests that threat models need to treat custody, signing workflows, and privileged access as first-class attack surfaces.



What to watch next: exploit severity, not just incident counts


As Blockaid’s data shows, H1 2026 combined higher incident volume with a significant jump in verified high-threshold exploits. Readers should watch whether future quarters keep the same balance—especially whether Solana’s key-compromise trend persists and whether Ethereum’s code and privileged-access attack patterns accelerate as new high-value applications launch.



https://www.cryptobreaking.com/ethereum-and-solana-drive-most/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Ethereum%20and%20Solana%20Drive%20Most%20Crypto%20Hack%20Losses%20in%20H1%202026,%20Blockaid%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Solana Policy Institute Calls on SEC to Safeguard DeFi Developers from Overly Strict Regulations

US Crypto Policy Innovation: Advocates Push for Clear Regulations and Developer Protections The Solana Policy Institute has urged the U.S. Securities and Exchange Commission (SEC) to differentiate between centralized crypto exchanges and non-custodial decentralized finance (DeFi) software. The nonprofit emphasizes that developers creating and publishing non-custodial code should not be classified as intermediaries, advocating for balanced regulation that fosters innovation without compromising security or legality. Key Takeaways Advocates call for regulatory clarity distinguishing between non-custodial DeFi protocols and centralized exchanges. The Institute argues that applying traditional securities laws to DeFi code risks stifling innovation and pushing activity offshore. Authorities are encouraged to adopt a custody-and-control-based framework to clarify legal liabilities. Legislation proposals aim to shield developers from legal liabilities associated with blockchain code and activ...