One signature. One compromised laptop. One overworked engineer with too much access. That is what took down more crypto value in six months than almost any exploit chain ever devised — and it is why the industry’s latest security reckoning should worry builders more than any zero-day.
Blockaid’s newly published H1 2026 security report puts a number on the damage: 212 verified onchain incidents between January and June, totalling $1.1 billion in losses. That is 3.4 times the number of incidents logged across the whole of 2025, and the highest first-half tally the firm has recorded. The headline figure is bad. The breakdown is worse, because it shows the industry’s biggest vulnerability is no longer exotic code — it is who holds the keys.
The privileged-key problem
Of the $1.1 billion lost, $790 million — nearly three-quarters — traces back to privileged-key misuse rather than smart contract bugs, oracle manipulation or bridge exploits. In practice, that means compromised admin credentials, multisig signers tricked into approving malicious transactions, or insiders and infrastructure with more control than any single point of failure should ever hold.
This matters because it is not a problem code audits solve. A protocol can pass every formal verification going and still fall the moment someone with privileged access is deceived, coerced or simply careless. Blockaid’s data suggests that is now happening at industrial scale.

The average loss per incident sits at $5.4 million, but that figure hides an extraordinarily lopsided distribution. Two incidents alone — the KelpDAO exploit in April, at $292 million, and the Drift Protocol hack seventeen days later, at $285 million — accounted for roughly $577 million between them. That is more than half of every dollar lost across the entire half-year, concentrated into a fortnight-and-a-half window. As Blockaid’s report puts it: “Drift ($285M) and KelpDAO ($292M) occurred 17 days apart, and together they accounted for roughly $577M, more than half of all H1 dollar losses.”
Lazarus, still the biggest single actor
North Korea’s Lazarus Group, operating through its TraderTraitor tooling, is tied to roughly 55% of total H1 losses — around $609 million. That is not a new trend; Lazarus has topped attribution tables for several years running. What has changed is scale and method. Rather than relying purely on novel exploit code, DPRK-linked operators increasingly target the humans and processes around a protocol: social engineering signers, compromising employee devices, and exploiting exactly the kind of privileged-access gaps that Blockaid’s cause-of-loss breakdown highlights.
That convergence — a well-resourced, patient state actor hunting for privileged-key weaknesses rather than contract bugs — is arguably the more important story than the dollar total itself. Smaller, less sophisticated projects such as Resolv ($80 million) and CoW Swap ($50.4 million) also appear among the year’s notable incidents, a reminder that this is not a problem confined to the largest protocols.

Why audits alone won’t fix this
The uncomfortable implication for the industry is that the standard security playbook — audits, bug bounties, formal verification — addresses a shrinking share of the actual threat surface. Those tools are built to catch flaws in code, not flaws in who controls the code’s execution.
Protocols serious about closing the privileged-key gap will need to look at multisig threshold design, hardware-backed signing, time-locked upgrades, and rigorous operational security for anyone holding admin or upgrade keys — treating key-holders themselves as the attack surface, not just an afterthought around it. Several teams have already begun shifting toward decentralised or time-delayed key management following high-profile incidents, though Blockaid’s figures suggest adoption remains patchy at best.
None of this diminishes the raw scale of what happened in the first half of 2026. A record number of incidents, well over a billion dollars lost, and a state-sponsored actor responsible for more than half the total is a serious indictment of the sector’s operational security. But the more durable lesson is about where the next dollar of protection needs to go. Code is being audited more rigorously than ever. The people and processes holding the keys to that code are, by comparison, still dangerously under-defended.
For an industry that has spent years hardening smart contracts against reentrancy bugs, flash-loan manipulation and oracle attacks, the H1 2026 numbers are a reminder that attackers go where the defences are thinnest. Right now, that is not the contract layer. It is the small number of people and devices that can move hundreds of millions of dollars with a single signature — and until that changes, reports like Blockaid’s are likely to keep getting bigger, not smaller.










