Crypto

Crypto Hacks Just Had Their Worst Six Months Ever. The Next Target Might Not Even Be Human.

4 min read

Blockchain security firm Blockaid’s mid-year report on 2026 lands on a genuinely stark number: 212 verified exploits and roughly $1.1 billion in stolen funds across the crypto industry in the first six months of 2026 alone — the highest half-year total the firm has ever recorded. Q2 2026 on its own was the worst single quarter ever measured, with 83 separate incidents. Two attacks — against the liquid restaking protocol KelpDAO and the Solana-based trading platform Drift — accounted for more than $573 million of that quarter’s total by themselves, and both have been attributed to North Korean state-linked hacking groups.

That North Korean attribution isn’t an isolated data point in this report; it’s close to the whole story. Separate reporting drawing on the same underlying research puts North Korea’s share of total H1 2026 crypto theft at more than $600 million — roughly two-thirds of everything stolen industry-wide in the period. This is now a familiar pattern for anyone following crypto security over the past few years: state-sponsored North Korean operations, widely understood to fund the country’s weapons programs, aren’t opportunistic outliers anymore. They’re the single largest, most consistent source of loss in the entire industry, outpacing every independent criminal group combined.

The New Line in the Report: AI Agents Are Now a Named Target

The detail in Blockaid’s report that stands out from prior years’ security roundups is a new category entirely: AI agents — autonomous or semi-autonomous software given wallet access or trading authority to act on a user’s behalf — are now being explicitly flagged as an emerging attack surface, not a theoretical one. As crypto platforms and DeFi protocols increasingly let AI agents execute trades, manage yield strategies, or hold and move funds with reduced human oversight, that autonomy is exactly what makes them attractive targets: a compromised AI agent with wallet permissions can potentially be manipulated into authorizing transfers a human operator would have caught and stopped. Blockaid’s report treats this as a genuinely new risk category worth naming specifically, not folding into the general phishing or smart-contract-exploit buckets that have dominated past reports.

The Exploits Themselves Keep Getting More Sophisticated, Not Less

What makes the KelpDAO and Drift incidents worth understanding beyond their dollar figures is what they represent about attacker patience. Both were carried out by groups with the resources and discipline to study a protocol’s actual mechanics closely enough to find a genuine structural weakness, rather than relying on a phishing link or a leaked private key — the crude, high-volume attacks that once dominated crypto theft statistics are increasingly a smaller share of total losses relative to this kind of deep, targeted protocol-level exploitation. That shift matters for anyone building in this space: the security bar for a DeFi protocol handling real user funds isn’t “avoid the obvious phishing risks” anymore, it’s genuine, adversarial-minded smart contract auditing against attackers with nation-state-level time and resources.

Why This Report Matters Beyond the Headline Number

A billion-dollar half-year loss figure is the kind of statistic that’s easy to read as background noise — crypto hacks have been a recurring headline for years, and the scale can numb rather than inform. What this specific report adds is a genuine shift in where the risk is concentrated: fewer, larger, state-sponsored attacks against increasingly sophisticated targets, and a brand-new, named risk category — AI-agent compromise — that barely existed as a line item in last year’s security reporting. Both trends point the same direction: the attackers at the top end of this threat landscape are well-resourced, patient, and actively adapting to wherever crypto infrastructure is adding new forms of automated authority.

What This Means for Philippine Founders

For any Philippine startup building in DeFi, Web3 infrastructure, or crypto-adjacent fintech, this report is a direct argument for treating security spend as core product cost, not an optional line item to add once you have real traction — the protocols getting hit hardest in 2026 aren’t unaudited side projects, they’re established platforms with real user funds and, presumably, real security processes that still weren’t enough against a sufficiently resourced, patient attacker. The AI-agent finding deserves particular attention given how much of the current Philippine and regional startup conversation is about integrating AI agents into products, including financial ones — any founder giving an AI agent wallet access, trading authority, or the ability to move user funds autonomously should treat that specific integration as a new, first-class security surface requiring its own audit and limits, not an extension of whatever access controls already exist for human users. The two-thirds-North-Korea statistic is also a reminder that the biggest threat to a crypto product with real value locked in it is rarely a random opportunist — it’s patient, well-funded, state-level actors who will spend months studying a protocol before ever touching it.

AI agents Blockaid Crypto Security DeFi Hacks North Korea

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.