Blockaid: 212 On-Chain Exploits Steal $1.1B as AI Attacks Accelerate

Onchain security incidents surged to a record in the first half of 2026, according to blockchain security firm Blockaid, which verified 212 high-threshold exploits — a 3.4-fold increase over all of 2025. Blockaid estimates total losses reached roughly $1.1 billion, with North Korea–linked actors responsible for about $600 million.

Key Findings

  • Record activity: 212 verified high-threshold onchain exploits in H1 2026, the most active period on record.
  • Year-over-year escalation: Exploits were 3.4 times higher than the total recorded in 2025.
  • Losses concentrate: Estimated $1.1 billion stolen in the period.
  • State-linked impact: Approximately $600 million attributed to North Korea–linked hacking operations, according to Blockaid.

North Korea–Linked Activity

Blockaid’s analysis indicates that North Korea–linked groups accounted for more than half of the stolen funds in H1 2026. These operations have historically targeted decentralized finance (DeFi) protocols, bridges, and token swap infrastructure, exploiting smart contract vulnerabilities and compromising private keys or developer infrastructure to siphon funds across multiple chains.

AI and Wallet-Targeted Attacks Accelerate

Beyond protocol exploits, Blockaid observed rapid growth in wallet-focused attacks. These typically rely on malicious transaction approvals, deceptive signature requests, and phishing that leads users to expose seed phrases or grant dangerous permissions. The firm notes that attackers are increasingly using AI-driven tooling and social engineering to scale operations, improve lures, and tailor attacks to specific communities and projects.

Why It Matters

The spike in confirmed exploits and losses underscores the widening attack surface across DeFi and user wallets. It also highlights the need for stronger pre-transaction checks, permission transparency, and domain-level threat filtering within wallets and dapps. As attackers incorporate automation and AI, security vendors and ecosystem teams are prioritizing real-time detection, transaction simulation, and stricter key management practices to reduce successful thefts.

×