SlowMist aggregate data show a total of 158 publicly disclosed security incidents in the encryption industry in the first half of 2026, up from a high number during the same period. However, the total amount stolen was approximately $929 million, which is significantly lower than approximately $2.3 billion during the same period in 2025.
This means that attacks are still on the rise, but the scale of the losses in a single incident is less than last year. According to the report, hackers are increasingly turning to higher- and medium-sized attacks rather than concentrating on a small number of super-scale incidents.
The stolen money is concentrated in a few big cases.
The largest single incident in the first half of the year took place in Drift Protocol, at a loss of approximately $295 million, the highest number of encrypted attacks in the first half of the year. The report also mentions that the theft caused by the country ' s related hacker organizations amounted to approximately $643 million, or about 66 per cent of all stolen funds.
According to researchers, this data reflects a clear difference between common attackers and organized hacker groups with a national background, which tend to carry out larger attacks.
- Public disclosure of security incidents: 158
- Total losses for the first half of the year: approximately $929 million
- Related hacker share: around 66%
It's still the main target.
In terms of the distribution of chains, the ETA is the most heavily attacked block chain, with 56 incidents recorded during the first six months. Then BNB Chain, Base and Arbitrum. The report considers this to be related to the dominance of the Etherfel in the DeFi area and to the larger size of the chain-locked assets.
The highest number of attacks was recorded in May, at 41, in June and April, at 36 and 34 respectively. In terms of loss amounts, the month of April was the most severe, with thefts of approximately $631 million per month, or nearly 68 per cent of the total losses in the first half of the year.
Private key leaks and predictor-risk rises.
The report states that the smart contract loophole remains the most common entry point for attacks, but that the largest amount of the loss comes from the breaking of private key and administrator certificates, which account for approximately 40 per cent of the total loss. Cases included Drift Protocol, Humanity Protocol, Resolv, Wasabi Protocol, Gravity Bridge, Fluid, StablR and Polymark.
Except for private key leaks, prophecies remain a high-risk point for DeFi. The cases of Blend Pools V2, Aave V3, Sharwa Finance, Edel and Ploutos Money show that, in case of abnormal price data, the attackers may use it to transfer funds and remove liquidity. Even if the project had completed a security audit, it could have been damaged by the failure of the price source.
It is also mentioned that AI-driven encryption fraud is increasing. According to the previously published 2026 encrypted criminal report issued by Chainalysis, the profitability of such frauds is about 4.5 times greater than that of traditional frauds. The attackers are using the video and voice generated by AI to bypass the exchange identification, mislead customers or impersonate corporate executives to initiate large transfer orders.
Recovery of funds remains low
Only one of the larger attacks in the first half of the year resulted in the full recovery of stolen assets, while two other projects together frozen more than $74 million. It was reported that more than $620 million remained largely unrecoverable.
Long-term data show that since Bitcoin was born, the number of publicly disclosed block chain security incidents has reached 2172, with cumulative losses of over $37.880 billion. Reports indicate that the attack has been extended from early smart contractual loopholes to private keys, cross-chain bridges, centralized exchanges, wallets, governance mechanisms and third-party infrastructure.
