Exploits targetting the DeFi ecosystems have repeatedly made it to the headlines so far this year, pushing multiple protocols into irreversable financial damages and market exits. Onchain security firm Blockaid said over 212 exploits hit the blockchain space in the first half of 2026 leading to over a billion dollars in losses.
Blockaid released its H1 2026 Onchain Security Report this week highlighting that operational security attacks have become as common as smart contract exploits in the DeFi space.
Understanding operational security attacks
In operational security attacks, the malicious actors usually compromise insider credentials, private keys, signer infrastructure, bridge infrastructure, and backend systems. Between January and June this year, attacks via these channels led to the drain of around $789 million, or 74 percent of the total funds stolen.
The attacks KelpDAO, Drift Protocol, and Humanity Protocol were all operational security incidents that pulled out $292 million, $285 million, and $32 million respectively from their ecosystems.
“The biggest crypto attacks are no longer just breaking code. They’re compromising the systems and access points that control it,” said Ido Ben-Natan, Co-Founder and CEO of Blockaid. “The largest incidents we analyzed this year began with compromised credentials, signer infrastructure, or operational controls.”
Analyzing the observation, Blockaid said, attackers are not going for a blockchain code exploitation. Instead, they have started targeting privileged access points used to authorize and execute transactions.
While crypto hacks caused less total financial loss in the first half of 2026, Blockaid said, the number of individual attacks surged to 212 — clocking a three-times rise compared to the total of all of 2025 attacks.
Heists from North Korea spike
The crypto ecosystem, that presently stands on the valuation of $2.2 trillion, has been infested with North Koran hackers. The Lazarus Group is particularly infamous for hitting crypto and DeFi sectors with attacks and stealing billions. The group has been responsible for for major attacks like ByBit’s recent $1.5 billion exploit and WazirX’s $235 million hack from 2024.
Blockaid said, even this year so far, threat actors linked to North Korea accounted for approximately 55 percent of all exploit losses. The compromise of KelpDAO, Humanity Protocol, as well as Drift Protocol have all been linked to North Korean hackers according to the report.
“The findings highlight how a small number of sophisticated threat actors can drive a significant share of industry-wide losses by targeting operational weaknesses, rather than relying solely on vulnerabilities in deployed code,” the report noted.
Need for faster detection systems
Blockaid said existing and upcoming DeFi protocols have to bring faster threat detection systems to their systems. Stronger controls across the systems that manage blockchain transactions and secure credentials as well as signer infrastructure is the need of the hour.
Source: Blockaid
With global AI access now arming hackers with more advanced techniques, tightening existing security measures and upgrading the threat flagging systems should also deploy high-level AI elements.
“The data shows that while mega-exploits continue to drive headlines, attackers are also targeting a broader range of protocols, applications, and infrastructure components,” the p;latform noted.




