Loading prices…
STKR NewsSTKR News0 of 3 free this month
Solana News

Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says

New data from Blockaid shows crypto exploit losses topped $1 billion in the first half of 2026, with Ethereum and Solana ecosystems bearing the brunt of the damage.

Originally on The Block
AB

Adrian Boysel

Contributor

Jul 28, 2026

4 min read

Photo illustration / STKR News

We have a problem in the founder community. Every time a new bull cycle starts to breathe, we act like the security lessons of the last four years never happened. We spend months building elegant code, only to leave the back door unlocked for the first sophisticated drainer that walks by.

The latest mid-year data from security firm Blockaid is a sobering gut check. In the first half of 2026, crypto hacks reached a record high. We aren't just talking about a slight uptick; total losses crossed the $1 billion mark. For those of us keeping score, that is a massive step backward for an industry trying to prove it is ready for prime time.

The Distribution of Disaster

If you are building on Ethereum or Solana, you are currently standing in the line of fire. The numbers show that these two ecosystems were hit the hardest, accounting for the lion's share of the liquidations. Ethereum projects saw about $332 million vanish, while Solana was right behind at $326 million.

It is easy to blame the chains, but that is a lazy take. The reason these ecosystems are getting hit isn't because the underlying L1 is broken; it is because that is where the users are. Hackers are rational economic actors. They go where the liquidity is highest and the users are the most distracted. During this first half of 2026, the volume of new retail participants on Solana meant a target-rich environment for social engineering and drainers.

Why This Hits Different in 2026

In previous cycles, we saw massive protocol-level exploits—smart contract bugs that drained hundreds of millions in one shot. Those still happen, but the current trend is more insidious. We are seeing a massive rise in sophisticated phishing and front-end attacks. It turns out it is much easier to trick a user into signing a malicious transaction than it is to find a zero-day in a battle-tested vault contract.

For founders, this should be a wake-up call. You can have a perfectly audited smart contract, but if your DNS is hijacked or your Discord moderator gets sim-swapped, your users still lose everything. Security is no longer just about the code; it is about the entire operational surface area of your company.

The Cost of Speed

As a founder, I get the pressure to ship. The market moves fast, and if you aren't first to market with a new primitive, you feel like you've already lost. But the $1 billion lost in six months proves that shipping fast without a security-first culture is just an expensive way to fail.

We are seeing the return of the "move fast and break things" mentality, but in crypto, what you break is people's life savings. When a project gets exploited, it doesn't just hurt that specific team. It creates a cumulative drag on the entire industry. Every headline about a $300 million hack is another reason for a regular person to stay away from on-chain finance.

The Technical Shift

Blockaid’s report highlights that the sophistication of these attacks is maturing alongside our tech. We are seeing drainers that can bypass common wallet warnings and even simulate transactions to make them look legitimate to the user. This is an arms race, and right now, the attackers have better tooling than the defenders.

If you are building a dApp right now, you need to be thinking about security at the interface level. How are you communicating risk to your users? Are you using multi-sig for every critical infrastructure piece? Are you monitoring your front-end for unauthorized changes in real-time? If the answer is no, you are essentially part of the problem.

What Builders Should Take Away

This isn't meant to be a doom-and-gloom post, but we need to stop sugarcoating the state of the industry. Having $1 billion stolen in six months is an embarrassment. It suggests that despite all our talk about decentralized security, we are still incredibly vulnerable to basic human error and operational lapses.

  • Audit your operations, not just your code. Your social media accounts, your domain registrar, and your team's personal security are all part of your tech stack.
  • User education is a failed strategy. You cannot expect the average user to read hexadecimal transaction data. Your UI needs to protect them from themselves.
  • Slow down. The cost of a three-week delay for a secondary security review is nothing compared to the cost of a permanent loss of reputation and capital.

The market might be back, but our credibility is still on thin ice. If we hit $2 billion in losses by the end of the year, we have no one to blame but ourselves. We have the tools to build safely; we just keep choosing not to use them because they get in the way of the hype cycle.

If you’re a founder, look at these numbers and ask yourself if your project could survive a $20 million drain tomorrow morning. If the answer makes you sweat, it’s time to stop building features and start building defenses.


Read the original at The Block →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses