Blockaid Report: Ethereum and Solana Dominate First Half 2026 Crypto Breach Losses
According to Blockaid's latest findings, Ethereum continued to experience the most significant blockchain-related losses throughout the first half of 2026, with Solana emerging as the network suffering the second-highest theft totals, overtaking Arbitrum primarily due to widespread key compromise incidents.

The cryptocurrency sector witnessed over $1 billion in stolen assets during the initial six months of 2026, marking a record-breaking period for the total number of security breaches within any half-year timeframe, data from onchain security platform Blockaid reveals.
The Ethereum and Solana blockchain networks experienced the most substantial financial damage from security incidents impacting their ecosystems, suffering approximately $332 million and $326 million in pilfered assets, respectively, as detailed in Blockaid's first-half 2026 security analysis released on Tuesday.
Throughout this timeframe, Blockaid documented a total of 212 security breach events, with KelpDAO representing the single largest exploitation incident at $292 million in losses, while the security platform confirmed detecting 3.4 times the volume of high-threshold exploitations in H1 2026 compared to the entirety of 2025.
Protocol code vulnerabilities were the primary catalyst behind Ethereum-related incidents, whereas compromised private keys and authentication signing systems represented the predominant attack vector for Solana network losses, the analysis indicates.
Ethereum losses reflected the risks of high-value protocols
Throughout the first half of 2026, Ethereum sustained the greatest financial damage from security incidents, with malicious actors concentrating their efforts on exploiting weaknesses within decentralized applications deployed on the platform.
According to Blockaid's findings, code-based exploitations represented the most frequent incident type affecting Ethereum by total count, though significant financial losses were also attributed to private key compromises impacting Humanity Protocol and StablR. The Ethereum-based decentralized trading platform CoWSwap stood as the sole major Ethereum-related incident documented in the analysis that was categorized as user error.
The security platform highlighted multiple recurring attack methodologies employed against Ethereum infrastructure, encompassing vulnerabilities within cross-chain bridges and smart contract logic, illegitimate access gained to accounts holding elevated permissions, and various forms of market price manipulation strategies.
According to the analysis, Ethereum continues to attract substantial attacker attention due to its role as the primary host for numerous high-value cryptocurrency applications across the ecosystem, including liquid restaking protocols, algorithmic and fiat-backed stablecoins, and permissionless decentralized trading venues.
Solana losses surged as attackers shifted focus
During the first six months of 2026, Solana experienced nearly equivalent financial losses to Ethereum, representing a dramatic escalation from the approximately $127 million in stolen cryptocurrency the blockchain network documented throughout the full year of 2025.
2025 had $2.58 billion lost across 63 incidents, concentrated in Q1 by Bybit's $1.5 billion, with Ethereum and Arbitrum the top chains by stolen-fund flow
Blockaid CEO Ido Ben-Natan told Cointelegraph
This dramatic shift in attack patterns was not the result of increased smart contract vulnerability exploitation. Rather, private key and credential compromises were responsible for over 98% of total Solana network losses, with the majority of stolen funds traced to security incidents affecting Drift Protocol and Step Finance, both of which Blockaid associated with North Korea-linked cybercriminal organizations.
In contrast to the Ethereum ecosystem, where threat actors predominantly focused on identifying and exploiting flaws in underlying protocol code implementations, security incidents on Solana primarily compromised transaction signing infrastructure and organizational-level security controls, with only a limited number of code-based exploitation events involving the Raydium and Volo protocols representing the balance of documented losses.