Crypto Lost Over $1 Billion to Hacks in Six Months

More than $1 billion gone in six months, across more separate incidents than the whole of last year. The pattern behind the number matters more than the number.

Share
Crypto lost over $1 billion to exploits in the first half of 2026, per Blockaid

Key takeaways

  • Crypto projects lost over $1 billion to exploits in the first half of 2026, according to security firm Blockaid.
  • Blockaid verified more individual exploit incidents in those six months than in all of 2025 combined.
  • The shift is toward more frequent, smaller attacks rather than a handful of headline megahacks.
  • Recent infrastructure incidents, including the BTCPay Server exploit that drained merchant Lightning nodes, fit the same pattern.
  • Most of this risk sits in platforms and infrastructure, not in the act of holding your own keys.

A billion dollars in six months is a big number, but the more useful detail is underneath it: security firm Blockaid says it verified more separate exploit incidents in the first half of 2026 than in all of 2025. The industry is not being robbed less often at larger size. It is being robbed more often, in more places.

What the data says

  • Over $1 billion lost to exploits across H1 2026, per Blockaid's report as covered by Investing News Network.
  • More individual incidents in six months than in the entirety of 2025, which points to breadth rather than a few outliers.
  • Infrastructure is squarely in scope: BTCPay Server issued an emergency alert on August 7 after attackers actively exploited a flaw and drained Lightning nodes belonging to merchants, per CoinDesk.

Why the shape of the losses matters

A single $600 million bridge hack is a story about one broken bridge. Hundreds of separate incidents totalling a billion is a story about an attack surface. Every additional protocol, front end, self-hosted payment server and browser extension in your workflow is another door, and attackers are systematically walking down the corridor trying all of them. The tooling to find these flaws has simply gotten better and cheaper than the tooling most teams use to prevent them.

The honest read

Two things are true at once. Crypto infrastructure is getting attacked more often, and the base layers themselves, Bitcoin and Ethereum and their major chains, were not what broke in these incidents. What broke was the software around them: bridges, contracts, servers, integrations. That distinction matters when you are deciding where to keep money, because it tells you the risk is concentrated in intermediaries and add-ons.

What actually reduces your exposure

  • Keep less money sitting on platforms you do not control. Custodial balances are somebody else's attack surface with your name on it.
  • Update self-hosted payment software immediately when a maintainer issues a security alert, as BTCPay users were told to do.
  • Limit approvals and revoke old ones. Many drains are not exotic; they exploit a permission you granted months ago and forgot.
  • Treat any unexpected wallet prompt as hostile until proven otherwise, especially after a public exploit when copycats appear.

The structural answer is uncomfortable but simple: fewer intermediaries between you and your money. That is the design principle behind Fizen, where your USDT stays in a self-custody wallet and spends directly by Visa card and QR, rather than sitting in a company's pooled account waiting for that company's worst day.

Frequently asked questions

How much crypto was stolen in 2026?

Security firm Blockaid reports more than $1 billion lost to exploits in the first half of 2026 alone, across more individual incidents than were recorded in all of 2025.

Are crypto hacks getting worse?

By frequency, yes. The notable change in 2026 is the number of separate incidents rather than the size of any single one, which suggests a wider attack surface being probed systematically.

What is usually hacked, the blockchain or the apps?

Almost always the software around the chain: bridges, smart contracts, front ends, self-hosted servers and integrations. Major base layers themselves are rarely the point of failure.

How do I protect my crypto from exploits?

Hold your own keys, keep minimal balances on custodial platforms, patch self-hosted software as soon as alerts land, revoke stale token approvals, and treat unexpected signature requests as hostile.

Fewer middlemen, less to steal

Fizen keeps your USDT in self-custody and spends it by Visa card and QR across 150+ countries. Backed by an investment from Tether.

Download the app

This is news coverage, not financial advice. Fizen is a self-custody app, backed by an investment from Tether.