BTC
ETH
HTX
SOL
BNB
ดูตลาด
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Nearly 90% of stolen funds cannot be recovered: In the first half of 2026, Web3 attack targets are shifting from "code" to "people"

欧易OKX
特邀专栏作者
2026-07-28 02:43
บทความนี้มีประมาณ 8810 คำ การอ่านทั้งหมดใช้เวลาประมาณ 13 นาที
What most urgently needs patching in the first half of 2026 is not a specific contract, but people and processes themselves.
สรุปโดย AI
ขยาย
  • Core Viewpoint: In the first half of 2026, the number of security incidents in the crypto industry increased by 50% year-on-year, but total losses fell by 60% due to the absence of extreme outlier cases. The attack paradigm has systematically shifted from exploiting smart contract code to leveraging human trust, supply chains, and AI-generated environments, with only about 12% of stolen funds being recoverable.
  • Key Elements:
    1. There were 182 publicly reported security incidents in the first half of the year, with total losses of approximately $956 million. The number of incidents rose by about 50% year-on-year, but the total value decreased by about 60% year-on-year, mainly because the massive Bybit incident from last year (approximately $1.5 billion) did not recur.
    2. Attack targets have shifted from "code" to "people." None of the top losses were achieved by breaching contracts: Drift Protocol suffered losses of approximately $285 million through social engineering infiltration that induced signatures, and a Singapore AI video conference fraud resulted in losses of approximately S$4.9 million.
    3. By loss value, supply chain attacks (approximately $298 million) surpassed contract vulnerabilities (approximately $152 million) as the largest cause. Cross-chain bridges, despite only 20 incidents, caused approximately $346 million in losses, exhibiting a pattern of "decentralized events, concentrated losses."
    4. Attacks on AI Agents are evolving through four tiers, from the input layer to the supply chain layer. A typical case is the Bankr incident, where indirect prompt injection caused the Agent to recognize Morse code-encoded instructions as a trusted transaction, resulting in losses of approximately $175,000.
    5. Money laundering has become highly industrialized. Attackers, represented by Lazarus, form a complete chain using privacy protocols, cross-chain bridges, mixers, and theft-as-a-service tools. In the first half of the year, only 18 incidents saw recoveries totaling approximately $118 million, or 12.3% of total losses.
    6. Supply chain poisoning has evolved in three dimensions: breadth, depth, and height. For example, the Shai-Hulud worm published 637 malicious versions in 22 minutes, systematically stealing development pipeline permissions. In the LiteLLM incident, the security tool Trivy was compromised and became a link in the attack chain.
    7. "Trust" itself has become a new attack surface. OKX analyzed over 50,000 on-chain methods and managed signing risks, intercepting and protecting approximately $526 million cumulatively, while SlowMist, through built-in security execution gates and anti-money laundering screening, moved defense forward to before the action occurs.

In an era where AI-generated reality is possible, what needs to be verified is no longer a single piece of information, but the environment itself.

In the first half of 2026, the crypto industry witnessed 182 publicly reported security incidents, resulting in losses of approximately $956 million. More alarming than the total loss figure is the destination of the funds: according to SlowMist, only 18 incidents saw stolen funds recovered or frozen during this period, totaling about $118 million, representing just 12.3% of the total losses. Nearly 90% of the stolen funds are irretrievable.

Another statistic can be easily misinterpreted: The $956 million loss represents a nearly 60% decline year-over-year, but this does not mean the industry has become safer. The drop in losses is almost entirely attributable to the absence of a repeat of last year's single massive Bybit incident (approximately $1.5 billion); the number of incidents actually increased by roughly 50% year-on-year. Attacks haven't weakened, but have shifted their focus—from targeting protocol contracts to targeting people.

The two highest-loss attacks in the first half of the year did not succeed by breaching smart contracts: Drift Protocol was drained of approximately $285 million through a six-month-long social engineering infiltration campaign, starting with a few seemingly innocuous transactions signed by a single multisig signer; a victim in Singapore was lured into a video conference where government officials were all AI-generated, losing about S$4.9 million. The most expensive vulnerability was found in humans.

This is one of the core conclusions from the "2026 OKX Web3 Security Semi-Annual Report" jointly released by the OKX Web3 security team, SlowMist, and OtterSec, echoing the findings of the "2026 First Half Blockchain Security and Anti-Money Laundering Report" published concurrently by SlowMist. Although originating from an exchange and a security firm respectively, both reports point to the same conclusion: the frequency of attacks is increasing, tactics are evolving, and the target is shifting from "code" to "people."

Losses Down Nearly 60% YoY, But Attack Activity Rises Instead of Falls

The same set of data, when segmented with different metrics, can lead to contradictory conclusions. This is the prerequisite for understanding the security landscape of this half-year.

According to statistics cited in the OKX report from SlowMist's Hacked database, H1 2026 saw 182 incidents with losses of approximately $956 million; the same period in 2025 saw 121 incidents with losses of about $2.373 billion. Incident numbers rose by roughly 50% year-on-year, while the total amount fell by about 60% year-on-year. The primary reason for the decline in total losses is the Bybit incident in February 2025 (approximately $1.5 billion, where hackers compromised the computer of a Safe{Wallet} developer and tampered with the official website script), which was an extreme outlier. The OKX report's assessment is: excluding this anomaly, comparable losses for this year have actually increased.

The OKX report further dissects the data by attack cause using two metrics: by number of incidents, contract and logic vulnerabilities remain the primary cause, accounting for 85 incidents; but by loss amount, supply chain attacks top the list at approximately $298 million, followed by contract vulnerabilities (approx. $152 million) and private key leaks (approx. $130 million). SlowMist summarizes this characteristic in eight words: Incidents Dispersed, Losses Concentrated. Genuinely damaging large-scale losses are now concentrated in critical bottlenecks like infrastructure, cross-chain bridges, and supply chains. A telling footnote: cross-chain bridges were involved in only 20 incidents in the entire half-year, yet caused approximately $346 million in losses.

Funds are no longer primarily lost through contract vulnerabilities. The OKX report summarizes the changes this half-year into three main themes: Large losses are increasingly occurring outside of contracts; ordinary users are becoming primary targets; AI Agents are transitioning from tools to prey. Additionally, two threads run throughout: supply chain poisoning infiltrating development processes, and the downstream money laundering pathways where all stolen funds eventually converge. We will elaborate on each below.

For Projects: The Biggest Losses Occur Where Audits Don't Reach

Most of the projects suffering the heaviest losses in the first half of the year were not unaudited; their points of failure lay precisely outside the scope of standard audits: signing processes, cloud keys, validator nodes, and developer devices. An audit can prove a contract's logic is sound, but it cannot prove the security of these operational aspects.

KelpDAO: Not the Contract Was Breached, But the Verification Path. This was the largest single loss in H1. According to OtterSec's post-mortem, the attacker poisoned LayerZero's internal RPC nodes while launching a DDoS attack against honest external nodes. Cross-chain messages are supposed to be cross-verified by multiple independent nodes, but the bridge was configured with a "1-of-1" single validator node setup. The single verification point received only forged data, ultimately approving a withdrawal backed by no real assets, leading to the transfer of approximately 116,500 rsETH, of which about $75 million worth was subsequently frozen. A single validator node has long been considered a high-risk configuration, previously just a theoretical warning in architecture reviews. After the KelpDAO incident, it became a near $300 million concrete loss. SlowMist adds details on the stolen funds: LayerZero attributed the incident to the Lazarus sub-group TraderTraitor. The stolen tokens were then used as collateral on lending platforms like Aave to borrow approximately $236 million in real assets (WETH), briefly triggering a liquidity crisis in the DeFi market.

Drift: A Six-Month-Long Signature Inducement. Its mechanism warrants explanation: a durable nonce acts like a pre-signed transaction voucher that can be executed at any point in the future. The attacker, disguised as a quantitative trading firm and cultivating trust for six months with over $1 million in genuine deposits, induced a signer to pre-sign such management transactions. At the time of signing, the impact was indiscernible. When the project later adjusted the multisig threshold, creating a window lacking a timelock (a mechanism requiring a delay for sensitive operations to take effect), the attacker broadcast the pre-acquired signed transactions, executing 31 withdrawals in 12 minutes and draining over half the locked assets. The core lesson from this incident: a transaction that has "no impact" at the moment of signing doesn't guarantee it won't be executed later. Blind signing, pre-signing, and unparsed management transactions should all be considered high-risk operations.

A Gallery of Single Points of Failure. Resolv Labs had its AWS cloud keys stolen, which the attacker used to mint approximately 80 million unbacked tokens. Step Finance suffered a breach of an executive's device, where a private key was used to drain the treasury. Humanity Protocol saw a developer's device infected with malware, leading to a loss of control over a private key. SlowMist notes that on-chain analyst ZachXBT tracked the stolen funds from Step Finance and found them mixed with funds from the KelpDAO incident, essentially ruling out an inside job and again pointing towards Lazarus.

The SlowMist report also documents a set of more fundamental cases, probing down to the cryptographic engineering implementation level. The commonality among these three incidents is that the vulnerabilities were outside the routine coverage of standard code audits.

Taiko (June 22, ~$1.7 million): A signing private key was mistakenly committed to a public GitHub repository. The attacker used it to forge Layer 2 state proofs, tricking the system into releasing funds. The TAIKO token price dropped over 20% briefly.

SecondFi / formerly Yoroi (June 21–23, ~$2.4 million): The signature algorithm implementation was missing a necessary random blinding step, allowing the complete private key to be derived from a single on-chain signature. 374 addresses were drained. The flaw originated from a third-party component introduced two weeks prior without a security audit.

THORChain (May 15, ~$10.7 million): Treasury private keys were co-managed by multiple nodes via threshold signatures, designed so no single node possesses the full key. However, a malicious node gradually collected key shares over multiple rounds of normal signing, eventually reconstructing the complete private key.

From cross-chain verification and cloud keys to signature algorithms, these cases represent different manifestations of the same fundamental failure: If a single node in a critical path can independently decide the fate of funds, it becomes the attacker's primary target.

Based on this assessment, OKX's signature risk controls not only verify "whether the transaction was initiated by the user" but increasingly focus on helping users understand the consequences of a transaction before signing. Surrounding high-risk scenarios like durable nonces and account ownership changes, OKX intercepted or alerted on over 4 million related high-risk operations in H1, protecting funds totaling approximately $526 million. It has also parsed over 50,000 on-chain method signatures, translating unreadable calldata into plain English like "This transaction will change these assets and grant these permissions." It's important to note that such capabilities can only reduce, not eliminate, risk. Exchanges and wallet services themselves are the highest-value targets; the 2025 Bybit incident was caused by breaching a signing tool. No single entity can claim immunity.

User Side: Attacks Start at the Most Familiar Entry Points

As attacking protocols becomes more costly, attackers are turning to users. According to the OKX report, today's attack entry points are often the scenarios where users have the lowest guard: app stores, top search results, friend's accounts, conference software, and recruitment processes.

Malicious browser extensions employ a "locally benign, remotely poisoned" model: the extension itself contains no malicious logic, passing app store static reviews. The actual phishing page is delivered in real-time from a remote server, capable of changing its domain at will (SlowMist captured a similar extension impersonating TronLink in May). Once a user enters their seed phrase on such a page, control of their assets is lost.

Search ad poisoning is even closer to daily routine. The OKX report documents a case where a user, after purchasing a new computer, searched for a development tool. They clicked on a paid advertisement at the top of the search results and followed the on-page instructions to execute an "installation command" in their terminal. The command actually deployed a clipboard hijacking trojan. Later, when the user transferred approximately $20,000, the recipient address was automatically replaced. The insidious nature of this attack is that the victim performed only routine operations (searching for the official website, downloading the tool, copying/pasting a command).

Job interview scams follow a "reconnaissance, profiling, targeted strike" path: Posing as a technical interviewer, the attacker asks the candidate to share their screen and open their wallet to "confirm DeFi experience," but is actually recording their wallet addresses, holdings, and frequently used protocols. Subsequently, they forge airdrop pages for protocols the victim genuinely uses, delivering customized phishing messages. The OKX report records a case where a victim lost approximately $88,000 due to this method.

Two other new tactics are noteworthy. First, fake "2FA security verification": Attackers send an email purporting to be from a wallet provider, using a domain that differs from the official one by just a single character. Combined with a countdown timer to create urgency, they trick users into entering their seed phrase to "complete verification." Second is business process fraud: Using lures like "external audit" or "token vesting confirmation" to deliver malicious attachments (SlowMist analyzed one sample using a double extension to disguise a script as a document). Once opened, it masquerades as a system update to steal passwords, then requests permissions for the camera, screen recording, and keyboard logging. The ultimate target is often office terminals and cloud service credentials, not just personal wallets.

Regarding the former, both reports offer consistent, fundamental advice:

Any page requesting your seed phrase for "verification," "authentication," "recovery," or "upgrade" is a scam. Your seed phrase is not a verification code; it is the control of your assets themselves. No legitimate wallet will ever ask for your seed phrase via a web page.

Because many losses don't start with an on-chain transaction but originate from malicious apps or phishing sites, OKX has moved its defenses earlier to the device and access layer. Its security scanning assistant has performed over 200,000 risk checks, discovering over 60,000 high-risk applications. Against phishing sites and malicious DApps, it has intercepted over 7 million risky website visits, aiming to block threats before users enter their seed phrase or connect their wallet.

Before attackers even contact users, a significant portion of risk has already been embedded in an even earlier stage—the software supply chain.

Supply Chain: What's Poisoned Isn't the Software Package, But Trust Itself

The unique nature of supply chain poisoning: the victim makes no mistake; they simply install a dependency, update a version, or visit an official domain as usual. This is the chapter the SlowMist report addresses in greatest depth, with three representative cases illustrating the evolution of this attack vector in breadth, depth, and height.

Breadth: The Shai-Hulud Worm. Mid-May, a single account published 637 malicious versions across 317 package names within 22 minutes, impacting popular components like echarts-for-react (over 3.8 million monthly downloads) and size-sensor (over 4.2 million monthly downloads). The malicious packages triggered obfuscated payloads upon installation, systematically collecting AWS, GCP, and Azure cloud credentials, Kubernetes cluster keys, SSH private keys, and other sensitive information, encrypting and exfiltrating the data. It included a self-propagation module for worm-like spread and pre-installed persistence mechanisms targeting Claude Code and VS Code. Its target was no longer a single software package, but the permissions of the entire development pipeline.

Depth: Cascading Trust Chains. In March, the Python library LiteLLM, with 97 million monthly downloads, was attacked. The attacker didn't compromise the library directly. Instead, they first poisoned the Trivy security scanner, which LiteLLM's build process depended on, thereby stealing the release key and pushing a malicious version. Developers trusted LiteLLM, LiteLLM trusted Trivy, but Trivy was compromised. This turned a security tool, meant to provide protection, into a link in the attack chain. The poisoning of Apifox's official CDN, monitored by SlowMist in the same month, is a similar case. Attackers tampered with the official script, embedding malicious code with random timers that activated 30 minutes to 3 hours after installation, making it difficult for users to link the anomaly to a specific action. This illustrates that "official source" is no longer completely synonymous with "safe."

Height: The Attacker's "Attack Surface Mindset." In April, SlowMist CISO 23pds warned that the Lazarus sub-group HexagonalRodent was using high-paying remote positions as lures to trick developers into running backdoored code. According to the OKX report, this group heavily utilizes ChatGPT and Cursor to generate code and scripts, uses AI website builders to fake company pages and executive identities, and even uses AI to "self-check" its malicious code to evade detection. In just one quarter, they stole wallet data from over 2,700 developer systems. Concurrently, AI-generated code itself is creating new risk surfaces. The OKX report, citing OtterSec data, notes that Georgia Tech attributed 35 of the 74 CVEs in March to AI-generated code. A scan of approximately 1,400 "casually generated" applications found 2,038 critical vulnerabilities and over 400 exposed keys. "Functional" does not equate to "production-ready."

Other similar incidents include the sudden appearance of an anomalous version of node-ipc after 21 months of inactivity, and the TrapDoor operation coordinating poisoning across three major ecosystems. They all point to a single conclusion: The focus of defense used to be auditing code; now it must be auditing the source of trust. This is especially critical for the Agent ecosystem, where Agents actively read, install, and execute external plugins. Based on this, OKX has established admission review and periodic inspection mechanisms for its Agentic Wallet's plugin integration, covering code security, permission scope, and external dependencies, moving the judgment of "is this dependency trustworthy?" to before the plugin goes live.

AI: From Forging Single Content to Synthesizing Entire Environments

Connecting the points above reveals an implicit theme: there exists an inherent trust in "smarter systems." The next collective misjudgment currently forming is: Agents are more reliable than humans. This perception hasn't been corrected by enough incidents yet, but the cost is already apparent.

The Bankr incident in May is a case that barely resembles an "intrusion": the attacker didn't steal private keys, attack a contract, or hack a server. They simply asked Grok to translate Morse code. BankrBot was an AI Agent deployed on Platform X, capable of executing on-chain transactions based on natural language instructions. According to SlowMist's post-mortem, the attacker first airdropped a membership

กระเป๋าสตางค์
ความปลอดภัย
OKX
AI
ยินดีต้อนรับเข้าร่วมชุมชนทางการของ Odaily
กลุ่มสมาชิก
https://t.me/Odaily_News
กลุ่มสนทนา
https://t.me/Odaily_GoldenApe
บัญชีทางการ
https://twitter.com/OdailyChina
กลุ่มสนทนา
https://t.me/Odaily_CryptoPunk
ค้นหา
สารบัญบทความ
ดาวน์โหลดแอพ Odaily พลาเน็ตเดลี่
ให้คนบางกลุ่มเข้าใจ Web3.0 ก่อน
IOS
Android