Nearly 90% of Stolen Funds Cannot Be Recovered: Web3 Attacks in the First Half of 2026 Shift Targets from "Code" to "People"
- Core Insight: In the first half of 2026, the number of security incidents in the crypto industry increased by 50% year-over-year, but the total value lost dropped by 60% due to the absence of a single extreme case. The attack paradigm has systematically shifted from exploiting smart contract code to exploiting human trust, supply chains, and AI-generated environments, with only about 12% of stolen funds recoverable.
- Key Elements:
- A total of 182 publicly reported security incidents occurred in the first half of the year, causing approximately $956 million in total losses. While the number of incidents rose ~50% year-over-year, the total amount lost fell ~60%, mainly because no incident approached the scale of last year's Bybit hack (~$1.5 billion).
- Attack targets have shifted from "code" to "people"; the top losses were not achieved through contract exploits: The Drift Protocol incident involved a social engineering infiltration leading to a signed transaction, resulting in losses of ~$285 million. A Singapore-based AI video conference scam caused losses of ~4.9 million Singapore dollars.
- By loss amount, supply chain attacks (~$298 million) surpassed contract vulnerabilities (~$152 million) as the leading cause. Despite only 20 bridge-related incidents, they caused ~$346 million in losses, demonstrating a pattern of "decentralized events, concentrated losses."
- Attacks targeting AI Agents have evolved through four stages, from the input layer to the supply chain layer. A typical case is the Bankr incident, where an indirect prompt injection caused the Agent to interpret Morse code-encoded commands as legitimate transactions, leading to a loss of ~$175,000.
- Money laundering has become highly industrialized. Attackers, notably groups like Lazarus, form a complete chain using privacy protocols, cross-chain bridges, mixers, and stolen-crypto-as-a-service tools. In the first half of the year, funds were recovered from only 18 incidents, totaling ~$118 million, or 12.3% of the total losses.
- Supply chain poisoning has evolved in breadth, depth, and height. For example, the Shai-Hulud worm published 637 malicious versions within 22 minutes to systematically steal development pipeline privileges. In the LiteLLM incident, the security tool Trivy was itself compromised and became a link in the attack chain.
- "Trust" itself has become a new attack surface. OKX, by analyzing over 50,000 on-chain methods and managing signing risks, has cumulatively protected approximately $526 million. SlowMist, through built-in security execution gates and anti-money laundering screening, has moved defense to before the action occurs.

In an era where AI-generated reality becomes possible, what needs to be verified is no longer a single piece of information, but the environment itself.
In the first half of 2026, the crypto industry recorded 182 public security incidents, resulting in losses of approximately $956 million. More alarming than the total loss is the destination of the funds: according to SlowMist, funds were recovered or frozen in only 18 incidents, totaling approximately $118 million, representing 12.3% of the total losses. Nearly 90% of the stolen funds are irretrievable.
Another figure is easily misinterpreted: the $956 million loss represents a nearly 60% decrease year-on-year, but this does not mean the industry has become safer. The drop in losses is almost entirely due to the fact that last year's single massive Bybit incident (approximately $1.5 billion) did not repeat; the number of incidents actually increased by about 50% year-on-year. Attacks have not diminished but shifted direction—from targeting protocol contracts to targeting people.
The two highest-loss attacks in the first half of the year did not succeed by breaching smart contracts: Drift Protocol was infiltrated by a six-month social engineering campaign, draining approximately $285 million, starting with a few "seemingly harmless" transactions signed by a multi-signatory. A victim in Singapore was invited to a video conference where government officials were all AI-generated, losing approximately 4.9 million SGD. The most expensive vulnerability appeared in humans.
This is one of the core conclusions of the "2026 OKX Web3 Security Semi-Annual Report" jointly released by the OKX Web3 security team, SlowMist, and OtterSec, sharing common ground with the "2026 H1 Blockchain Security and Anti-Money Laundering Report" published simultaneously by SlowMist. Although originating from an exchange and a security company, both reports point to the same assessment: the frequency of attacks is rising, the methods are evolving, and the target is shifting from "code" to "people."
Losses Down Nearly 60% YoY, But Attack Activity Rises Instead of Falls
The same set of data, sliced by different metrics, can lead to opposite conclusions. This is the prerequisite for understanding the security landscape of this half-year.
According to OKX's report, citing SlowMist's hacked database, the first half of the year saw 182 incidents with losses of approximately $956 million; the same period in 2025 recorded 121 incidents with losses of approximately $2.373 billion. The number of incidents increased by about 50% year-on-year, while the total loss amount decreased by about 60%. The main reason for the drop in losses is that the February 2025 Bybit incident (approximately $1.5 billion, where hackers compromised the computer of a Safe{Wallet} developer and tampered with the official website script) was an extreme outlier. OKX's report assesses that excluding this anomaly, comparable losses for this year have actually increased.
The OKX report further analyzed the causes of attacks using a dual perspective: by number of incidents, contract and logic vulnerabilities remain the top cause, accounting for 85 incidents; but by loss amount, supply chain attacks topped the list at approximately $298 million, followed by contract vulnerabilities (approximately $152 million) and private key leaks (approximately $130 million). SlowMist summarizes this characteristic in eight words: Incidents are fragmented, losses are concentrated. Truly devastating large losses are now concentrated in critical links such as infrastructure, cross-chain bridges, and supply chains. A stark illustration: cross-chain bridges experienced only 20 incidents throughout the half-year, but caused approximately $346 million in losses.
Funds are no longer primarily lost through contract vulnerabilities. The OKX report summarizes the changes in this half-year into three main threads: Large losses increasingly occur outside of contracts; ordinary users become primary targets; AI Agents transform from tools into prey. Additionally, two threads run throughout: supply chain poisoning infiltrating development stages, and the downstream money laundering process where all stolen funds eventually converge. The following elaborates on each.
For Projects: The Biggest Losses Occur Where Audits Don't Reach
Most projects suffering the heaviest losses in the first half of the year were not unaudited; the points of failure lay precisely outside the scope of audits: signing processes, cloud keys, validator nodes, developer devices. Audits can prove the logic of a contract is sound, but they cannot prove the security of these operational links.

KelpDAO: Not the Contract Was Breached, But the Verification Path. This was the largest single loss in the first half of the year. According to OtterSec's post-mortem, the attacker polluted LayerZero's internal RPC nodes while launching a DDoS attack against honest external nodes. Cross-chain messages should be cross-verified by multiple independent nodes, but the bridge at the time used a "1-of-1" single verifier node configuration. The single verification point received only forged data, ultimately approving a withdrawal backed by no real assets. Approximately 116,500 rsETH were transferred out, with about $75 million later frozen. A single verifier node has long been considered a high-risk configuration, previously just a theoretical warning in architectural reviews. After the KelpDAO incident, it became a real-world loss approaching $300 million. SlowMist added details on the stolen funds: LayerZero attributed the incident to the Lazarus sub-group TraderTraitor. The stolen tokens were subsequently used as collateral on lending platforms like Aave to borrow approximately $236 million in real assets (WETH), even triggering a liquidity crisis in the DeFi market.
Drift: A Six-Month Signature Induction Campaign. Its mechanism is worth explaining: a durable nonce acts like a pre-signed transaction voucher that can be executed at any point in the future. The attacker, disguised as a quant institution, cultivated trust for six months with over $1 million in real deposits, inducing signatories to pre-sign such management transactions. The signatures showed no effect at the time; when the project later adjusted the multi-sig threshold, creating a window lacking a timelock (a delay for sensitive operations to take effect after public disclosure), the attacker broadcast the pre-signed transactions, completing 31 withdrawals in 12 minutes, draining over half of the locked assets. The core lesson from this incident: a transaction that has "no effect" at the moment of signing does not mean it cannot be executed later; blind signing, pre-signing, and unparsed management transactions should all be treated as high-risk operations.
A Gallery of Single Points of Failure. Resolv Labs' AWS cloud keys were stolen, allowing the attacker to mint approximately 80 million unpegged tokens. Step Finance's executive device was compromised, and private keys were used to empty the treasury. Humanity Protocol's developer device was infected with malware, leading to loss of private key control. SlowMist noted that on-chain analyst ZachXBT traced the stolen funds and found them being mixed with funds from the KelpDAO incident, largely ruling out an inside job and pointing again to Lazarus.
The SlowMist report also recorded a set of more fundamental cases, probing attacks down to the level of cryptographic engineering implementation. The commonality among these three incidents is that the vulnerabilities were all outside the typical scope of code audits.
• Taiko (June 22, ~$1.7 million): A signing private key was mistakenly committed to a public GitHub repository. The attacker used it to forge Layer 2 state proofs, tricking the system into releasing funds. The TAIKO token dropped over 20% briefly.
• SecondFi / formerly Yoroi (June 21-23, ~$2.4 million): The signature algorithm implementation was missing a necessary random masking step. This allowed a single on-chain signature to reveal the complete private key, leading to the draining of 374 addresses. The flaw originated from an unaudited third-party component introduced only two weeks before the incident.
• THORChain (May 15, ~$10.7 million): The vault's private key was co-managed by multiple nodes (threshold signature scheme), designed so that no single node possesses the complete key. However, a malicious node gradually collected key fragments over multiple rounds of legitimate signing processes, eventually reconstructing the full private key.
From cross-chain verification and cloud keys to signature algorithms, these cases represent different forms of the same failure: As long as a critical path has a single node that can independently determine the destination of funds, it becomes the attacker's primary target.
Based on this judgment, OKX's signature risk control not only verifies "whether the transaction was initiated by the user" but also focuses on helping users understand the consequences of a transaction before signing. Around high-risk scenarios like durable nonces and account ownership changes, OKX intercepted or alerted on over 4 million related high-risk operations in the first half of the year, protecting funds totaling approximately $526 million. It has also parsed over 50,000 on-chain methods, translating unreadable calldata into understandable statements like "which assets will be moved, what permissions will be granted." It's important to note that such capabilities can only reduce, not eliminate, risk. Exchanges and wallet service providers themselves are the highest value targets; the 2025 Bybit incident was caused by breaching a signing tool, and no party can claim immunity.
User Side: Attacks Start at the Most Familiar Entry Points
As the cost of attacking protocols rises, attackers turn to users. According to the OKX report, attack entry points today are often the scenarios where users have the least vigilance: app stores, top search results, friend accounts, conferencing software, recruitment processes.
• Malicious Browser Extensions use a "local shell, cloud poison" model: the extension itself doesn't contain malicious logic, passing app store static reviews; the actual phishing page is delivered in real-time from a remote server, capable of changing domains frequently (SlowMist caught a similar extension imitating TronLink in May). Once users enter their seed phrases on such pages, control of their assets is lost.
• Search Ad Poisoning is more closely related to daily operations. A case documented in the OKX report involved a user who, after buying a new computer, searched for a development tool and clicked a paid ad at the top of the search results. Following the page's prompts, they executed an "installation command" in the terminal, which actually deployed clipboard hijacking malware. Later, when the user transferred approximately $20,000, the receiving address was automatically swapped. The insidiousness of such attacks lies in the victim performing only routine operations like "searching for an official website, downloading a tool, copying a command."
• Recruitment Interview Scams follow a "reconnaissance, profiling, targeted attack" path: attackers, under the guise of a technical interview, ask candidates to share their screen and open their wallet to "confirm DeFi experience," actually recording wallet addresses, holdings, and commonly used protocols. They then create fake airdrop pages and deliver customized phishing messages targeting protocols the victim actually uses. In one case documented in the OKX report, the victim lost approximately $88,000 due to this method.
Two other new techniques are noteworthy. First, fake "2FA Security Verification": attackers send emails in the name of wallet providers, using a spoofed domain only one character off from the official one, creating urgency with timers to trick users into entering their seed phrases for "verification." Second, business process fraud: attackers use lures like "external audits" or "token vesting confirmation" to deliver malicious attachments (SlowMist analyzed a sample using a double extension to disguise a script as a document). Opening it triggers malware that disguises itself as a system update to steal passwords, then requests camera, screen recording, and keyboard listening permissions. The ultimate target is often office terminals and cloud service credentials, not personal wallets.
Regarding the former, both reports give a consistent, fundamental warning:
Any page requesting your seed phrase for verification, authentication, recovery, or upgrade is a scam. Your seed phrase is not a verification code; it is the control of your assets. No legitimate wallet will ever ask for your seed phrase via a webpage.
Since many losses don't start with on-chain transactions but earlier with malicious apps or phishing sites, OKX has moved protection forward to the device and access point. Its security scan assistant has performed over 200,000 risk detections, discovering over 60,000 high-risk applications. For phishing websites and malicious DApps, it has blocked over 7 million risk site visits, aiming to intercept users before they enter seed phrases or connect their wallets.
Before attackers even contact users, a significant portion of the risk has already been embedded in upstream links—the software supply chain.
Supply Chain: What's Being Poisoned Isn't Just a Software Package, But Trust Itself
The unique nature of supply chain poisoning is that the victim makes no mistake; they merely installed a dependency, updated a version, or visited an official domain as usual. This is the chapter SlowMist's report focuses on most heavily, with three representative cases illustrating the evolution of such attacks in breadth, depth, and height.
• Breadth: The Shai-Hulud Worm. In mid-May, an account published 637 malicious versions covering 317 package names within 22 minutes, affecting popular components like echarts-for-react (over 3.8 million monthly downloads) and size-sensor (over 4.2 million monthly downloads). The malicious packages triggered obfuscated payloads during installation, systematically collecting various sensitive information like AWS, GCP, Azure cloud credentials, Kubernetes cluster keys, and SSH private keys, encrypting them, and exfiltrating them. It also built-in self-propagation modules for worm-like spread and pre-installed persistence mechanisms targeting Claude Code and VS Code. The target was no longer a single software package but the credentials of the entire development pipeline.
• Depth: Cascading Trust Chain. In March, the Python library LiteLLM, with 97 million monthly downloads, was attacked. The attacker didn't directly compromise the library but first poisoned Trivy, a security scanning tool its build process depended on, using it to steal publishing keys and push malicious versions. Developers trusted LiteLLM, LiteLLM trusted Trivy, and Trivy was compromised. This turned a tool meant for defense into a link in the attack chain. The Apifox official CDN poisoning detected by SlowMist in the same month falls into the same category: attackers tampered with official scripts, embedding malicious code with random timers that activated between 30 minutes to 3 hours after installation, making it hard for users to link the anomaly to a specific action. This shows that "official source" is no longer fully synonymous with "safe."
• Height: The Attacker's "Attack Surface Mindset." SlowMist's Chief Information Security Officer, 23pds, warned in April: Lazarus sub-group HexagonalRodent lured developers with high-paying remote jobs, getting them to run backdoored code. According to the OKX report, this group heavily uses ChatGPT and Cursor to generate code and scripts, uses AI website building tools to create fake company websites and executive identities, and even uses AI to "self-check" its malicious code to avoid detection. In just one quarter, they stole wallet data from over 2,700 developer systems. Simultaneously, AI-generated code itself is creating new risk surfaces. Citing OtterSec data, the OKX report notes: Georgia Tech attributed 35 of the 74 CVEs in March to AI-generated code. A scan of approximately 1,400 "quickly generated" applications found 2,038 critical vulnerabilities and over 400 exposed keys. "Functionality works" does not equate to "ready for production."
Other similar incidents include the sudden appearance of an anomalous version of node-ipc after 21 months of inactivity, and the TrapDoor campaign poisoning across three major ecosystems simultaneously. They all point to a common conclusion: the past focus was on auditing code; now, one must audit the source of trust. This is particularly critical for the Agent ecosystem, as Agents actively read, install, and execute external plugins. Based on this, OKX has established an admission review and regular inspection mechanism for Agentic Wallet plugin integration, covering code security, permission scope, and external dependencies, moving the judgment of "whether a dependency is trustworthy" forward to before the plugin goes live.
AI: From Fabricating Single Content to Synthesizing the Entire Environment
Tying the previous content together, a hidden thread emerges: the outside world has an inherent trust in "smarter systems." The next collective misjudgment forming is: Agents are more reliable than humans. This notion hasn't been corrected by enough incidents yet, but the cost is already evident.
The May Bankr incident is a case that hardly seems like an "intrusion": the attacker didn't steal private keys, didn't attack contracts, didn't hack servers, just asked Grok to translate Morse code. BankrBot is an AI Agent deployed on X platform that can automatically execute on-chain transactions based on natural language commands. According to SlowMist's post-mortem, the attacker first airdropped a membership NFT to an associated wallet, triggering its high-permission mode, then sent a Morse code message asking Grok to translate it. After Grok decoded it, it @BankrBot, outputting the hidden transfer instruction (


