← H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges1 decision on this page
Audit log
Every state-changing event for H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-29 17:20:58ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
pDkaBPfLVLzg…wg9A4RbFsha256 → base58
verifying row…canonical bytes (36931 B) ▸
{"actor":"system:backfill","investigation_id":"684bbcae-ea55-4172-b244-30907016bf98","kind":"publish","page_slug":"h1-2026-crypto-hack-landscape-ai-agent-attack-vector-emerges","published_at":"2026-07-29T17:20:58.607Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges","sections":[{"content":"Four major security firms published H1 2026 retrospectives with overlapping but non-identical findings. Blockaid counted 212 verified exploits and $1.1 billion in total losses, describing this as the highest first-half incident count on record and noting that 3.4 times as many high-threshold exploits occurred in H1 2026 as in all of 2025. TRM Labs counted 207 incidents and $972 million in losses, noting a 58% decline from the $2.3 billion recorded in H1 2025; TRM attributed North Korea-linked actors with $643 million, or approximately 66% of its total. CertiK's Hack3D report tracked 344 incidents (a broader scope that includes scams and phishing) and $1.31 billion in losses ($1.2 billion net of frozen and recovered funds), published July 8, 2026. CertiK noted that when the $1.45 billion Bybit hack of early 2025 is excluded as an outlier, H1 2026 losses were approximately 28% higher year-over-year rather than lower. The four largest single incidents in Blockaid's count — KelpDAO ($292M), Drift Protocol ($285M), Resolv ($80M), and CowSwap ($50.4M) — represented approximately 64% of total reported losses. Attack count rose approximately 50% year-over-year while average loss per incident declined, indicating a broader attack surface concentrated across smaller protocols alongside a small number of very large events.","heading":"Incident Count and Loss Totals: Competing Methodologies","severity":"critical","sources":[{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":2,"name":"CertiK Hack3D: H1 2026 Report Reveals Over $1.31 Billion Lost — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/08/3324276/0/en/certik-hack3d-h1-2026-report-reveals-over-1-31-billion-lost-to-web3-security-incidents-in-the-first-half-of-2026.html"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":2,"name":"Crypto Losses Hit $1.1B in First Half of 2026 — Metaverse Post","type":"news_article","url":"https://mpost.io/crypto-losses-hit-1-1b-in-first-half-of-2026-as-dprk-actors-and-new-attack-vectors-drive-record-incident-surge/"}]},{"content":"Across both major April 2026 incidents, Lazarus Group's TraderTraitor subunit is estimated to have stolen approximately $577–609 million within a 17-day window, representing 55–66% of total H1 losses depending on the reporting firm. Attribution was made independently by TRM Labs, Elliptic, Chainalysis, Mandiant, and CrowdStrike, all of whom identified DPRK-linked infrastructure indicators. Lazarus Group has now been linked to more than $7.3 billion in cumulative crypto theft across documented incidents since 2016.\n\nDrift Protocol (April 1, 2026): Attackers drained approximately $285 million from Drift Protocol, the largest decentralized perpetual futures exchange on Solana, in a window lasting roughly 12 minutes. TRM Labs attributes the attack to North Korean operators. On-chain staging began March 11, nearly three weeks prior, with attacker infrastructure, a fabricated asset (CarbonVote Token, or CVT), and social engineering running in parallel. Attackers spent months cultivating relationships with Drift team members, then used Solana's 'durable nonces' feature to induce Security Council members to unknowingly pre-sign transactions that ultimately transferred administrative control. A zero-timelock governance migration removed the review window that would have permitted detection. Once admin control was obtained, 31 withdrawal transactions executed in roughly 12 minutes, draining SOL, USDC, and Bitcoin.\n\nKelpDAO (April 18, 2026): On April 18, an attacker stole approximately $290–292 million in rsETH from KelpDAO's cross-chain bridge built on LayerZero. The breach began March 6 when an attacker socially engineered a LayerZero Labs developer to harvest session keys and pivot into LayerZero's RPC cloud environment. The attacker deployed malware that fed false transaction data exclusively to LayerZero's verifier while returning honest responses to monitoring systems, then conducted a DDoS attack against legitimate RPC endpoints to force the verifier to rely solely on the poisoned nodes. LayerZero confirmed that KelpDAO had configured the bridge with a 1-of-1 DVN (Decentralized Verifier Network) setup — a single point of failure that LayerZero's documentation had previously warned against. Once the verifier signed a fabricated transaction, the bridge released unbacked rsETH before the malware self-destructed and erased traces. LayerZero attributed the attack to TraderTraitor; Mandiant and CrowdStrike independently confirmed UNC4899 (TraderTraitor) as the threat actor. CoinDesk reported LayerZero's formal attribution on April 20, 2026.","heading":"North Korea / Lazarus Group (TraderTraitor): April 2026 Concentration","severity":"critical","sources":[{"credibility":2,"name":"North Korean Hackers Attack Drift Protocol In USD 285 Million Heist — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"credibility":2,"name":"Drift Protocol Hit by $285M Exploit: Crypto's Biggest Hack of 2026 — Yahoo Finance / CCN","type":"news_article","url":"https://www.ccn.com/news/crypto/drift-protocol-285m-biggest-hack-2026-april-fools-day/"},{"credibility":2,"name":"Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"credibility":2,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":2,"name":"LayerZero ties KelpDAO exploit to Lazarus subgroup TraderTraitor — BeInCrypto","type":"news_article","url":"https://beincrypto.com/layerzero-kelpdao-hack-lazarus-north-korea/"},{"credibility":2,"name":"KelpDAO, Bybit, Ronin: Lazarus Group's Crypto Hacks Behind a $7.3B Heist Empire — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/04/21/kelpdao-bybit-ronin-lazarus-groups-crypto-hacks-behind-a-7-3b-heist-empire/"},{"credibility":2,"name":"Explained: The Kelp DAO Hack (April 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"KelpDAO & LayerZero: Incident Report — Nexus Mutual","type":"other","url":"https://nexusmutual.io/blog/kelpdao-layerzero-incident-report"}]},{"content":"Blockaid's H1 2026 report identified AI autonomous agents as the top new attack vector of the period, citing the May 4, 2026 BankrBot exploit as the first widely documented AI-agent-specific crypto exploit. The incident demonstrated a complete attack chain from untrusted input through AI output to on-chain asset transfer without any smart contract vulnerability in the conventional sense.\n\nBankrBot is an AI-powered trading assistant on X (formerly Twitter) that automatically generates crypto wallets for users who interact with it and executes transactions via natural language commands. The exploit proceeded in two stages. In stage one, an attacker sent a Bankr Club Membership NFT to the target wallet; receipt of this NFT automatically activated a high-privilege permission set within BankrBot, including transfer authorization. In stage two, the attacker sent a message to xAI's Grok chatbot encoded in Morse code — a format that bypassed Grok's plain-text safety filters screening for financial instructions. Grok decoded the message as designed and tagged @bankrbot in its public reply. BankrBot interpreted Grok's public reply as a valid executable command and initiated an ERC-20 transfer on the Base blockchain, moving 3 billion DRB tokens (valued at approximately $150,000–$216,000 at time of exploit) to an attacker-controlled address before rapid liquidation.\n\nSlowMist's forensic analysis identified three root-cause vulnerabilities: (1) BankrBot mapped Grok's natural language outputs to executable financial instructions without validating instruction source, intent authenticity, or anomalous transfer patterns; (2) NFT-based membership activation directly granted high-risk tool permissions without secondary confirmation or transfer limits; and (3) inter-agent communication relied on plain-text public social media outputs rather than structured authenticated protocols. Approximately 80–88% of stolen assets were reportedly returned through public pressure and negotiations; the attacker's X account was subsequently deleted with no definitive attribution established.\n\nBlockaid projected in its H1 report that AI agent deployments are growing approximately ten times per year and that the industry should expect multiple AI agent incidents in H2 2026, with prompt injection attacks leading and tool-use abuse and unauthorized signing following as secondary vectors.","heading":"AI Agents as Emerging Attack Vector: The BankrBot/Grok Incident","severity":"high","sources":[{"credibility":2,"name":"AI Wallet Drained as Hacker Uses Encoded Prompt in Bankr Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/ai-wallet-drained-as-hacker-uses-encoded-prompt/"},{"credibility":2,"name":"Behind the Grok Exploitation: An Analysis of AI Agent Permission Chain Abuse — SlowMist / Medium","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":2,"name":"AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet — OECD.AI","type":"other","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"How Grok got prompt-injected: an X user drained $150,000 from an AI wallet — Giskard","type":"research","url":"https://www.giskard.ai/knowledge/how-grok-got-prompt-injected-an-x-user-drained-150-000-from-an-ai-wallet"},{"credibility":2,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Grok Hack Explained: How Prompt Injection Drained Nearly $200K — Memeburn","type":"news_article","url":"https://memeburn.com/grok-hack-explained-how-prompt-injection-drained-nearly-200k/"}]},{"content":"Cross-chain bridges remained the single highest-value attack target category in H1 2026. Blockaid identified at least seven bridge incidents in its 212-exploit count; broader tallies including minor exploits place the figure at eight or more. The KelpDAO rsETH bridge ($290–292M) dominated this category and is addressed separately under the North Korea section. Other documented bridge incidents in H1 2026 include: the Verus-Ethereum bridge ($11 million, May 2026), in which the attacker made off with 103.6 tBTC, 1,625 ETH, and 147,000 USDC — approximately $8.5 million was subsequently returned; Hyperbridge, where an attacker used a forged cross-chain message to gain control of a bridged DOT token contract and mint 1 billion bridged DOT tokens (smaller dollar impact); CrossCurve, which halted user activity after a $3 million attack targeted its cross-chain bridge; and several additional smaller incidents on Taiko, Alephium, Secret/Axelar, Swapnet, and Syscoin. A May 2026 analysis found that cross-chain bridges claimed 42% of that month's approximately $70 million in total crypto exploit losses. Phemex reported that bridge exploits continued to dominate the DeFi loss landscape through the first half. Structural security challenges — single-DVN configurations, inadequate verifier redundancy, and off-chain prover infrastructure susceptibility — were identified as persistent root causes across multiple incidents.","heading":"Cross-Chain Bridge Exploits: Persistent Highest-Value Target Category","severity":"high","sources":[{"credibility":2,"name":"Verus-Ethereum bridge loses $11 million as hackers keep targeting cross-chain infrastructure — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"credibility":2,"name":"Cross-Chain Bridges Keep Getting Drained, So Why Does It Keep Happening? — Yellow.com","type":"research","url":"https://yellow.com/research/cross-chain-bridge-exploits-security-risks-2026"},{"credibility":2,"name":"Every Major DeFi Hack in 2026 So Far — Phemex","type":"news_article","url":"https://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained"},{"credibility":3,"name":"Anatomy of 2026's Bridge Exploits — Mintlayer","type":"research","url":"https://www.mintlayer.com/blog/anatomy-of-2026-bridge-exploits/"},{"credibility":2,"name":"Contagion in Decentralized Infrastructure: How Cross-Chain Bridge Exploits Propagate Failure — AMCIS 2026 / AISeL","type":"research","url":"https://aisel.aisnet.org/amcis2026/sig_dspe/sig_dspe/12/"}]},{"content":"Across all major reporting firms, a consistent pattern emerged: infrastructure and operational security compromises — targeting private keys, seed phrases, signing infrastructure, and administrative access — accounted for a disproportionate share of dollar losses relative to incident frequency. TRM Labs found that infrastructure and operational compromises represented approximately 15% of H1 incidents but accounted for roughly 76% of total losses. Blockaid's data showed private key compromises drove approximately $789 million (74%) of total damage across roughly ten incidents, with near-zero recovery rates as assets were typically routed through mixers within hours. CertiK categorized wallet compromises as $445 million across 33 incidents, with phishing at $366 million across 63 incidents.\n\nSocial engineering was the dominant enabler across both major DPRK-linked events (Drift Protocol via durable-nonce pre-signing; KelpDAO via LayerZero developer session-key harvest) as well as multiple smaller incidents targeting employee LinkedIn profiles and developer access. The median loss per incident across all reports was approximately $219,000 (TRM Labs figure), demonstrating the bifurcated distribution between a small number of catastrophic infrastructure compromises and a large volume of lower-value smart contract exploits.","heading":"Infrastructure and Private Key Compromises: Outsized Loss Concentration","severity":"high","sources":[{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":2,"name":"Crypto Losses Hit $1.1B in First Half of 2026 — Metaverse Post","type":"news_article","url":"https://mpost.io/crypto-losses-hit-1-1b-in-first-half-of-2026-as-dprk-actors-and-new-attack-vectors-drive-record-incident-surge/"},{"credibility":2,"name":"CertiK Hack3D: H1 2026 Report — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/08/3324276/0/en/certik-hack3d-h1-2026-report-reveals-over-1-31-billion-lost-to-web3-security-incidents-in-the-first-half-of-2026.html"}]},{"content":"Blockaid's H1 report documented EIP-7702 wallet delegation abuse as a novel and growing attack vector on EVM chains, including the first documented production EIP-7702 wallet-delegation drain on Arbitrum. EIP-7702 permits a standard externally owned account (EOA) to temporarily delegate its execution rights to a smart contract for a specific transaction payload — a feature designed to improve user experience that has been weaponized by attackers. According to analysis from Wintermute and GoPlus Security, over 90% of EIP-7702 delegations observed on-chain are linked to malicious contracts, with 'sweeper' contracts automating the draining of compromised wallets. Attack methods include tricking victims into signing delegation contracts disguised as 'wallet security upgrades' or 'AI asset assistants,' effectively converting the victim's EOA into a programmable contract under attacker control. A concrete earlier instance in January 2026 involved IPOR's Fusion PlasmaVault on Arbitrum, where a legacy smart contract flaw involving EIP-7702 was exploited to drain $336,000 USDC, subsequently laundered through Tornado Cash. Blockaid projected EIP-7702 incidents as one of three primary risk areas for H2 2026 alongside bridge exploits and AI agent attacks.","heading":"EIP-7702 Wallet Delegation Abuse: Novel EVM Attack Surface","severity":"medium","sources":[{"credibility":2,"name":"IPOR's Fusion PlasmaVault Hit by $336K Exploit via EIP-7702 Flaw — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/01/07/ipors-fusion-plasmavault-hit-by-336k-exploit-via-eip-7702-flaw/"},{"credibility":3,"name":"EIP-7702 and the New Frontiers of DeFi Phishing — Ainvest","type":"research","url":"https://www.ainvest.com/news/eip-7702-frontiers-defi-phishing-ethereum-upgrades-reshaping-crypto-risk-2508/"},{"credibility":2,"name":"Inside Wallet Drainers and EIP-7702 Exploits — Three Sigma","type":"research","url":"https://threesigma.xyz/blog/opsec/ai-phishing-wallet-drainers-eip7702-part-2"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"}]},{"content":"CertiK's supplemental Intel3D report, published July 25, 2026, documented a separate physical-world threat dimension. CertiK recorded 52 verified wrench attacks globally in H1 2026, up from 39 in H1 2025 (a 33% increase), with recorded financial exposure reaching an estimated $124.1 million. Average recorded exposure per incident rose from approximately $270,000 in H1 2025 to $2.39 million in H1 2026, a roughly 12x increase in average impact. Europe accounted for 39 of 52 verified incidents (79.6% of global total); France alone recorded 33 incidents, representing 63.5% of all verified cases worldwide. The most significant shift in H1 2026 was the rise of home invasion incidents, growing from a single recorded case in H1 2025 to 20 in H1 2026. Kidnapping rose from 12 to 16 incidents; torture (4) and murder (1) were also recorded. CertiK noted that traditional self-custody advice (hardware wallets, offline seed phrases) is no longer sufficient against this threat class, and recommended multi-signature and MPC setups, withdrawal delays, staged vault architecture, and family preparedness protocols.","heading":"Physical Coercion ('Wrench Attacks'): 33% Surge and Geographic Concentration","severity":"high","sources":[{"credibility":2,"name":"CertiK Intel3D: H1 2026 Wrench Attacks Report — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/25/3333162/0/en/CertiK-Intel3D-H1-2026-Wrench-Attacks-Report-Reveals-33-Surge-in-Physical-Crypto-Crime-Estimated-Losses-Top-124-Million.html"},{"credibility":2,"name":"Crypto 'Wrench Attacks' Cost Victims $124M in Six Months, Up 12x: CertiK — Decrypt","type":"news_article","url":"https://decrypt.co/374136/crypto-wrench-attacks-cost-victims-124m-in-six-months-up-12x-certik"},{"credibility":2,"name":"Crypto home invasions jump 20x as wrench-attack exposure hits $124 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-home-invasions-jump-20x-as-wrench-attack-exposure-hits-124-million/"},{"credibility":2,"name":"CertiK Intel3D H1 2026 Wrench Attacks — CertiK","type":"research","url":"https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026"}]},{"content":"Blockaid's figures showed approximate parity between Ethereum-ecosystem and Solana losses in H1 2026. Ethereum-based projects suffered approximately $332 million in losses, primarily from smart contract vulnerabilities. Solana-based projects suffered approximately $326 million, with 98% of that total attributable to compromised keys (dominated by the Drift Protocol breach). CertiK data showed smart contract (code) exploits comprised the highest incident count at roughly 204 of 344 tracked incidents but the lowest average loss per event. Wallet compromise events (33 incidents) and phishing incidents (63 incidents) generated disproportionate dollar losses relative to their frequency. The Stellar network was highlighted as a partial positive case: Blockaid assisted in quarantining $7.3 million (73%) of a $10.2 million oracle manipulation drain on the Stellar Blend protocol within minutes using real-time wallet clustering.","heading":"Blockchain Distribution of Losses","severity":"medium","sources":[{"credibility":2,"name":"Crypto Losses Hit $1.1B in First Half of 2026 — Metaverse Post","type":"news_article","url":"https://mpost.io/crypto-losses-hit-1-1b-in-first-half-of-2026-as-dprk-actors-and-new-attack-vectors-drive-record-incident-surge/"},{"credibility":2,"name":"CertiK Hack3D: H1 2026 Report — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/08/3324276/0/en/certik-hack3d-h1-2026-report-reveals-over-1-31-billion-lost-to-web3-security-incidents-in-the-first-half-of-2026.html"},{"credibility":2,"name":"Crypto hacks hit record high in H1 2026, Blockaid says — The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"}]},{"content":"CertiK's H1 2026 CEO analysis, covered by Forbes on July 17, 2026, cautioned against interpreting the headline year-over-year decline in losses as evidence of improved ecosystem security. CertiK emphasized that the comparison is materially skewed by the February 2025 Bybit hack ($1.45 billion), a single historic outlier that inflated the H1 2025 baseline. Excluding that event, H1 2026 losses were approximately 28% higher than the comparable prior-year period. CertiK characterized the pattern as 'fewer but far more surgical' attacks, with attackers shifting toward higher-conviction targets with larger per-incident returns rather than high-volume lower-value exploits. Phishing saw a 52.3% decline in volume but only a 10.8% decline in total losses, consistent with this selectivity shift. TRM Labs offered a parallel framing: 'Lower 2026 totals reflect the absence of record-setting thefts, not reduced attacker capability.' Both firms noted that North Korean activity showed no slowdown and that the primary state-sponsored threat remained operational.","heading":"Fewer But More Surgical: CertiK's Reframing of the YoY Narrative","severity":"medium","sources":[{"credibility":1,"name":"Crypto Hacks 2026: CertiK CEO On $1.3 Billion In Losses — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/07/17/fewer-but-far-more-surgical-crypto-hacks-hit-13-billion-in-2026/"},{"credibility":2,"name":"Crypto Hacks Fell 47% in H1 2026, But CertiK Says the Ecosystem Is No Safer — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/crypto-hacks-fell-47-percent-in-h1-but-ecosystem-is-no-safer-certik"},{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":2,"name":"CertiK exposes hidden truth behind crypto's 50% loss drop — Crypto.news","type":"news_article","url":"https://crypto.news/certik-exposes-truth-of-cryptos-50-percent-loss-drop/"}]}],"sources_used":[{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":2,"name":"CertiK Hack3D: H1 2026 Report — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/08/3324276/0/en/certik-hack3d-h1-2026-report-reveals-over-1-31-billion-lost-to-web3-security-incidents-in-the-first-half-of-2026.html"},{"credibility":2,"name":"CertiK Intel3D: H1 2026 Wrench Attacks Report — GlobeNewswire","type":"research","url":"https://www.globenewswire.com/news-release/2026/07/25/3333162/0/en/CertiK-Intel3D-H1-2026-Wrench-Attacks-Report-Reveals-33-Surge-in-Physical-Crypto-Crime-Estimated-Losses-Top-124-Million.html"},{"credibility":2,"name":"North Korean Hackers Attack Drift Protocol In USD 285 Million Heist — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"credibility":2,"name":"Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"credibility":2,"name":"LayerZero blames Kelp's setup for $290 million exploit, attributes it to North Korea's Lazarus — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"credibility":2,"name":"Explained: The Kelp DAO Hack (April 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"credibility":2,"name":"$292 Million Lost, Zero Bugs Found: Lessons From the rsETH Bridge Exploit — OpenZeppelin","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"KelpDAO & LayerZero: Incident Report — Nexus Mutual","type":"other","url":"https://nexusmutual.io/blog/kelpdao-layerzero-incident-report"},{"credibility":2,"name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"Behind the Grok Exploitation: An Analysis of AI Agent Permission Chain Abuse — SlowMist / Medium","type":"research","url":"https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73"},{"credibility":2,"name":"AI Wallet Drained as Hacker Uses Encoded Prompt in Bankr Exploit — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/ai-wallet-drained-as-hacker-uses-encoded-prompt/"},{"credibility":2,"name":"AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet — OECD.AI","type":"other","url":"https://oecd.ai/en/incidents/2026-05-04-4a73"},{"credibility":2,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Verus-Ethereum bridge loses $11 million — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"credibility":2,"name":"IPOR's Fusion PlasmaVault Hit by $336K Exploit via EIP-7702 Flaw — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/01/07/ipors-fusion-plasmavault-hit-by-336k-exploit-via-eip-7702-flaw/"},{"credibility":1,"name":"Crypto Hacks 2026: CertiK CEO On $1.3 Billion In Losses — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/07/17/fewer-but-far-more-surgical-crypto-hacks-hit-13-billion-in-2026/"},{"credibility":2,"name":"Crypto Hacks Fell 47% in H1 2026, But CertiK Says the Ecosystem Is No Safer — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/crypto-hacks-fell-47-percent-in-h1-but-ecosystem-is-no-safer-certik"},{"credibility":2,"name":"Crypto 'Wrench Attacks' Cost Victims $124M in Six Months, Up 12x: CertiK — Decrypt","type":"news_article","url":"https://decrypt.co/374136/crypto-wrench-attacks-cost-victims-124m-in-six-months-up-12x-certik"},{"credibility":2,"name":"Crypto home invasions jump 20x as wrench-attack exposure hits $124 million — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-home-invasions-jump-20x-as-wrench-attack-exposure-hits-124-million/"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":2,"name":"Crypto Losses Hit $1.1B in First Half of 2026 — Metaverse Post","type":"news_article","url":"https://mpost.io/crypto-losses-hit-1-1b-in-first-half-of-2026-as-dprk-actors-and-new-attack-vectors-drive-record-incident-surge/"},{"credibility":2,"name":"LayerZero ties KelpDAO Exploit to Lazarus subgroup TraderTraitor — BeInCrypto","type":"news_article","url":"https://beincrypto.com/layerzero-kelpdao-hack-lazarus-north-korea/"},{"credibility":2,"name":"Every Major DeFi Hack in 2026 So Far — Phemex","type":"news_article","url":"https://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained"},{"credibility":2,"name":"Crypto security breaches surpass $1B in H1 2026, hit record high — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/crypto-security-breaches-surpass-1b-in-h1-2026-hit-record-high/"},{"credibility":3,"name":"Drift Protocol Hack: $285M Stolen in 12 Min — Shattered.io","type":"research","url":"https://shattered.io/drift-protocol-hack-285m/"}],"summary":"The first half of 2026 established a new all-time record for cryptocurrency exploit frequency, with 207–212 verified incidents (varying by methodology) resulting in $972 million to $1.32 billion in losses depending on the reporting firm. North Korea's Lazarus Group (TraderTraitor subunit) was responsible for approximately 55–66% of total losses through two concentrated attacks in April 2026, while AI-powered autonomous agents emerged as a distinct and novel attack surface for the first time in widely documented crypto security history.","timeline":[{"date":"2026-01-07","event":"IPOR Fusion PlasmaVault on Arbitrum drained of $336,000 USDC via EIP-7702 wallet-delegation exploit — first documented production EIP-7702 drain.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/01/07/ipors-fusion-plasmavault-hit-by-336k-exploit-via-eip-7702-flaw/"},{"date":"2026-03-06","event":"Social engineering of LayerZero Labs developer begins; attacker harvests session keys and pivots into LayerZero's RPC cloud environment — earliest known staging date for KelpDAO exploit.","source":"Halborn / LayerZero incident reporting","source_url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"date":"2026-03-11","event":"On-chain staging begins for Drift Protocol attack: 10 ETH withdrawn from Tornado Cash; durable nonce accounts created for pre-signed transaction delivery.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"date":"2026-03-27","event":"Drift Protocol Security Council migrated to a zero-timelock governance configuration, removing the review window that would have allowed detection of the pending exploit.","source":"TRM Labs / Chainalysis","source_url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"date":"2026-04-01","event":"Drift Protocol drained of approximately $285 million in SOL, USDC, and Bitcoin across 31 withdrawal transactions in roughly 12 minutes. Attributed to North Korea's Lazarus Group / TraderTraitor by TRM Labs and Elliptic.","source":"TRM Labs / Yahoo Finance","source_url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"date":"2026-04-14","event":"CoW Swap suffers a DNS hijacking attack seizing front-end control; core smart contracts unaffected. A separate single-signature approval event resulted in $50.4 million in losses attributed to CowSwap in Blockaid's H1 count.","source":"The Block / 99Bitcoins","source_url":"https://www.theblock.co/post/397432/cow-swap-pauses-protocol-amid-domain-hijacking"},{"date":"2026-04-18","event":"KelpDAO rsETH bridge drained of approximately $290–292 million by attacker who poisoned LayerZero RPC nodes via malware after social engineering a LayerZero developer on March 6. Attributed to TraderTraitor (UNC4899) by Mandiant, CrowdStrike, LayerZero, and three independent analytics firms.","source":"CoinDesk / LayerZero / Halborn","source_url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"date":"2026-04-20","event":"LayerZero publishes formal attribution of KelpDAO exploit to TraderTraitor; blames KelpDAO's single-DVN configuration as the critical enabler.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/04/20/layerzero-blames-kelp-s-setup-for-usd290-million-exploit-attributes-it-to-north-korea-s-lazarus"},{"date":"2026-05-04","event":"BankrBot/Grok prompt injection exploit executed on the Base blockchain: attacker uses Morse-code-encoded message to trick Grok into tagging @bankrbot with a transfer command, draining approximately $150,000–$216,000 in DRB tokens. First widely documented AI-agent-specific crypto exploit.","source":"Crypto Economy / SlowMist / OECD.AI","source_url":"https://crypto-economy.com/ai-wallet-drained-as-hacker-uses-encoded-prompt/"},{"date":"2026-05-18","event":"Verus-Ethereum bridge hacked for $11 million (103.6 tBTC, 1,625 ETH, 147,000 USDC); approximately $8.5 million later returned.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack"},{"date":"2026-07-08","event":"CertiK publishes Hack3D H1 2026 Report: 344 incidents, $1.31 billion in losses ($1.2 billion net), noting adjusted YoY increase of 28% when Bybit outlier is excluded.","source":"GlobeNewswire / CertiK","source_url":"https://www.globenewswire.com/news-release/2026/07/08/3324276/0/en/certik-hack3d-h1-2026-report-reveals-over-1-31-billion-lost-to-web3-security-incidents-in-the-first-half-of-2026.html"},{"date":"2026-07-25","event":"CertiK Intel3D Wrench Attacks H1 2026 report published: 52 verified physical coercion incidents, $124.1 million in financial exposure, 33% increase in incidents year-over-year, 20x increase in home invasions.","source":"GlobeNewswire / CertiK","source_url":"https://www.globenewswire.com/news-release/2026/07/25/3333162/0/en/CertiK-Intel3D-H1-2026-Wrench-Attacks-Report-Reveals-33-Surge-in-Physical-Crypto-Crime-Estimated-Losses-Top-124-Million.html"},{"date":"2026-07-29","event":"Blockaid H1 2026 Security Report published: 212 verified exploits, $1.1 billion in losses, identifies AI agents as top new attack vector, projects multiple AI agent incidents in H2 2026.","source":"The Block / CryptoTimes","source_url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"date":"2026-07-29","event":"TRM Labs H1 2026 report published: 207 incidents, $972 million in losses, $643 million attributed to North Korean actors (66% of total), average loss per hack $4.7 million, median $219,000.","source":"TRM Labs / Blockonomi","source_url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 182e1d7e-c7d7-4afe-ae21-18552e6db3f9
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.