Fact-check findings
What an automated fact-checker found when it re-read H1 2026 Crypto Hack Landscape — AI Agent Attack Vector Emerges against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
3 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #8[disputed][awaiting moderator]in section: AI Agents as Emerging Attack Vector: The BankrBot/Grok Incident
“Approximately 80–88% of stolen assets were reportedly returned through public pressure and negotiations; the attacker's X account was subsequently deleted with no definitive attribution established.”
reviewerThe BankrBot/Grok exploit (May 4, 2026) drained 3 billion DRB tokens worth approximately $150,000-$216,000 via a Morse-code prompt injection and NFT-based privilege escalation; the attacker's X account was subsequently deleted with no definitive attribution established.Multiple independent outlets name a specific handle/address linked to the attacker and describe the community having identified them, which is materially different from 'no definitive attribution established.' The 80-88% recovery figure and account deletion are confirmed.Proposed correction (not yet applied)Approximately 80–88% of stolen assets were reportedly returned through public pressure and negotiations; the attacker's X account was subsequently deleted after the community identified the attacker's on-chain handle (ilhamrafli.base.eth / @Ilhamrfliansyh), though the real-world identity behind it was not independently confirmed. - #13[disputed][awaiting moderator]in section: EIP-7702 Wallet Delegation Abuse: Novel EVM Attack Surface
“A concrete earlier instance in January 2026 involved IPOR's Fusion PlasmaVault on Arbitrum, where a legacy smart contract flaw involving EIP-7702 was exploited to drain $336,000 USDC, subsequently laundered through Tornado Cash.”
reviewerBlockaid documented the first documented production EIP-7702 wallet-delegation drain on Arbitrum, exemplified by the January 2026 IPOR Fusion PlasmaVault exploit ($336,000 USDC), subsequently laundered through Tornado Cash.The page's own cited July 29 Blockaid/CryptoTimes source describes the IPOR incident's final classification as a 'complete white hat return,' which the page's text (final outcome stated as funds laundered) does not reflect, creating an internal contradiction with its own sourcing.Proposed correction (not yet applied)A concrete earlier instance in January 2026 involved IPOR's Fusion PlasmaVault on Arbitrum, where a legacy smart contract flaw involving EIP-7702 was exploited to drain $336,000 USDC; Blockaid's H1 report categorizes the incident as a complete white-hat return, though the funds were initially moved through an external wallet to Tornado Cash before recovery. - #14[disputed][awaiting moderator]in the timeline
“2026-01-07”
reviewerIPOR Fusion PlasmaVault on Arbitrum was drained on January 7, 2026.The timeline date field records the source's publish date rather than the incident date; the exploit itself occurred one day earlier, on January 6, 2026, per the cited article's own body text and IPOR's own incident disclosure.Proposed correction (not yet applied)2026-01-06
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #9[unverifiable][awaiting moderator]in section: AI Agents as Emerging Attack Vector: The BankrBot/Grok Incident
“SlowMist's forensic analysis identified three root-cause vulnerabilities: (1) BankrBot mapped Grok's natural language outputs to executable financial instructions without validating instruction source, intent authenticity, or anomalous transfer patterns; (2) NFT-based membership activation directly granted high-risk tool permissions without secondary confirmation or transfer limits; and (3) inter-agent communication relied on plain-text public social media outputs rather than structured authenticated protocols.”
reviewerSlowMist's forensic analysis identified three specific root-cause vulnerabilities in the BankrBot/Grok chain.Could not access the primary SlowMist post directly to confirm the specific three-part root-cause framing; secondary coverage describes a simpler two-vulnerability framing, so this could not be independently confirmed or refuted.
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #15[partially supported][awaiting moderator]in section: EIP-7702 Wallet Delegation Abuse: Novel EVM Attack Surface
“According to analysis from Wintermute and GoPlus Security, over 90% of EIP-7702 delegations observed on-chain are linked to malicious contracts, with 'sweeper' contracts automating the draining of compromised wallets.”
reviewerOver 90% of EIP-7702 delegations observed on-chain are linked to malicious contracts, per Wintermute and GoPlus Security analysis.The underlying Wintermute figure is actually higher (~94-97%) than the 'over 90%' cited, and one of the two sections' own cited sources (Three Sigma) does not contain this statistic; GoPlus's specific involvement in this figure could not be independently confirmed. - #20[partially supported][awaiting moderator]in the timeline
“A separate single-signature approval event resulted in $50.4 million in losses attributed to CowSwap in Blockaid's H1 count.”
reviewerA separate single-signature approval event resulted in $50.4 million in losses attributed to CowSwap in Blockaid's H1 count, distinct from the April 14 DNS hijacking of the frontend.The $50.4M figure and 'single-signature approval'/user-mistake characterization are accurate per Blockaid's own count, but the underlying event (the Aave/CoW Swap swap-execution disaster) appears to have occurred around March 12, 2026, not April 14; bundling it into the April 14 DNS-hijack timeline row without its own date is a chronological placement issue even though the text correctly flags it as 'separate.'
confirmed
14 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Incident Count and Loss Totals: Competing Methodologies
“Blockaid counted 212 verified exploits and $1.1 billion in total losses, describing this as the highest first-half incident count on record and noting that 3.4 times as many high-threshold exploits occurred in H1 2026 as in all of 2025.”
reviewerBlockaid counted 212 verified exploits and $1.1 billion in total losses in H1 2026, the highest first-half incident count on record, with 3.4x as many high-threshold exploits as all of 2025.Independently corroborated by multiple outlets summarizing the same Blockaid H1 2026 report. - #2[confirmed][no action needed]in section: Incident Count and Loss Totals: Competing Methodologies
“TRM Labs counted 207 incidents and $972 million in losses, noting a 58% decline from the $2.3 billion recorded in H1 2025; TRM attributed North Korea-linked actors with $643 million, or approximately 66% of its total.”
reviewerTRM Labs counted 207 incidents and $972 million in losses, a 58% decline from $2.3 billion in H1 2025; North Korea-linked actors accounted for $643 million (~66%).Figures match TRM's own report exactly; the 58% decline rounds correctly from 972/2300. - #3[confirmed][no action needed]in section: Incident Count and Loss Totals: Competing Methodologies
“CertiK's Hack3D report tracked 344 incidents (a broader scope that includes scams and phishing) and $1.31 billion in losses ($1.2 billion net of frozen and recovered funds), published July 8, 2026. CertiK noted that when the $1.45 billion Bybit hack of early 2025 is excluded as an outlier, H1 2026 losses were approximately 28% higher year-over-year rather than lower.”
reviewerCertiK's Hack3D tracked 344 incidents and $1.31 billion in losses ($1.2 billion net), published July 8, 2026; excluding the Bybit outlier, H1 2026 losses were ~28% higher YoY.All figures verified against CertiK's own published report. - #4[confirmed][no action needed]in section: Incident Count and Loss Totals: Competing Methodologies
“The four largest single incidents in Blockaid's count — KelpDAO ($292M), Drift Protocol ($285M), Resolv ($80M), and CowSwap ($50.4M) — represented approximately 64% of total reported losses.”
reviewerThe four largest single incidents in Blockaid's count — KelpDAO ($292M), Drift Protocol ($285M), Resolv ($80M), CowSwap ($50.4M) — represented approximately 64% of total reported losses.Figure reconciles exactly across two independent summaries of the Blockaid report. - #5[confirmed][no action needed]in section: North Korea / Lazarus Group (TraderTraitor): April 2026 Concentration
“Across both major April 2026 incidents, Lazarus Group's TraderTraitor subunit is estimated to have stolen approximately $577–609 million within a 17-day window, representing 55–66% of total H1 losses depending on the reporting firm.”
reviewerLazarus/TraderTraitor stole ~$577-609M across the two April 2026 incidents within a 17-day window (55-66% of H1 losses); Lazarus's cumulative crypto theft since 2016 now exceeds $7.3 billion.Both the dollar range and the cumulative $7.3B figure are corroborated by the cited source and independently found reporting. - #6[confirmed][no action needed]in section: North Korea / Lazarus Group (TraderTraitor): April 2026 Concentration
“Attackers spent months cultivating relationships with Drift team members, then used Solana's 'durable nonces' feature to induce Security Council members to unknowingly pre-sign transactions that ultimately transferred administrative control. A zero-timelock governance migration removed the review window that would have permitted detection. Once admin control was obtained, 31 withdrawal transactions executed in roughly 12 minutes, draining SOL, USDC, and Bitcoin.”
reviewerDrift Protocol was drained of ~$285M in ~12 minutes via durable-nonce pre-signed transactions and a zero-timelock governance migration; staging began March 11.Every specific mechanical detail checked against the primary TRM Labs source and confirmed verbatim in substance. - #7[confirmed][no action needed]in section: North Korea / Lazarus Group (TraderTraitor): April 2026 Concentration
“LayerZero confirmed that KelpDAO had configured the bridge with a 1-of-1 DVN (Decentralized Verifier Network) setup — a single point of failure that LayerZero's documentation had previously warned against.”
reviewerKelpDAO's rsETH bridge was drained of ~$290-292M via LayerZero RPC node poisoning after a developer's session keys were harvested via social engineering beginning March 6; the bridge used a 1-of-1 DVN configuration.Mechanically and attributionally consistent with independent reporting. - #10[confirmed][no action needed]in section: Cross-Chain Bridge Exploits: Persistent Highest-Value Target Category
“Other documented bridge incidents in H1 2026 include: the Verus-Ethereum bridge ($11 million, May 2026), in which the attacker made off with 103.6 tBTC, 1,625 ETH, and 147,000 USDC — approximately $8.5 million was subsequently returned”
reviewerCross-chain bridges remained the single highest-value attack target category in H1 2026, with at least seven Blockaid-counted bridge incidents including Verus-Ethereum ($11M), Hyperbridge, and CrossCurve ($3M).Asset amounts match independent reporting closely; the $8.5M return figure is consistent with the ~$11.5-11.6M gross figures reported and partial recovery via Tornado Cash tracing. - #11[confirmed][no action needed]in section: Infrastructure and Private Key Compromises: Outsized Loss Concentration
“TRM Labs found that infrastructure and operational compromises represented approximately 15% of H1 incidents but accounted for roughly 76% of total losses. Blockaid's data showed private key compromises drove approximately $789 million (74%) of total damage across roughly ten incidents, with near-zero recovery rates as assets were typically routed through mixers within hours.”
reviewerTRM Labs found infrastructure/operational compromises represented ~15% of H1 incidents but ~76% of total losses; Blockaid found private key compromises drove ~$789M (74%) of total damage across ~10 incidents.TRM figure verified precisely; Blockaid's 74%/$789M figure is consistent with, though not verbatim quoted in, secondary sources reviewed. - #12[confirmed][no action needed]in section: Infrastructure and Private Key Compromises: Outsized Loss Concentration
“CertiK categorized wallet compromises as $445 million across 33 incidents, with phishing at $366 million across 63 incidents.”
reviewerCertiK categorized wallet compromises as $445 million across 33 incidents, with phishing at $366 million across 63 incidents; phishing volume fell 52.3% while losses fell only 10.8%.Exact match against CertiK's primary report. - #16[confirmed][no action needed]in section: Physical Coercion ('Wrench Attacks'): 33% Surge and Geographic Concentration
“CertiK recorded 52 verified wrench attacks globally in H1 2026, up from 39 in H1 2025 (a 33% increase), with recorded financial exposure reaching an estimated $124.1 million. Average recorded exposure per incident rose from approximately $270,000 in H1 2025 to $2.39 million in H1 2026, a roughly 12x increase in average impact. Europe accounted for 39 of 52 verified incidents (79.6% of global total); France alone recorded 33 incidents, representing 63.5% of all verified cases worldwide.”
reviewerCertiK recorded 52 verified wrench attacks globally in H1 2026, up 33% from 39 in H1 2025, with $124.1 million in financial exposure; Europe accounted for 79.6% and France for 63.5% of global incidents; home invasions rose from 1 to 20.Comprehensive verbatim match to CertiK's own press release; independently corroborated by CryptoSlate and Decrypt coverage. - #17[confirmed][no action needed]in section: Blockchain Distribution of Losses
“Ethereum-based projects suffered approximately $332 million in losses, primarily from smart contract vulnerabilities. Solana-based projects suffered approximately $326 million, with 98% of that total attributable to compromised keys (dominated by the Drift Protocol breach).”
reviewerBlockaid's figures showed Ethereum-based projects suffered ~$332 million and Solana-based projects ~$326 million, with 98% of Solana losses attributable to compromised keys.Precisely matched against independent reporting on the same Blockaid report. - #18[confirmed][no action needed]in section: Blockchain Distribution of Losses
“The Stellar network was highlighted as a partial positive case: Blockaid assisted in quarantining $7.3 million (73%) of a $10.2 million oracle manipulation drain on the Stellar Blend protocol within minutes using real-time wallet clustering.”
reviewerBlockaid assisted in quarantining $7.3 million (73%) of a $10.2 million oracle manipulation drain on the Stellar Blend protocol within minutes using real-time wallet clustering.Figure independently corroborated, though total loss estimates vary slightly ($10.2M-$10.97M) across different outlets covering the same YieldBlox/Blend incident. - #19[confirmed][no action needed]in section: Fewer But More Surgical: CertiK's Reframing of the YoY Narrative
“CertiK characterized the pattern as 'fewer but far more surgical' attacks, with attackers shifting toward higher-conviction targets with larger per-incident returns rather than high-volume lower-value exploits.”
reviewerCertiK characterized the H1 2026 pattern as 'fewer but far more surgical' attacks; phishing saw a 52.3% decline in volume but only a 10.8% decline in losses; TRM offered a parallel framing about lower totals reflecting absence of record-setting thefts, not reduced attacker capability.Confirmed via search-derived excerpts of the Forbes piece (direct WebFetch was blocked by the site, but the phrase and framing are corroborated by the article's own headline and by secondary aggregation).