In the first half of 2026, cybercriminals carried out 212 onchain exploits, stealing $1.1 billion — a 3.4-fold increase over the total number of exploits recorded in all of 2025. North Korea-linked hackers were responsible for $600 million of the stolen funds, according to data released this week.
North Korea's Growing Role
The $600 million attributed to North Korean operatives represents more than half of the total stolen in the period. While the report did not break down individual incidents, the figure underscores the regime's continued focus on cryptocurrency theft as a revenue source. Previous years have seen similar patterns, but the scale in 2026 marks a significant escalation.
AI and Wallet Attacks Accelerate
The surge is being driven in part by the accelerating use of artificial intelligence in attacks, as well as a rise in wallet-specific exploits. AI tools are helping attackers automate phishing campaigns and identify vulnerabilities faster than ever. Wallet attacks, which target both hot and cold storage, have become more sophisticated, often bypassing traditional security measures.
What the Numbers Mean
The 212 exploits in just six months compare to roughly 62 in the same period last year — a pace that security teams are struggling to match. The $1.1 billion stolen is a stark reminder of the risks in the onchain ecosystem. While some of the funds may be recovered through blockchain tracing and law enforcement action, the majority is likely lost.
The data also highlights a shift in attacker behavior. Rather than targeting exchanges or bridges exclusively, criminals are increasingly going after individual wallets and using AI to scale their operations. This makes defense harder for both platforms and users.
With the second half of 2026 already underway, the industry is watching to see whether the trend accelerates further or if new security measures can slow the tide.




