Blockaid H1 Report: 212 Incidents and $1.1 Billion Lost—Rewriting On-Chain Security Priorities

crypto securityon-chain attacksauditTrustformer

74% of $1.1 Billion: Why Operational Security Became the Biggest Gap

Blockaid released its H1 2026 on-chain security report on July 28, showing 212 verified attack incidents in the first half of the year that caused approximately $1.1 billion in losses. The number of incidents was 3.4 times higher than the total tracked throughout 2025, exceeding the company’s previous annual monitoring volume. The most important structural finding was that 74% of losses came from operational security failures, including device theft, credential leaks, private key exposure and compromised signing infrastructure, rather than smart contract code vulnerabilities. A single attack cluster linked to North Korea's DPRK contributed 55% of total losses, approximately $600 million. TRM Labs independently recorded 207 incidents, showing strong alignment with Blockaid's findings.

Institutions therefore need to place public news events, protocol developments and on-chain indicators into the same assessment framework instead of treating short-term volatility as structural change. When a news event suddenly drives attention toward a token or product sector, risk teams should quickly reassess source-of-funds exposure and address activity to determine whether wallet access controls or liquidation thresholds require temporary adjustment. Teams should also establish pre-event, during-event and post-event baselines to record normal fund flows and counterparty structures. These baselines help models distinguish broad market volatility from abnormal behavior by a single entity, reducing false positives in news-driven environments.

Audit Failure: How Legitimate Signatures Become Attack Vectors

The fact that 74% of losses came from operational security failures means code audits are no longer the primary defense layer. Audited contracts can still be exploited when authorized signers approve malicious transactions, while bridge validation nodes may depend on compromised external infrastructure. After attackers gain administrative control through social engineering, long-term infiltration or pre-signed transactions, their on-chain actions remain technically valid, making traditional screening methods based on address blacklists and transaction validity ineffective. In addition, Drift attackers transferred approximately 23,095 ETH, worth around $44.4 million, into Tornado Cash between July 23 and 24, showing that stolen assets can remain actively moved months after an incident.

Single-transaction thresholds and static blacklists cannot effectively detect wallet rotation, transaction splitting, cross-chain movement or common ownership. A stronger approach combines transaction velocity, counterparty exposure, concentration levels, contract permissions and historical baselines into an explainable composite risk score. Investigators must trace every label, rule and graph relationship back to its source rather than relying on conclusions that cannot be verified. High-impact events also require manual review and secondary data validation to prevent unverified risk labels from spreading across customer accounts. Confirmed findings should update entity profiles so future transactions receive more accurate and consistent risk assessments.

Connecting Operational Signals to KYT Monitoring

Institutions should integrate KYT with operational security frameworks by monitoring not only address labels but also administrative permission changes, multisig restructuring, large transfers and historical behavior consistency. Trustformer KYT can monitor project treasuries, bridge contracts, validator-related addresses and protocol multisig wallets, while combining events such as staking migrations, token unlocks and Tornado Cash inflows into cross-chain risk alerts. This allows operational compromises to leave a traceable evidence chain through blockchain activity.

Risk responses should follow a tiered model: low-risk transactions can pass automatically, medium-risk cases move to enhanced due diligence, and high-risk activity may trigger delay, restriction or freezing recommendations. Every alert should preserve timestamps, rule versions, transaction paths and human decisions so compliance, audit and regulatory reporting operate on the same evidence base. Management should regularly evaluate alert accuracy, investigation speed and prevented exposure, then adjust thresholds based on measurable outcomes. In this way, KYT becomes more than a compliance checkpoint; it supports business continuity, market-risk analysis and accountable operational decisions. A shared dashboard also gives legal, operations and security teams the same view of open cases, ownership and response deadlines.

About Trustformer

Trustformer is a leading blockchain security and compliance technology company specializing in providing professional risk management and compliance solutions for the global cryptocurrency ecosystem. We have developed the cutting-edge Trustformer KYT (Know Your Transaction) platform, which integrates artificial intelligence, blockchain analytics, and regulatory technology to deliver comprehensive, accurate real-time transaction monitoring, risk assessment, and suspicious activity reporting services.

With deep industry expertise and technological innovation, Trustformer is dedicated to helping Virtual Asset Service Providers (VASPs), crypto financial institutions, and investors build a safer and more transparent crypto financial environment. We believe that driving compliance and trust through technology can contribute to the thriving growth of the global digital economy.