Morning Edition · Wednesday, July 29, 2026Published at 1:31 AM EDT · New York
On-Chain Theft Reached 1.1 Billion Dollars in First Half as Reward-Vault Exploits Continue
Blockaid counted 212 incidents through June, with stolen keys now overtaking contract bugs, while fresh self-dealing attacks drained a token contract of about 605,000 dollars.

Crypto security incidents caused about 1.1 billion dollars in losses across 212 cases in the first half of 2026, according to a report from the security firm Blockaid. The report's central finding is a shift in the attack surface. Private-key and access-control compromises overtook smart-contract bugs as the leading cause of loss. Projects tied to Ethereum accounted for roughly 332 million dollars and Solana-linked projects for about 326 million, per the same data.
The pattern continued into this week's on-chain activity. Security researchers at DeFiHackLabs published proof-of-concept reconstructions of two fresh self-dealing drains, in which an attacker who controls a contract's privileged logic routes the contract's funds to itself. One targeted a token's reward-on-transfer mechanism, moving about 605,000 dollars in the dollar-pegged stablecoin Tether in a single transaction. A second drained a reward vault on Ethereum of about 301.7 ether, roughly 565,000 dollars at current prices. Both are logic-and-access exploits rather than reentrancy or oracle manipulation. The contract behaved as written, and the design let insiders extract value.
Rekt News is separately tracking incidents at AFX Trade, Ostium, Bonzo Finance and BonkDAO, the continual series of smaller drains that accompanies the largest incidents. Neither the token nor the vault losses this week have been publicly attributed, and there is no indication of frozen or recovered funds.
What this means
The composition of losses matters more than the total. When contract bugs dominated, audits and formal verification were the defense. As stolen keys and privileged-logic self-dealing become the leading cause, the exposed parties shift to operators with signing authority and to users of contracts whose admin controls receive little scrutiny. The mechanism is custody and access control, not code correctness, which means an audit's approval does not cover the dominant failure mode.
What to watch
- Whether monthly loss totals for the second half stay elevated, which would confirm key compromise as a durable rather than episodic driver.
- Attribution or fund recovery on the reward-vault drains, which would show whether on-chain forensics can reach self-dealing insiders.
Observations to monitor, not financial advice.
Synthesized from: crypto.news · Polylog editors · DeFiHackLabs
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
More from this edition
- Senate Shelves CLARITY Act Before Recess as SEC Says It Will Write Crypto Rules Itself
- Ethereum Privacy Projects Reframe Confidentiality as the Condition for Banks to Go On-Chain
- Anthropic Says Claude Found a Real Weakness in a Post-Quantum Signature Under US Review
- A Single Anomalous Trade Crashed a Tokenized SK Hynix Perp 20% and Liquidated 57 Million Dollars
- Ethereum Researchers Turn to Mechanism Design to Kill Oracle-Extractable Value at the Source
- Russia's Central Bank Publishes Draft Crypto-Trading Rules Ahead of a Fall Framework
- Ondo Abandons Its Public Tokenization Blockchain for a Private High-Speed Trading Network
- ARK Researcher Expects More Crypto Bankruptcies and Shutdowns as Revenue Concentrates
- Federal Judge Blocks Minnesota's Prediction-Market Felony Law Days Before It Took Effect
- Bitcoin Treasury Firms Keep Buying as a New Metric Reframes the Case for Preferred-Stock Buybacks
- Fake Wallet Apps and Seed-Phrase Malware Widen Crypto's Endpoint Attack Surface