Polylog
The Polylog Crypto Intelligence Brief

Morning Edition · Wednesday, July 29, 2026Published at 1:31 AM EDT · New York

On-Chain Theft Reached 1.1 Billion Dollars in First Half as Reward-Vault Exploits Continue

Blockaid counted 212 incidents through June, with stolen keys now overtaking contract bugs, while fresh self-dealing attacks drained a token contract of about 605,000 dollars.

On-Chain Theft Reached 1.1 Billion Dollars in First Half as Reward-Vault Exploits Continue

Crypto security incidents caused about 1.1 billion dollars in losses across 212 cases in the first half of 2026, according to a report from the security firm Blockaid. The report's central finding is a shift in the attack surface. Private-key and access-control compromises overtook smart-contract bugs as the leading cause of loss. Projects tied to Ethereum accounted for roughly 332 million dollars and Solana-linked projects for about 326 million, per the same data.

The pattern continued into this week's on-chain activity. Security researchers at DeFiHackLabs published proof-of-concept reconstructions of two fresh self-dealing drains, in which an attacker who controls a contract's privileged logic routes the contract's funds to itself. One targeted a token's reward-on-transfer mechanism, moving about 605,000 dollars in the dollar-pegged stablecoin Tether in a single transaction. A second drained a reward vault on Ethereum of about 301.7 ether, roughly 565,000 dollars at current prices. Both are logic-and-access exploits rather than reentrancy or oracle manipulation. The contract behaved as written, and the design let insiders extract value.

Rekt News is separately tracking incidents at AFX Trade, Ostium, Bonzo Finance and BonkDAO, the continual series of smaller drains that accompanies the largest incidents. Neither the token nor the vault losses this week have been publicly attributed, and there is no indication of frozen or recovered funds.

What this means

The composition of losses matters more than the total. When contract bugs dominated, audits and formal verification were the defense. As stolen keys and privileged-logic self-dealing become the leading cause, the exposed parties shift to operators with signing authority and to users of contracts whose admin controls receive little scrutiny. The mechanism is custody and access control, not code correctness, which means an audit's approval does not cover the dominant failure mode.

What to watch

  • Whether monthly loss totals for the second half stay elevated, which would confirm key compromise as a durable rather than episodic driver.
  • Attribution or fund recovery on the reward-vault drains, which would show whether on-chain forensics can reach self-dealing insiders.

Observations to monitor, not financial advice.

3 sources

Synthesized from: crypto.news · Polylog editors · DeFiHackLabs

Part of a tracked trend

Bridge and Mint Exploits Sustain Heavy DeFi Losses

Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.