Crypto Fraud Watch: A Record $1.1 Billion in H1 Hacks, North Korea's Long Shadow, and a DEX Goes Dark

The first half of 2026 has now earned an unwelcome distinction: it is the most hacked six-month stretch in cryptocurrency's history. A new security report, a fresh wave of state-linked theft, and yet another project quietly closing its doors all landed in the past two days. Here is what the latest news means for anyone holding, building, or investing in digital assets, and where the legal exposure sits.

A Record $1.1 Billion Stolen in Six Months

On July 28, security firm Blockaid released its H1 2026 report tallying 212 verified on-chain exploits that drained more than $1.1 billion from protocols, wallets, and infrastructure. It is the highest six-month total the industry has ever recorded. Two incidents alone accounted for roughly half of the losses: the KelpDAO exploit at about $292 million and the Drift Protocol attack at around $285 million, together nearing $577 million.

The more sobering finding is about cause. Roughly 74% of stolen funds came from operational security failures rather than flawed smart-contract code, and infrastructure compromises, including social engineering, drove about 76% of the total value lost. In plain terms, attackers are increasingly beating people and processes, not cryptography. For companies, that reframes liability: a breach traced to a mishandled private key, a phished employee, or lax internal controls looks far more like a negligence and governance problem than an act of God, and courts and regulators tend to treat it that way.

North Korea's Long Shadow and the Compliance Problem

According to figures cited alongside the report, DPRK-linked actors were responsible for roughly two-thirds of all losses in the period, with a single cluster accounting for more than half. That concentration matters legally. Funds that pass through North Korean hacking operations implicate U.S. and international sanctions regimes, which means an exchange, custodian, or DeFi front end that unknowingly processes tainted assets can face OFAC exposure regardless of intent.

The practical upshot for businesses is that anti-money-laundering and sanctions screening are no longer optional niceties. Robust know-your-customer procedures, transaction monitoring, and prompt reporting are becoming the baseline a regulator will expect to see if funds tied to a state-sponsored theft surface on your platform. Victims, meanwhile, face a hard road to recovery when the trail leads offshore and into mixers, which is precisely why preserving evidence and acting quickly is so important.

Projects Fold as the Market Grinds On

The pressure is not only from attackers. On July 29, perpetual-futures exchange Dango halted trading and confirmed it will shut down its Layer-1 blockchain on August 13, concluding there was no viable path to commercial success barely three months after its mainnet launch. It joins dozens of blockchain and crypto projects that have wound down or filed for bankruptcy in 2026 amid a difficult market, with Bitcoin trading around $64,000 on July 30. Orderly shutdowns like Dango's, which settled positions at oracle prices and returned balances in USDC, are the responsible model, but they are a reminder that users should understand what happens to their funds if the lights go out, and that terms of service, custody arrangements, and wind-down mechanics carry real legal weight.

How to Protect Yourself

Because most losses this year traced back to operational failures rather than broken code, the strongest defenses are behavioral. Use a hardware wallet and never enter your seed phrase into a website, app prompt, or message, no matter how legitimate it appears. Treat unexpected links, "support" agents, and urgent security alerts as hostile by default, verify software and contracts through official channels, and for businesses, enforce multi-signature controls, hardware key custody, least-privilege access, and regular sanctions and AML screening. When withdrawing from a platform that has announced a wind-down, do not wait for the final deadline.

If you have already been victimized, legal recourse exists but is time-sensitive. Preserve every record, including transaction hashes, wallet addresses, and communications, and report the theft promptly to law enforcement and, where relevant, to the platform involved. Early action improves the odds of tracing funds, supporting a civil recovery claim, or participating in a coordinated seizure. An attorney who understands both blockchain forensics and the applicable regulatory framework can help you move before the trail goes cold.

At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud, whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.

Disclaimer

This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.

Next
Next

Crypto Law Brief: A New CLARITY Act Draft, Storj's Chapter 11, and Malware That Hunts Seed Phrases