OKX has released its H1 2026 Web3 security semi annual report revealing 182 security incidents that resulted in $956 million total losses, showing 50% more events than H1 2025. Meanwhile, total losses dropped 60% as attackers shifted from large smart contract exploits to social engineering, single-point risks and AI-powered attacks.
OKX Report Records 182 Crypto Incidents and $956M Losses in H1 2026
According to OKX’s Web3 Security report, jointly produced with SlowMist and OtterSec, H1 2026 recorded 182 publicly disclosed security incidents with $956M total losses, marking a 50% increase from 121 events in H1 2025. The total losses fell by about 60% from the $2.373B reported in the same period of 2025.
The significant decline in losses was largely due to the lack of an outlier event similar to the approximately $1.5B supply-chain attack on Bybit in February 2025. The top 10 biggest project losses compiled by OtterSec were led by KelpDAO attack at approximately $292M, followed by Drift Protocol attack at approximately $285M.
How AI Is Reshaping Crypto Attacks Beyond Smart Contract Exploits
The report reveals that the biggest financial losses no longer stem primarily from smart contract vulnerabilities. Rather, losses were led by supply chain compromises, social engineering, cloud key theft and single point validation failures. Supply chain attacks resulted in approximately $298M in losses, followed by contract logic issues at $152M in losses and private key leaks at $130M.
Notably, the report cited the Bankr incident to show how AI agents can be manipulated. Attackers activated an Agent membership privilege and sent a Morse code prompt injection to xAI’s Grok, which decoded and forwarded it to @bankrbot. The bot accepted the instruction as trusted input and executed transfers worth about $150k to $200k on Base.
AI has also widened the attack surface in the crypto world via social engineering, identity forgery, and code generation. This report mentioned North Korea’s HexagonalRodent, which employed ChatGPT, Cursor, AI-generated websites, and fake recruitment campaigns to breach over 2,700 developer systems. OtterSec also linked 35 of 74 March 2026 CVEs to AI-generated code.
What’s Next as Users and AI Agents Become Top Targets?
As users and AI agents emerge as primary targets, the next phase of Web3 security will likely emphasize proactive, layered defenses that move protection earlier in the attack chain before signing, execution, or trust is granted. Expect wider adoption of sandboxed tool calling, permission tiering, pre execution simulation, and secondary human confirmations for sensitive actions.
Furthermore, more wallets and platforms will offer real-time device scanning, URL and DApp risk detection, and malware identification to block threats before seed phrases or connections occur. The report recommends understanding before signing, avoiding single points of failure, and verifying before trusting through rigorous AI-generated code audits, scoped permissions, transaction transparency, and layered backstops that do not rely solely on AI judgment.