SlowMist | 2026 Mid-year Blockchain Security and AML Report
Due to space limitations, this article highlights only the key findings from the report. The full report can be accessed at the following link:
https://drive.google.com/file/d/15qFJu9X-mKXO98lG63LLll0PzywT9Xxw/view
I. Overview
In the first half of 2026, while the blockchain industry continued its rapid growth, the security threat landscape and regulatory environment further evolved, with the overall risk structure exhibiting a trend toward systematic expansion. As applications such as DeFi, cross-chain infrastructure, and AI Agents accelerated their adoption, the attack surface continued to expand. Security risks have extended beyond smart contracts to encompass the developer ecosystem, software supply chains, end-user interaction environments, and user authorization trust chains. Meanwhile, the widespread adoption of AI technologies has significantly lowered the barriers to social engineering and automated attacks, driving cyber threats toward greater specialization, scalability, and persistence.
State-sponsored threat actors and other highly sophisticated attacks remained active. Attack vectors such as Drainer-as-a-Service (DaaS), supply chain poisoning, and AI-driven scams continued to evolve, exhibiting increasingly modularized and service-oriented characteristics. DeFi protocols, cross-chain bridges, and the developer ecosystem remained among the most frequently targeted risk areas. Privilege abuse and software supply chain dependencies continued to cause significant losses, while the systematic exploitation of trust relationships across the ecosystem became even more pronounced. On the regulatory front, global regulatory frameworks surrounding stablecoins, Anti-Money Laundering (AML), and Virtual Asset Service Providers (VASPs) continued to mature, with compliance requirements tightening at an accelerated pace. Regulatory approaches are shifting from isolated enforcement actions toward systematic governance, accompanied by continuous improvements in on-chain tracing and asset-freezing capabilities.
As a pioneer in blockchain security, SlowMist continues to stay at the forefront of technological innovation by investing deeply in threat intelligence, large language model (LLM) AI security, blockchain tracing and attribution, and compliance and Anti-Money Laundering (AML) infrastructure. Against this backdrop, this report analyzes the major security incidents, global regulatory developments, and emerging trends in on-chain Anti-Money Laundering technologies during the first half of 2026. We hope this report will provide industry practitioners, security researchers, and compliance professionals with timely, systematic, and forward-looking insights, helping the ecosystem strengthen its ability to identify, respond to, and anticipate emerging threats in an era of increasingly stringent compliance requirements and intensifying cyber threats.
II. Blockchain Security Landscape
In the first half of 2026, the blockchain industry continued to face severe security challenges. According to incomplete statistics from the SlowMist Hacked archive, a total of 182 security incidents occurred during the first half of the year, resulting in approximately US$956 million in losses. Compared with the first half of 2025 (121 incidents with approximately US$2.373 billion in losses), the number of incidents increased by approximately 50.41% year-over-year, while the overall financial losses decreased by approximately 59.72% year-over-year.
Note: The data presented in this report is calculated based on token prices at the time each incident occurred. Due to factors such as token price fluctuations, undisclosed incidents, and losses suffered by individual users that are not included in the statistics, the actual losses are expected to be higher than the figures reported above.
Security Incident Overview
(1) According to ecological distribution
- Ethereum was the most frequently targeted ecosystem, with related losses of approximately $134 million.
- The BSC ecosystem followed, with losses of around $36.35 million.
- Arbitrum ranked third, with losses of approximately $4.93 million.
(2) By project type
- DeFi projects remained the most frequently targeted sector. In the first half of 2026, a total of 116 DeFi-related security incidents were recorded, accounting for approximately 63.74% of all incidents (182 in total), with losses reaching approximately $490 million. Compared to the first half of 2025 (92 incidents with approximately $470 million in losses), losses increased by about 4.26% year-on-year.
- Cross-chain bridge incidents totaled 20 cases, resulting in cumulative losses of approximately $346 million. The most severe incident was the Kelp DAO event, where a 1-of-1 DVN (Decentralized Verification Network) configuration in the LayerZero cross-chain bridge was exploited. Attackers compromised LayerZero’s RPC infrastructure and launched DDoS attacks to forge cross-chain messages, leading to a single loss of approximately $292 million. This incident became the largest security loss event in the first half of 2026.
(3) According to the reason for the attack
- From the perspective of incident count, contract and logic vulnerabilities remained the primary attack vector, with a total of 85 incidents.
- This was followed by private key and credential compromise, with 17 incidents.
- Supply chain attacks ranked third, with 12 incidents.
- From the perspective of total losses, supply chain attacks ranked first, with approximately $298 million in total losses, largely driven by a single Kelp DAO incident involving losses of about $292 million.
- Contract and logic vulnerabilities and private key and credential compromise followed, with losses of approximately $152 million and $130 million respectively.
Overall, the blockchain security landscape in the first half of 2026 was characterized by a pattern of “dispersed incidents but concentrated losses.” While the majority of security incidents continued to stem from traditional attack vectors such as contract and logic vulnerabilities, the largest financial losses were increasingly concentrated in critical areas including infrastructure, cross-chain systems, and supply chain attacks. This trend indicates that attackers are shifting their focus toward higher-value, higher-impact targets.
Attack Techniques
The following attack techniques were among the most active and representative attack vectors observed during the first half of 2026.
1. Phishing Attacks
Phishing attacks are increasingly evolving toward a model characterized by platform-based impersonation, multi-stage interaction, and dynamic poisoning. Attackers are more inclined to leverage highly trusted channels — including browser extensions, search engine advertisements, email systems, and mainstream security verification processes — as initial attack vectors. By exploiting the trust mechanisms of these platforms, they effectively reduce users’ vigilance and increase the likelihood of successful attacks.
2. Social Engineering Attacks
Social engineering has become one of the primary threats to Web3 users’ assets. These attacks tend to exploit legitimate business scenarios and user trust, inducing targets to voluntarily perform dangerous actions through recruitment interviews, business collaborations, social interactions, and similar engagements. Meanwhile, the widespread adoption of generative AI has further enhanced the realism, precision, and scalability of such attacks. Personalized scripts, deepfake audio and video, and customized phishing content continue to reduce users’ ability to identify malicious activities, shifting the focus of attacks further from technical vulnerabilities to people and business processes.
3. Supply Chain Poisoning
Supply chain poisoning attacks have remained highly prevalent across the blockchain industry and the broader open-source ecosystem. Attack techniques have evolved from simple package name impersonation and account hijacking to the systematic exploitation of end-to-end trust relationships throughout the developer ecosystem. Rather than compromising a single library or piece of infrastructure, attackers have expanded their targets to include package management ecosystems, CI/CD pipelines, CDN distribution channels, and even AI Agent plugin marketplaces. By poisoning trusted software components, attackers can indirectly compromise a large number of downstream users. Such attacks have a broad impact, are difficult to trace, and can easily be combined with social engineering techniques.
4. AI-Driven Attacks
AI technologies have become deeply integrated into the attack lifecycle, significantly enhancing both the automation and stealth of cyberattacks. On one hand, attackers leverage generative AI to strengthen phishing campaigns, social engineering attacks, and malicious code delivery, making deepfakes, automated script generation, and the dissemination of deceptive content more realistic and scalable. On the other hand, the widespread adoption of AI Agents has expanded the attack surface to the cognition–execution trust chain. Through techniques such as prompt injection, memory poisoning, and tool permission abuse, attackers can manipulate AI Agents into performing unintended actions, further amplifying risks to digital assets and systems.
5. Cryptographic Attacks
In the first half of 2026, blockchain security threats exhibited a clear trend toward layered evolution. Earlier attacks primarily targeted smart contract business logic vulnerabilities or straightforward private key compromises. Today, however, attackers have shifted their focus to the very foundation of blockchain trust — the engineering implementation of cryptographic primitives and protocol mechanisms. These attacks often exploit subtle weaknesses in mathematical implementations, key lifecycle management, proof system integration, or multi-party computation (MPC) schemes to achieve precise, efficient, and difficult-to-detect asset theft. This section systematically examines the cryptographic security risk landscape across cross-chain bridges, wallets, vaults, and privacy protocols through a series of representative case studies.
III. Anti-Money Laundering (AML) Landscape
This section primarily covers four areas: global regulatory developments, asset freezing and recovery statistics, cybercrime organizations, and privacy protocols.
Global Regulatory Developments
In the first half of 2026, the global regulatory landscape for virtual assets continued to evolve. Regulatory priorities expanded beyond market access to encompass stablecoins, Anti-Money Laundering (AML), Virtual Asset Service Providers (VASPs), cross-border fund flows, and risk governance, reflecting an overall trend toward more comprehensive regulatory frameworks, more refined rules, and stronger enforcement.
Major jurisdictions across Asia, Europe, the Americas, and the Middle East successively advanced stablecoin regulatory frameworks, strengthened VASP licensing regimes, and enhanced AML/CFT compliance requirements. At the same time, regulators further intensified oversight of key areas, including cross-border transactions, digital asset custody, Real-World Assets (RWAs), derivatives, and privacy-enhancing assets.
This subsection summarizes the regulatory developments across jurisdictions during the first half of 2026. For the complete list of regulatory updates, please refer to the following link:
Funds Freezing / Recovery Data
In the first half of 2026, there were 18 incidents in which stolen funds were either recovered or frozen after attacks. In these 18 cases, the total amount of stolen funds was approximately 389 million USD, of which nearly 118 million USD was returned or frozen, accounting for 12.3% of the total losses in H1 2026.
In addition, with strong support from the SlowMist InMist Lab threat intelligence cooperation network, SlowMist assisted clients, partners, and publicly reported hacked incidents in freezing/recovering approximately 5.16 million USD in funds in the first half of 2026.
Cybercrime Organizations
1. Lazarus Group
The North Korean state-sponsored hacking group Lazarus Group has remained highly active in global cryptocurrency-related attacks, demonstrating a high degree of sophistication in supply chain compromise, social engineering, attacks against DeFi protocols, cross-chain infrastructure exploitation, and subsequent money laundering activities. Its operations have evolved into a complete attack chain encompassing intrusion, theft, and money laundering, while extensively leveraging privacy protocols, cross-chain bridges, DeFi lending platforms, and cryptocurrency mixing services to build multi-layered fund transfer networks, continuously enhancing operational stealth and increasing the difficulty of asset tracing. This section analyzes the attack characteristics of Lazarus Group through its representative money laundering techniques and major security incidents.
2. Drainers
In the first half of 2026, the Drainer-as-a-Service (DaaS) cybercrime ecosystem continued to evolve. Following the exit of several established drainer services, a new generation of platforms rapidly emerged to replace them, demonstrating an overall trend toward greater professionalism, platformization, and industrialization. By providing mature phishing infrastructure, malicious smart contract templates, multi-chain support, and automated deployment tools under an affiliate revenue-sharing model, operators have significantly lowered the barrier to entry for attackers and accelerated the large-scale proliferation of phishing campaigns. Meanwhile, Drainer platforms have continued integrating AI technologies, multi-chain compatibility, automated operations, and anti-detection capabilities, making attack chains increasingly sophisticated and further increasing the challenges of protecting Web3 user assets and governing on-chain risks. This section analyzes the operational models and attack characteristics of representative DaaS platforms.
Privacy Protocols
In recent years, privacy protocols have gradually evolved from standalone cryptocurrency mixers into more diversified privacy infrastructure. On one hand, classic mixing protocols represented by Tornado Cash continue to maintain high levels of activity. On the other hand, protocols such as Railgun have extended privacy capabilities to DeFi interactions and digital asset management, while projects including Hinkal and Privacy Pools are further exploring mechanisms such as verifiable privacy and selective disclosure, aiming to protect user privacy while addressing regulatory compliance requirements. This section provides a statistical analysis of capital inflows into the major privacy protocols during the first half of the year to examine current trends in the on-chain privacy ecosystem and their security implications.
Note: The statistical data is compiled based on Dune Analytics Dashboards and proprietary query results. Relevant links are available in the full report.
- From the perspective of total inflows, Tornado Cash continues to dominate the privacy protocol landscape, attracting approximately USD 691 million, accounting for roughly 71% of all tracked inflows. Railgun ranked second with approximately USD 222 million, representing about 23%, while Hinkal, Privacy Pools, and zkBOB collectively accounted for the remaining 6%.
- More noteworthy than the overall funding scale is the shift in the composition of deposited assets. With the exception of Tornado Cash, newly deposited funds in Railgun, Hinkal, and Privacy Pools were predominantly stablecoins. In particular, nearly 90% of Railgun’s inflows consisted of stablecoins. This trend suggests that privacy protocols are evolving beyond their traditional role in anonymous withdrawals and are increasingly being adopted for stablecoin transfers, on-chain asset management, and DeFi interactions, reflecting the growing diversification of privacy-preserving use cases within the blockchain ecosystem.
IV. Conclusion
Looking back at the first half of 2026, blockchain security risks continued to evolve, with the attack surface expanding beyond smart contracts to encompass broader areas of the ecosystem, including the developer supply chain, end-user devices, browser extensions, and AI Agents. At the same time, attack techniques became increasingly sophisticated and persistent.
Meanwhile, on-chain fund transfers and money laundering activities remained active, while global regulatory frameworks continued to evolve in key areas such as Anti-Money Laundering (AML), stablecoins, and Virtual Asset Service Providers (VASPs). These developments are driving the industry’s governance model from reactive incident response toward proactive risk prevention and systematic governance.
Against the backdrop of simultaneous technological innovation and the continuous evolution of security risks, strengthening the overall security posture of the blockchain ecosystem has become a fundamental prerequisite for the industry’s long-term, sustainable development.
In response to the rapidly evolving security landscape, SlowMist remains committed to strengthening security capabilities through technological innovation while continuously exploring the application of artificial intelligence in areas such as threat intelligence, on-chain tracing, risk analysis, and Anti-Money Laundering (AML).
To address the security challenges surrounding AI Agents, SlowMist has constructed a five-layer progressive digital fortress system and introduced security capabilities including SlowMist Agent Security Skill, MistTrack Skills, and MistEye Security Gate, a front-end security gateway skill. These solutions help developers and enterprises enhance the security resilience of AI Agents and proactively defend against emerging threats such as prompt injection and supply chain poisoning.
V. Disclaimer
The content of this report is based on our understanding of the blockchain industry, data from the SlowMist blockchain hacked archive database SlowMist Hacked, and the anti-money laundering tracking system MistTrack. However, due to the “anonymous” nature of blockchain, we cannot guarantee the absolute accuracy of all data and cannot be held responsible for errors, omissions, or losses caused by using this report. Additionally, this report does not constitute any investment advice or the basis for other analyses. We welcome criticism and corrections for any oversights or inadequacies in this report.
The complete report can be accessed via the links below:
English:
https://drive.google.com/file/d/15qFJu9X-mKXO98lG63LLll0PzywT9Xxw/view
Chinese:
https://drive.google.com/file/d/1zfngTKU3_dr10QqXKsQNe1kMhHtfQ7J0/view
About SlowMist
SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.
SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.
By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.
