Industry is facing a massive security crisis and it is not just about faulty smart contracts anymore.
According to the new H12026 data from on chain security platform Blockade, there have already been 212 security incidents this year and that is 3.4 times more than all of 2025 combined, resulting in over $1.1 billion in stolen funds, and attackers are rapidly.
Expanding their targets pivoting from code exploits to compromising wallets, developer credentials as well as operational infrastructure.
Well joining us live this morning to discuss how to secure this expanding ecosystem is time who is co-founder and CEO of Blockade.
You know, great to have you here.
Thank you so much for joining me.
Thanks for having me.
So what is fundamentally behind this massive growth in attacks?
So I think there's a couple of things, right?
I think that.
Obviously the number one culprit is AI.
AI makes it much easier for attackers to go and find vulnerabilities in all sorts of things, not just crypto.
But I think the fastest way for attackers to make money, and obviously most attackers are financially motivated actors, is to not just steal data and then monetize that by selling it in dark net markets and things like that, but it's actually to rob the bank directly.
And the best way to do that is just like hack a crypto company, take its money.
And run with it.
Yes, I do want to expand on this, but why are hackers suddenly pivoting to target private keys as well as these developer credentials?
I think it has to do with kind of the attack surface management and the industry has gotten really good at focusing on looking at smart contracts and understanding, you know, hey, there are different bugs across smart contracts and hardening those in different ways.
But you only have to find one bug in order to steal a bunch of money, right?
Um, and the attack surface outside of smart contracts is actually much larger than the attack surface within smart contracts specifically.
And so an attacker can go and perform social engineering operations like we saw with Kelp or with Drift.
They can go and find bugs or one days in all sorts of other dependencies and then kind of pivot and move laterally within a network to ultimately.
Kind of the crown jewels of this organization, which is crypto.
Yes, and you mentioned artificial intelligence.
This is something that all of us are paying attention to whether we're talking about retail investors or consumers or institutions.
So as you mentioned, bad actors are utilizing this technology, but on the other hand, what are companies doing?
So you know it's a great question.
I think that on one hand, you know, attackers have these kind of tools and generally being an attacker is easier than being an offender.
You only have to find one bug, one hole in a system, and and it all breaks.
And being a defender, you have to kind of cover everything all the time.
But we do things internally inside of Blockade to leverage AI in order to identify various different threats in real time across our customers and our users to go and prevent these types of threats and act on them in real time.
I think these things basically require two types of.
Of considerations one is is greatly reducing the mean time to respond to all sorts of threats because AI just accelerates things in meaningful ways, and two is it's just kind of identifying the surface area of attacks in a much more meaningful way.
And of course 2026 focus has also been on geopolitics.
So tell us about the reality of state sponsored attacks.
Yes, I think North Korea is obviously the number one culprit in terms of a fund loss perspective over the past 6 months for sure.
You know, I think what's really interesting is that when you look at a country that takes its finest and brightest people and sets them on a target, it can do really great things and it can also do really bad things.
What I think is really, really interesting is all of a sudden now you have a really, really smart person in the pocket or in the hands of everyone.
With these AI agents and as more are becoming kind of open source and openweight models we're able to go and kind of apply those to finding threats in every place, right?
So every threat actor is becoming as sophisticated as kind of a North Korean hacker and I understand you have spent many, many years fighting advanced cyber threats.
So what would you say is the best layered security approach when it comes to protecting protocols.
It's a great question.
I, I think, you know, um, security across crypto imports everything from security across everything else, right?
And so when, and, and the only thing that really changes is the organization's crown jewels.
The thing that you need to protect is no longer access to your infrastructure or or data, but it's actually the money your your organization holds or governs for your users, right?
And so you need to kind of import and leverage all the different security standards that.
We as an industry and broadly the world have kind of gone to adopt, but you also need to go and focus on this new kind of attack factor and this new kind of threat that targets these different types of assets, and companies like ours are the ones that the industry has adopted to go.
And finally, I know, before I let you go, there are so many things to be concerned about, but there's that saying that there's nothing new under the sun.
So tell us what Blockade is focused on as we head into your end as well as 2027.
Our main focus has been with our customers and prospective customers, working with them day in and day out to ultimately harden their systems, protect them from all sorts of different threats, giving them visibility into their dependencies, giving them an understanding of what is unfolding on chain in real time, not just at a single point in time, but continuously, and really working with them to understand that audits and point in time checks aren't enough, but you need a kind of a system that goes and understands.
Everything that's happening across your on chain infrastructure to really go and harden everything and make sure that you are secure from these different types of threats.
And finally, before I let you go, you and I are actual human beings.
So in this day and age of AI autonomous agents, it's so key to remember that social engineering component when it comes to security.
So what would you say to viewers out there who are watching right now?
I think the same rules that crypto has always kind of instilled in us, which is trust but verify everything that it is that you do, use solutions like ours, use products that we embed in to go and understand the transactions that you're doing and go and understand the various different things that you're interacting with, and I think the age-old truth where if something seems too good to be true it probably is.
And of course you have access to all this data.
So when it comes to the social engineering side, where do a lot of these security breaches happen?
So I think a lot of the times these social engineering incidents take place when an individual at a company is compromised in some kind of way.
But ultimately in many cases when these things take place.
The company does not lose any assets and things like that and is able to kind of recover and contain the breach in a meaningful way.
Where these types of breaches unfold and kind of become catastrophic is when attackers are able to pivot and move within a network and the security controls aren't there to go and detect these things or prevent these things in meaningful ways.
And we saw this in two of the biggest kind of hacks of the year, both in Kelp and across drift, where individuals were compromised.
But in many other cases that we see across our customers, sometimes through social engineering individuals are compromised, but still the threat actor is not able to go and exfiltrate the funds in a meaningful way.
And so there's tons of cases where we've been able to detect these things, prevent them across our customer base, and embedding various different tools into.
Transaction flows into signing flows and or just identifying various different threats happening on chain enable you to really kind of contain these things in a meaningful way and so even if there's one small breach, the whole system doesn't unravel.
Well, a lot to keep in mind, so I appreciate your insights as well as your time Ida.
First, thank you so much.
Thank you so much.