If you carry Professional code By now, you already know the feeling: chart update, X update, waiting for the team to say literally anything.
Somewhere on Ethereum, a scalper has approximately $8.2 million worth of USDT while the project behind the depleted token remains completely silent. This scene has become almost routine in 2026, a year that just witnessed the worst six months for serial security the industry has ever recorded.
Blockaid’s exploit detection system detected this issue in real time. Whether the team behind it will be able to catch up with its own community remains an open question, and if you’ve caught on here, that silence is probably the most frustrating part.

One of the active exploits accesses the Pro Token, and the team remains silent
Blockaid Monitoring Systems reported an ongoing exploit targeting Pro Code, a project associated with the @CryptoDAOGlobal account, in an alert detailed in a social media thread. The security firm’s tracking shows roughly $8.2 million worth of USDT currently sitting between the scalper’s wallet and a group of addresses that appear to have been won early on. attacks, Whether by pre-running the exploit or simply taking advantage of the ensuing chaos.
As of this writing, the CryptoDAOGlobal team has not issued a statement, post-mortem, or even a basic admission that anything went wrong. For coin holders monitoring their token chart in real time, this silence is arguably its own kind of red flag, and fits a pattern that security researchers have been pointing out all year: Teams are increasingly discovering their own exploits from the security company’s public alert before they find out internally. If you’re one of these carriers, you’re not overreacting out of anxiety. You just pay attention faster than the project.
Inside the drain is $8.2 million
Live exploit alerts like this follow a familiar format, and once you’ve seen a few of them, you start to get the rhythm. A security system designed to monitor onchain activity around the clock detects unusual contract behavior, minting patterns, or money movements within minutes, and sometimes seconds, of the first transaction.

Blockaid has built its reputation by doing exactly this kind of real-time detection, and its track record this year includes detecting everything from bridge exploits to governance takeovers before the broader cryptocurrency community even noticed the chain had moved. The Pro Token case falls into the same category: an active, unresolved exploit, a dollar figure that keeps the community committed to banning explorers, and a project team that went out of business at the moment its holders needed answers most. Until CryptoDAOGlobal responds, the $8.2 million currently in the scalper’s wallet and the associated winning addresses represent the clearest public record of what happened, which speaks volumes about where the accountability gap in the industry still exists.
Standard first half of Onchain crimes
Zoom out of any one incident, and the bigger picture quickly becomes bleak and, frankly, a bit stressful if you’re holding crypto through it. Blockaid’s research arm verified 212 separate security incidents during the first half of 2026 alone, a volume 3.4 times higher than what was recorded during all of 2025.
Total verified losses for the period were around $1.1 billion, with Ethereum and Solana absorbing the bulk of the damage, according to details shared in the recent crash. To put this pace in perspective, an industry that used to measure major exploits by the dozens per year now dumps the same number roughly every few weeks. If you feel like your timeline has been constant exploit alerts lately, it’s not just you. The data supports this gut feeling.
Why does operational encryption dry, but not code?
This is a finding that should reshape how every project, and every person who trusts a project with their money, thinks about security: 74% of all money stolen in the first half of 2026 did not come from a smart contract error at all. They came from operational security failures, compromised private keys, hijacked signer infrastructure, and social engineering that tricked an insider into agreeing to something they shouldn’t have.

Code audits, once treated as the bottom line of security, are increasingly capturing a smaller share of the problem. The biggest and most costly failures happen around the code, in the humans and processes that hold the keys to it. This should change how you evaluate a project before you start it, too. A clean audit badge on a landing page tells you almost nothing about whether the team’s laptop, multisig workspace, or Slack is the actual weak point.
The DPRK group is behind more than half of the first half’s losses
Attribution data from the same period indicate that a single actor group caused a large share of the damage. Blockaid’s research pegs North Korea-linked operators with 55% of all first-half 2026 losses, a concentration that’s in line with what other blockchain security firms have reported separately this year about the scale of cryptocurrency thefts in Pyongyang. These are not smash and grab hacks.
The pattern the researchers go on to describe involves patient and methodical campaigns: bogus job offers targeting developers, impersonating venture capital outreach, and compromising trusted infrastructure long before a single dollar moves. It’s worth sitting with that for a second. The team behind your token may have already experienced a compromised employee recruitment process months before anyone noticed anything was wrong.
What does Blockaid expect attackers to expand on next?
The forward-looking part of Blockaid’s research is arguably the most useful to anyone building or holding cryptocurrencies right now, including you. The company’s team has flagged a set of newer attack vectors that are expected to expand during the second half of 2026, patterns that have appeared in isolated incidents so far but have not yet become industry-wide trends. Given the speed with which the prevailing tactics this year, operational compromises and infrastructure targeting, have gone from fringe cases to the majority of funds stolen, these expectations carry real weight. If the first half of 2026 has taught the industry anything, it’s that the next wave of losses probably won’t look like the last one, which means the questions worth asking about any project you’re working on aren’t just “has the code been audited,” but “who has the keys, and how will I know if that changes.”
Currently, the Pro Token exploit remains active and unsolved, CryptoDAOGlobal remains quiet, and approximately $8.2 million is stuck between the exploiter’s wallet and addresses that previously appeared. It’s a small case study within a much larger story: an industry that continues to build faster than it can be secured, and a threat landscape that continually proves to pay close attention to exactly where vulnerabilities exist. If you’re holding anything now, it might be worth remembering next time the team gets quiet after the chart starts moving in the wrong direction.
Disclosure: This is not trading or investment advice. Always do your research before purchasing any cryptocurrency or investing in any services.
Follow us on Twitter @themerklehash To stay up to date on the latest Crypto, NFT, AI, Cybersecurity, and Metaverse news!





