{"id":122636,"date":"2026-07-29T11:02:12","date_gmt":"2026-07-29T11:02:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122636\/"},"modified":"2026-07-29T11:02:12","modified_gmt":"2026-07-29T11:02:12","slug":"crypto-hacks-hit-all-time-high-as-north-korea-drains-over-600m-and-ai-agents-become-new-target","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122636\/","title":{"rendered":"Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target"},"content":{"rendered":"<p>Cryptocurrency projects recorded more verified hacks in the first six months of 2026 than in any previous full year, with 212 separate exploit incidents generating over $1.1 billion in losses \u2014 and North Korea&#8217;s state-sponsored hacking apparatus responsible for roughly 55% of every dollar stolen, with most of that total taken in a 17-day window in April. That figure comes from <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/409944\/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says\" target=\"_blank\">Blockaid&#8217;s H1 2026 Security Report<\/a>, published Tuesday, which confirmed the <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/409944\/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says\" target=\"_blank\">six-month incident count was 3.4 times<\/a> what the firm recorded across all of 2025. Exchange rate note: all figures are denominated in USD; no currency conversions required.<\/p>\n<p>The numbers are not a blip. Three independent security firms \u2014 Immunefi, Quill Audits, and TRM Labs \u2014 each published <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/407707\/crypto-hack-losses-fall-below-1-billion-in-h1-2026-even-as-attack-volume-hits-record-immunefi\" target=\"_blank\">corroborating analyses<\/a> using different methodologies, and all three reached the same conclusion: the first half of 2026 set the highest-ever six-month incident count on record. The firms&#8217; dollar estimates vary (Blockaid at $1.1 billion, Immunefi at $972 million, Quill Audits at $935.3 million) because they apply different thresholds for what constitutes a verified incident \u2014 but all three agree on the direction.<\/p>\n<p>What Blockaid&#8217;s report reveals is that the nature of successful attacks has fundamentally changed. Code vulnerabilities in smart contracts \u2014 the failure mode that drove most earlier DeFi losses \u2014 are no longer the primary vector. Instead, attackers are exploiting the humans who control protocols, the infrastructure that bridges trust between blockchains, and now the artificial intelligence agents given authority to move money on behalf of users.<\/p>\n<p>North Korea Stole Over $600M in 17 Days \u2014 Without Finding a Single Bug<\/p>\n<p>North Korea&#8217;s Lazarus Group and its subunits took <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/409944\/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says\" target=\"_blank\">roughly 55% of all H1 losses<\/a> \u2014 approximately $609 million \u2014 through attacks that occurred in a concentrated 17-day window in April 2026. The two largest individual attacks, Drift Protocol ($285 million) and KelpDAO ($292 million), together account for $577 million of that total. Neither attack required finding a vulnerability in any smart contract. Both required finding the humans who could authorize the transactions \u2014 and then systematically deceiving them.<\/p>\n<p>TRM Labs, analyzing the first four months of 2026, found that North Korean state-sponsored hackers were responsible for <a rel=\"nofollow noopener\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks\" target=\"_blank\">76% of all cryptocurrency hack value<\/a> in that period. The group&#8217;s documented history of crypto theft now exceeds more than $6 billion since 2017, including the <a rel=\"nofollow noopener\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks\" target=\"_blank\">$1.5 billion Bybit breach<\/a> in February 2025 that remains the largest single cryptocurrency theft in history.<\/p>\n<p>Drift Protocol: How a Six-Month Con Emptied $285 Million in 12 Minutes<\/p>\n<p>The Drift Protocol attack, which drained approximately $285 million from the Solana-based perpetual futures exchange on April 1, 2026, <a rel=\"nofollow noopener\" href=\"https:\/\/thehackernews.com\/2026\/04\/285-million-drift-hack-traced-to-six.html\" target=\"_blank\">began in the autumn of 2025<\/a> \u2014 six months before a single dollar was moved.<\/p>\n<p>Threat actors affiliated with the DPRK subunit UNC4736 (also tracked under the names AppleJeus, Citrine Sleet, and Golden Chollima) posed as representatives of a legitimate quantitative trading firm. They met Drift contributors at an industry conference, built credibility over months through Telegram conversations and live vault integration sessions, and <a rel=\"nofollow noopener\" href=\"https:\/\/thehackernews.com\/2026\/04\/285-million-drift-hack-traced-to-six.html\" target=\"_blank\">deposited more than $1 million of their own capital<\/a> into the protocol to demonstrate seriousness.<\/p>\n<p>The technical mechanism that made the April 1 execution possible was <a rel=\"nofollow noopener\" href=\"https:\/\/www.chainalysis.com\/blog\/lessons-from-the-drift-hack\/\" target=\"_blank\">Solana&#8217;s durable nonce feature<\/a>. Unlike standard Solana transactions, which must reference a recent block hash and expire within roughly two minutes, durable nonce transactions can be created and stored indefinitely before execution. The attackers used this feature to pre-authorize administrative transactions months before acting on them \u2014 transactions that appeared cryptographically legitimate because they were.<\/p>\n<p>By March 2026, the group had socially engineered at least two of five Drift Security Council multisig signers into pre-signing malicious transactions using that mechanism. When April 1 arrived, the attackers used those stored authorizations to <a rel=\"nofollow noopener\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/north-korean-hackers-attack-drift-protocol-in-285-million-heist\" target=\"_blank\">seize Security Council administrative powers in approximately 12 minutes<\/a>, draining more than $285 million across multiple tokens before the protocol could respond. They then deposited a worthless fabricated token as collateral, withdrew real assets including USDC, SOL, and ETH, and bridged most funds to Ethereum within hours. The vaults were largely empty before any alarm was raised.<\/p>\n<p>As of July 23, 2026 \u2014 three months after the exploit \u2014 a wallet linked to the Drift attacker <a rel=\"nofollow noopener\" href=\"https:\/\/crypto.news\/drift-exploiter-moves-44m-through-tornado-cash-after-months\/\" target=\"_blank\">moved 23,095.1 ETH (worth approximately $44.4 million at the time of transfer)<\/a> through Tornado Cash, the crypto mixer, over a two-day window. The bulk of the stolen funds remain unrecovered.<\/p>\n<p>KelpDAO: When One Verifier Is All North Korea Needs<\/p>\n<p>Seventeen days after the Drift attack, on April 18, 2026, Lazarus Group&#8217;s TraderTraitor subunit struck KelpDAO&#8217;s rsETH bridge on the LayerZero protocol, <a rel=\"nofollow noopener\" href=\"https:\/\/www.openzeppelin.com\/news\/lessons-from-kelpdao-hack\" target=\"_blank\">draining approximately $292 million \u2014 116,500 rsETH \u2014 in under 46 minutes<\/a>.<\/p>\n<p>This attack required no social engineering. It required only that a single verifier stand between an attacker and $292 million \u2014 and it did.<\/p>\n<p>LayerZero&#8217;s cross-chain messaging protocol allows applications to configure how many independent Decentralized Verifier Networks (DVNs) must confirm a transaction before the destination chain accepts it. KelpDAO&#8217;s rsETH bridge was configured to require confirmation from just one DVN: LayerZero Labs itself. With no second verifier to catch a forged message, attackers needed only to <a rel=\"nofollow noopener\" href=\"https:\/\/www.openzeppelin.com\/news\/lessons-from-kelpdao-hack\" target=\"_blank\">compromise LayerZero Labs&#8217; verification infrastructure<\/a> \u2014 and they did, by gaining access to two RPC nodes the LayerZero Labs DVN used to read source-chain state, replacing the software with malicious versions that reported fabricated data.<\/p>\n<p>A simultaneous distributed denial-of-service attack against external backup nodes forced LayerZero&#8217;s verifier to rely on the compromised infrastructure. The forged data convinced the Ethereum contract that a legitimate token burn had occurred on the source chain \u2014 releasing 116,500 rsETH to an attacker-controlled address. The rsETH smart contract was never exploited. No cryptographic primitive was broken. As OpenZeppelin&#8217;s post-mortem headline put it: &#8220;<a rel=\"nofollow noopener\" href=\"https:\/\/www.openzeppelin.com\/news\/lessons-from-kelpdao-hack\" target=\"_blank\">zero bugs found<\/a>.&#8221;<\/p>\n<p>What the Blockaid report and subsequent forensic analyses revealed about the aftermath is as important as the attack itself: LayerZero&#8217;s own investigation found that <a rel=\"nofollow noopener\" href=\"https:\/\/thedefiant.io\/news\/security\/dune-layerzero-oapp-dvn-security-analysis-1bklaq\" target=\"_blank\">47% of active OApp contracts on its protocol were running the same 1-of-1 DVN configuration<\/a> at the time of the KelpDAO exploit. In a May 9 statement, <a rel=\"nofollow noopener\" href=\"https:\/\/thedefiant.io\/news\/security\/layerzero-labs-security-incident-multisig-violation-rjuv1s\" target=\"_blank\">LayerZero acknowledged that it had &#8220;made a mistake by allowing our DVN to act as a 1\/1 DVN for high-value transactions&#8221;<\/a> \u2014 reversing three weeks of statements that had assigned the configuration choice entirely to KelpDAO. LayerZero has since announced it will refuse to sign messages for any application still running a 1-of-1 configuration, and has raised its protocol default to <a rel=\"nofollow noopener\" href=\"https:\/\/thedefiant.io\/news\/security\/layerzero-labs-security-incident-multisig-violation-rjuv1s\" target=\"_blank\">at least 3-of-3 verifiers<\/a>.<\/p>\n<p>KelpDAO, for its part, has migrated rsETH bridging from LayerZero&#8217;s OFT standard to <a rel=\"nofollow noopener\" href=\"https:\/\/www.coindesk.com\/web3\/2026\/05\/05\/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack\" target=\"_blank\">Chainlink&#8217;s Cross-Chain Interoperability Protocol<\/a>, which requires consensus from at least 16 independent verifiers before any cross-chain message is accepted.<\/p>\n<p>Ethereum and Solana: Where the Money Went<\/p>\n<p>Tracking losses by blockchain, Blockaid found <a rel=\"nofollow noopener\" href=\"https:\/\/cointelegraph.com\/news\/ethereum-solana-led-crypto-hack-losses-h1-2026-blockaid\" target=\"_blank\">Ethereum projects absorbed the largest aggregate losses in H1 2026 at $332 million, while Solana \u2014 driven almost entirely by the Drift attack \u2014 took $326 million<\/a>. Solana&#8217;s figure represents a dramatic escalation from the <a rel=\"nofollow noopener\" href=\"https:\/\/cointelegraph.com\/news\/ethereum-solana-led-crypto-hack-losses-h1-2026-blockaid\" target=\"_blank\">approximately $127 million the network sustained across all of 2025<\/a>.<\/p>\n<p>Ethereum&#8217;s losses reflected the density of high-value protocols on its network: restaking platforms, stablecoins, and DEX aggregators. Code exploits dominated by count, with key compromises at Humanity Protocol and StablR driving some of the largest individual losses. Blockaid also identified novel attack vectors during the period, including the first production exploit of Ethereum&#8217;s EIP-7702 wallet-delegation standard on Arbitrum and <a rel=\"nofollow noopener\" href=\"https:\/\/www.cryptotimes.io\/2026\/07\/29\/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid\/\" target=\"_blank\">two zero-knowledge proof boundary exploits on the Aztec network<\/a>.<\/p>\n<p>On-chain protocols were the largest overall loss category at $524 million. Cross-chain bridges were <a rel=\"nofollow noopener\" href=\"https:\/\/www.fxstreet.com\/cryptocurrencies\/news\/crypto-hacks-hit-record-high-with-212-exploits-in-h1-2026-202607290212\" target=\"_blank\">second at $372 million<\/a> \u2014 a figure that includes the KelpDAO incident and code exploits at Verus, Taiko, Alephium, Secret, Axelar, Swapnet, and Syscoin.<\/p>\n<p>How Attackers Are Using AI \u2014 and a Milestone No One Wanted<\/p>\n<p>The most structurally novel finding in Blockaid&#8217;s report is not a number. It is a single incident from May 2026 that Blockaid described as &#8220;the first ever&#8221; AI agent exploit in the cryptocurrency space \u2014 a title no one would want \u2014 and its implications extend well beyond the $175,000 that changed hands.<\/p>\n<p>In early May 2026, an attacker targeted Bankr, an AI-powered crypto trading assistant that automatically generates crypto wallets for users on X who interact with its bot and executes transactions through natural language commands. The attack operated in two stages. First, the attacker gifted the target Bankr wallet a &#8220;Bankr Club Membership&#8221; NFT, which activated a high-privilege permission set including transfer authorization. Then, the attacker sent a message to xAI&#8217;s Grok chatbot encoded in Morse code \u2014 a format that bypassed <a rel=\"nofollow noopener\" href=\"https:\/\/slowmist.medium.com\/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73\" target=\"_blank\">Grok&#8217;s safety filters<\/a>, which screen for obvious financial instructions in plain text.<\/p>\n<p>Grok decoded the Morse code, as it was designed to do, and tagged @bankrbot in its public reply. Bankr&#8217;s system treated Grok&#8217;s public output as a trusted executable command \u2014 with no verification that the reply represented Grok&#8217;s own intent rather than the output of an adversarial input. The system autonomously transferred approximately 3 billion DRB tokens, worth <a rel=\"nofollow noopener\" href=\"https:\/\/slowmist.medium.com\/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73\" target=\"_blank\">approximately $175,000 at the time<\/a>, to the attacker&#8217;s wallet.<\/p>\n<p>SlowMist formally classified the incident as an <a rel=\"nofollow noopener\" href=\"https:\/\/slowmist.medium.com\/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73\" target=\"_blank\">&#8220;AI agent permission chain abuse&#8221;<\/a> attack \u2014 a category in which one AI system&#8217;s output is treated as trusted financial authorization by a second AI system, with no independent verification of intent or source. SlowMist&#8217;s recommendations were direct: natural language outputs from AI systems must be <a rel=\"nofollow noopener\" href=\"https:\/\/slowmist.medium.com\/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73\" target=\"_blank\">&#8220;strictly decoupled&#8221;<\/a> from financial execution; high-value operations require multi-factor verification and anomaly detection; inter-agent interactions should use structured, verifiable protocols rather than plain text.<\/p>\n<p>Blockaid projected in its H1 report that AI agent deployments are <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/409944\/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says\" target=\"_blank\">growing roughly ten times per year<\/a>, and that the industry should expect multiple AI agent incidents in H2 2026, with prompt injection attacks leading and tool-use abuse and unauthorized signing following.<\/p>\n<p>What Blocks Traditional Security Tools From Catching These Attacks<\/p>\n<p>Each of the three major attack categories documented in Blockaid&#8217;s H1 report shares a single defining characteristic: every transaction looked completely valid to on-chain monitoring tools.<\/p>\n<p>In the Drift exploit, the malicious administrative transactions were pre-authorized by legitimate keyholders using legitimate Solana cryptography. No blockchain monitor could detect the authorization was obtained through six months of social engineering rather than genuine governance. In the KelpDAO attack, the forged cross-chain message passed through verification infrastructure that LayerZero&#8217;s own DVN had already been manipulated into treating as authentic \u2014 meaning the on-chain record showed a valid attestation. In the Bankr exploit, Grok decoded a real Morse code message, produced a real output, and tagged a real bot. Bankr executed a real transaction. Every individual step in the chain was authentic; only the chain as a whole was adversarial.<\/p>\n<p>Blockaid warned that the multisig signer compromise pattern \u2014 &#8220;LinkedIn social engineering leading to multisig signer compromise&#8221; \u2014 produced two of the four largest H1 incidents and that there is <a rel=\"nofollow noopener\" href=\"https:\/\/www.theblock.co\/post\/409944\/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says\" target=\"_blank\">&#8220;no structural reason for it to stop.&#8221;<\/a> SlowMist separately confirmed that attackers across the crypto space have begun <a rel=\"nofollow noopener\" href=\"https:\/\/slowmist.medium.com\/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73\" target=\"_blank\">deploying AI tools including ChatGPT and Cursor<\/a> to write exploit code, craft more convincing social engineering narratives, and optimize attack sequencing.<\/p>\n<p>What H2 2026 Looks Like<\/p>\n<p>Blockaid&#8217;s forward outlook for the second half of 2026 identifies three primary threat categories: the continuation of DPRK-linked social engineering campaigns targeting multisig signers and bridge verification infrastructure; the proliferation of AI agent exploits as autonomous financial agents become more common and more capable; and the exploitation of novel Ethereum primitives \u2014 EIP-7702 wallet delegation, ZK proof boundary conditions \u2014 that were introduced in production in H1 and whose attack surface is not yet fully understood.<\/p>\n<p>Recovery prospects for H1 losses are uneven. Incidents involving code bugs or operator error \u2014 rather than state-sponsored theft \u2014 sometimes see partial or full recovery. The $8.5 million Verus exploit resulted in significant fund recovery, and IPOR Fusion experienced a complete white-hat recovery. Blockaid itself participated in recovering <a rel=\"nofollow noopener\" href=\"https:\/\/www.cryptotimes.io\/2026\/07\/29\/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid\/\" target=\"_blank\">approximately $7.3 million (73%) from the Stellar Blend oracle manipulation incident<\/a> through real-time wallet clustering and cross-chain tracing.<\/p>\n<p>For the DPRK-linked losses, the prognosis is bleak. Lazarus Group has a documented track record of successfully laundering even large hauls \u2014 the Drift attacker&#8217;s July movement of $44.4 million through Tornado Cash confirmed that laundering operations are active and ongoing. For DeFi users, protocol developers, and anyone building AI agents with on-chain financial capabilities, the H1 2026 record is less a historical data point than a threat model for the months ahead.<\/p>\n<p>Frequently Asked QuestionsWhy does Blockaid&#8217;s $1.1 billion figure differ from other security firms&#8217; estimates?<\/p>\n<p>Three major security firms \u2014 Blockaid, Immunefi, and Quill Audits \u2014 all analyzed H1 2026 crypto losses and reached figures ranging from $935 million to $1.1 billion. The variation is methodological, not factual: each firm applies different thresholds for what qualifies as a &#8220;verified&#8221; incident, and each covers a different scope of protocols and blockchains. All three independently confirmed that H1 2026 set the highest-ever six-month incident count on record.<\/p>\n<p>How did the Bankr AI agent get hacked without anyone breaking into a wallet or smart contract?<\/p>\n<p>The Bankr exploit worked by manipulating the trust relationship between two AI systems rather than breaking into either one. The attacker sent Grok a Morse-code encoded financial instruction; Grok decoded it and posted the result publicly; Bankr&#8217;s system treated Grok&#8217;s public output as a valid command and executed a token transfer. No private key was compromised and no smart contract was exploited \u2014 the only failure was that Bankr was designed to treat another AI&#8217;s output as trusted financial authorization without verifying that the output represented genuine intent rather than adversarial manipulation. SlowMist classifies this as &#8220;AI agent permission chain abuse,&#8221; and recommends that AI agents with financial capabilities require multi-factor verification and human approval for all high-value transfers.<\/p>\n<p>How did North Korea steal hundreds of millions without finding any code vulnerabilities?<\/p>\n<p>Both major DPRK-linked April attacks exploited trust rather than code. In the Drift attack, threat actors spent six months building personal relationships with protocol governance participants, ultimately inducing multisig signers to pre-authorize malicious transactions using a legitimate Solana feature. In the KelpDAO attack, they compromised the off-chain server infrastructure that LayerZero&#8217;s verification layer relied on to confirm cross-chain transactions \u2014 manipulating the verifier rather than the protocol&#8217;s own code. When a bridge relies on a single verifier, compromising that one verifier is sufficient to authorize arbitrary cross-chain transfers. No smart contract audit would have caught either attack.<\/p>\n<p>What should DeFi users and developers do differently after H1 2026?<\/p>\n<p>Developers building on cross-chain bridges should require multi-verifier configurations \u2014 post-KelpDAO, LayerZero now mandates a minimum of three independent verifiers. Protocols using multisig governance should treat all new contributors who request signing access with extended verification periods and compartmentalized access. AI agents with any on-chain financial capability should require explicit human confirmation before executing transfers above a defined threshold, and should not treat the output of third-party AI systems as trusted financial instructions. Users investing in DeFi protocols should verify their bridge architecture and whether a protocol&#8217;s governance has recently onboarded new multisig signers with limited track records.<\/p>\n","protected":false},"excerpt":{"rendered":"Cryptocurrency projects recorded more verified hacks in the first six months of 2026 than in any previous full&hellip;\n","protected":false},"author":2,"featured_media":122637,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61903,405,7537,38747,56136,61901,3277,61904,61902,6296],"class_list":["post-122636","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agent-exploit","tag-ai-agents","tag-artificial-intelligence-agents","tag-blockaid","tag-blockchain-security","tag-crypto-hack-2026","tag-cryptocurrency","tag-defi-security","tag-lazarus-group","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122636"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122636\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/122637"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}