Hacken's quarterly security and compliance report said Web3 suffered 67 security incidents in the second quarter of 2026, with stolen funds reaching $763.9 million, the worst quarter since the second quarter of 2025. According to Odaily, key and infrastructure compromises accounted for 88.3% of stolen funds, or about $674.5 million.
Smart contract flaws remained the most common attack type, with 44 of the 67 incidents linked to them, although they accounted for about 11% of total losses. About 75.5% of losses came from two incidents attributed to North Korean threat actors, and 14 audited protocols were compromised during the quarter.
Cysic founder Leo Fan said audits are scope assessments of a specific codebase at a specific point in time and do not automatically cover signing devices, cloud infrastructure, operational permissions, later upgrades, third-party dependencies, or older contracts that remain callable. Genius CTO Samuel Videau said nearly 90% of losses came from keys, signers, and infrastructure.
Several security executives said Web3 security needs layered defenses that include real-time monitoring, key management, multi-party authorization, and bug bounties. Leo Fan said attacks on operational access controls are likely to continue leading losses in the second half of 2026, including social engineering, credential theft, compromised signers, cloud or CI/CD intrusions, and attacks on off-chain validator infrastructure.
Web3 Losses Reach $763.9 Million in 2026's Second Quarter, Hacken Says
2026-07-23 11:44:08
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
Previous article:
美国航空CEO:正应对石油价格巨大波动Next article:
UBS: U.K. Inflation May Peak at 3.3% in November