$764 million stolen in Web3 security incidents in Q2 2026, with 88.3% stemming from key and infrastructure compromises
Show original
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold. Trade now!
A welcome pack worth 6200 USDT for new users! Sign up now!
Odaily reported that Hacken’s quarterly security and compliance report shows that in Q2 2026, the Web3 sector suffered 67 security incidents, with stolen funds reaching 763.9 million US dollars—the most severe quarter since Q2 2025. Compromised keys and infrastructure accounted for 88.3% of the stolen funds, approximately 674.5 million US dollars.
Smart contract vulnerabilities remain the most common attack type, with 44 out of 67 incidents related to them. However, losses from these accounted for only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached this quarter.
Leo Fan, founder of Cysic, stated that an audit is a scope assessment of a specific codebase at a particular time and does not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that can still be invoked. Genius CTO Samuel Videau pointed out that nearly 90% of losses come from keys, signers, and infrastructure.
Several security leaders noted that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan anticipates that the second half of 2026 will continue to see operational access control attacks dominating losses, including social engineering, credential theft, signer compromise, cloud or CI/CD breaches, and attacks on off-chain validator infrastructure.
Smart contract vulnerabilities remain the most common attack type, with 44 out of 67 incidents related to them. However, losses from these accounted for only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached this quarter.
Leo Fan, founder of Cysic, stated that an audit is a scope assessment of a specific codebase at a particular time and does not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that can still be invoked. Genius CTO Samuel Videau pointed out that nearly 90% of losses come from keys, signers, and infrastructure.
Several security leaders noted that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan anticipates that the second half of 2026 will continue to see operational access control attacks dominating losses, including social engineering, credential theft, signer compromise, cloud or CI/CD breaches, and attacks on off-chain validator infrastructure.
0
0
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!
You may also like
Bitcoin Supply Trend Flashes Warning: Exchange Reserves Climb Above 200D SMA
DailyCoin•2026/08/16 13:42
Foreign media: US stablecoin yield dispute once again impacts legislation
币界网•2026/08/16 13:14

'Make RLUSD Great Again': Ex-Ripple Engineer Teases Secret XRP Ledger Startup
UToday•2026/08/16 11:33
Crypto prices
MoreBitcoin
BTC
$62,996.64
+0.04%
Ethereum
ETH
$1,879.41
-0.12%
Tether USDt
USDT
$0.9989
-0.00%
USDC
USDC
$0.9999
+0.00%
XRP
XRP
$0.9994
-0.18%
Solana
SOL
$75.31
-0.24%
TRON
TRX
$0.3317
+0.21%
Hyperliquid
HYPE
$57.11
+1.16%
Dogecoin
DOGE
$0.06987
-0.26%
Zcash
ZEC
$486.56
-0.78%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now