$764 million stolen in Web3 security incidents in Q2 2026, with 88.3% stemming from key and infrastructure compromises
Show original
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold. Trade now!
A welcome pack worth 6200 USDT for new users! Sign up now!
Odaily reported that Hacken’s quarterly security and compliance report shows that in Q2 2026, the Web3 sector suffered 67 security incidents, with stolen funds reaching 763.9 million US dollars—the most severe quarter since Q2 2025. Compromised keys and infrastructure accounted for 88.3% of the stolen funds, approximately 674.5 million US dollars.
Smart contract vulnerabilities remain the most common attack type, with 44 out of 67 incidents related to them. However, losses from these accounted for only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached this quarter.
Leo Fan, founder of Cysic, stated that an audit is a scope assessment of a specific codebase at a particular time and does not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that can still be invoked. Genius CTO Samuel Videau pointed out that nearly 90% of losses come from keys, signers, and infrastructure.
Several security leaders noted that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan anticipates that the second half of 2026 will continue to see operational access control attacks dominating losses, including social engineering, credential theft, signer compromise, cloud or CI/CD breaches, and attacks on off-chain validator infrastructure.
Smart contract vulnerabilities remain the most common attack type, with 44 out of 67 incidents related to them. However, losses from these accounted for only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached this quarter.
Leo Fan, founder of Cysic, stated that an audit is a scope assessment of a specific codebase at a particular time and does not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that can still be invoked. Genius CTO Samuel Videau pointed out that nearly 90% of losses come from keys, signers, and infrastructure.
Several security leaders noted that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan anticipates that the second half of 2026 will continue to see operational access control attacks dominating losses, including social engineering, credential theft, signer compromise, cloud or CI/CD breaches, and attacks on off-chain validator infrastructure.
0
0
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!
You may also like
Humanity Protocol rises 11% as longs control 66% of Open Interest – $0.169 in focus
AMBCrypto•2026/09/13 07:03

Analyst Says XRP Is Two Major Breakouts Away
TimesTabloid•2026/09/13 07:03

XRP Army Reacts As Pundit Says Bitcoin Will Pump But XRP Will Go Parabolic
TimesTabloid•2026/09/13 06:03
Crypto prices
MoreBitcoin
BTC
$77,150.2
-0.22%
Ethereum
ETH
$2,514.15
-0.38%
Tether USDt
USDT
$0.9997
-0.00%
BNB
BNB
$722.49
-1.34%
XRP
XRP
$1.36
-0.23%
USDC
USDC
$0.9998
-0.00%
Solana
SOL
$101.32
-0.42%
TRON
TRX
$0.3398
+0.25%
Hyperliquid
HYPE
$78.9
-0.02%
Zcash
ZEC
$1,140.81
-0.17%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now