Institutional Web3 Market Shifts to Continuous Security Verification
Institutional participants in the digital asset market are relying less on one time security audits and increasingly on continuous verification of system, infrastructure, and operational security, as losses tied to code vulnerabilities accounted for only about 11% of total damages from security incidents.
Web3 cybersecurity firm Hacken recorded 67 security incidents in Q2 2026, with total losses reaching $763.97 million. The company found that 88.3% of stolen funds resulted from compromised keys, signers, and infrastructure rather than coding errors. Against this backdrop, Hacken observed a shift in how institutional market participants assess trust, with firms moving toward continuous verification of their systems’ security posture.
According to the report, the quarter was the most severe for the Web3 industry since Q2 2025. Total losses increased 58.3% from Q1 2026, when they stood at $482.7 million, and declined 25.9% compared with Q2 2025. Smart contract vulnerabilities remained the most common type of incident, accounting for 44 of the 67 cases. However, they caused just $87.7 million in losses, or about 11% of the total.
The largest incidents stemmed from infrastructure failures and operational issues. The biggest cases included:
- KelpDAO: $292 million
- Drift Protocol: $285 million
- Humanity Protocol: $31 million
Hacken also highlighted the first confirmed case of a prompt injection attack that resulted in unauthorized fund transfers involving the Grok AI agent and the Bankr platform, ultimately leading to the transfer of tokens worth approximately $174,000.
The report emphasized that traditional trust signals, including completed security audits, a project’s operating history, and high total value locked, didn’t prove to be reliable indicators of risk. The affected projects included both platforms that underwent multiple security audits and projects with years of operating history. Against this backdrop, Hacken argued for a broader approach to security that considers not only code reliability, but also the resilience of critical infrastructure and essential third party components, along with the effectiveness of monitoring, incident response readiness, and the ability to withstand operational disruptions.
Just days ago, CoinsPaid Media published a new episode of the Money Rewired podcast, in which Hacken CEO and Co-Founder Yev Broshovan discussed how cybersecurity for Web3 projects is evolving as real world institutional use cases continue to expand.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
On the eve of the 5% threshold, the U.S. Treasury sell-off presents a tough challenge for the market and the Federal Reserve
A sell-off in the bond market has pushed a key U.S. Treasury yield close to 5%, heightening concerns from Wall Street to Washington about the impact of rising borrowing costs on the U.S. economy.

McDonald’s Corporation stock hits 52-week low as dividend yield hits 6-year high

Filecoin Crypto’s RSI Hits 84 as Timeframes Send Mixed Signals

Bitcoin’s 4-year cycle faces scrutiny as ETF inflows reshape price behavior
