Web3 Q2 2026 Losses Hit $764M, 88.3% From Compromised Keys
2026-07-23 19:34

Woofun AI data shows that 67 security incidents in the Web3 sector resulted in $763.9 million in losses during Q2 2026, marking the most severe quarter since Q2 2025. Compromised keys and infrastructure were responsible for 88.3% of the total theft, amounting to approximately $674.5 million. Smart contract vulnerabilities were the most common attack type, linked to 44 of the 67 incidents, but accounted for only about 11% of the financial losses. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached.

Leo Fan, founder of Cysic, stated that audits provide a point-in-time assessment of specific codebases and do not automatically cover signature devices, cloud infrastructure, or operational permissions. Samuel Videau, CTO of Genius, noted that nearly 90% of losses originated from compromised keys, signers, and infrastructure. Security leaders emphasized the need for layered defenses, including real-time monitoring and multi-party authorization. Leo Fan expects operational access control attacks to continue dominating losses in the second half of 2026.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
Leo Fan
Samuel Videau
Hacken
Cysic
Genius
Share:
back