Login
Sign Up
Woofun AI data shows that 67 security incidents in the Web3 sector resulted in $763.9 million in losses during Q2 2026, marking the most severe quarter since Q2 2025. Compromised keys and infrastructure were responsible for 88.3% of the total theft, amounting to approximately $674.5 million. Smart contract vulnerabilities were the most common attack type, linked to 44 of the 67 incidents, but accounted for only about 11% of the financial losses. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached.
Leo Fan, founder of Cysic, stated that audits provide a point-in-time assessment of specific codebases and do not automatically cover signature devices, cloud infrastructure, or operational permissions. Samuel Videau, CTO of Genius, noted that nearly 90% of losses originated from compromised keys, signers, and infrastructure. Security leaders emphasized the need for layered defenses, including real-time monitoring and multi-party authorization. Leo Fan expects operational access control attacks to continue dominating losses in the second half of 2026.