BTC
ETH
HTX
SOL
BNB
ดูตลาด
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

2026 Q2 Web3 Security Incidents: $764 Million Stolen, 88.3% from Key and Infrastructure Compromises

2026-07-23 11:34
Odaily Odaily News: Hacken's quarterly security and compliance report reveals that in Q2 2026, stolen funds from 67 security incidents in the Web3 sector reached $763.9 million, making it the most severe quarter since Q2 2025. Key and infrastructure compromises accounted for 88.3% of stolen funds, approximately $674.5 million.

Smart contract vulnerabilities remained the most common attack type, linked to 44 of the 67 incidents, but corresponding losses accounted for about 11% of the total. Approximately 75.5% of losses came from two incidents attributed to North Korean threat actors. 14 audited protocols were breached during the quarter.

Leo Fan, founder of Cysic, stated that an audit is a scope assessment of a specific codebase at a specific point in time and does not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or old contracts that are still callable. Genius CTO Samuel Videau pointed out that nearly 90% of losses came from keys, signers, and infrastructure.

Several security leaders stated that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan expects that operational access control attacks will continue to dominate losses in the second half of 2026, including social engineering, credential theft, compromised signers, cloud or CI/CD intrusions, and off-chain validator infrastructure attacks.
ค้นหา
ดาวน์โหลดแอพ Odaily พลาเน็ตเดลี่
ให้คนบางกลุ่มเข้าใจ Web3.0 ก่อน
IOS
Android