GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Regulation/Compliance

News linked to both this project and an event.

2026 Q2 Web3 Security Incidents: $764 Million Stolen, 88.3% from Compromised Keys and Infrastructure

According to the quarterly Security and Compliance Report by Hacken, 67 security incidents in the Web3 space resulted in losses of $763.9 million in Q2 2026, making it the most severe quarter since Q2 2025. Compromised keys and infrastructure accounted for 88.3% of the stolen funds, approximately $674.5 million. Smart contract vulnerabilities remained the most common type of attack, linked to 44 out of the 67 incidents, but corresponding losses represented only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached during the quarter. Leo Fan, founder of Cysic, stated that an audit is a point-in-time assessment of a specific codebase and does not automatically cover signature devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or old contracts that remain callable. Samuel Videau, CTO of Genius, pointed out that nearly 90% of losses came from compromised keys, signers, and infrastructure. Multiple security leaders noted that Web3 security requires layered defenses including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan expects that operational access control attacks will continue to dominate losses in the second half of 2026, including social engineering, credential theft, compromised signers, cloud or CI/CD intrusions, and attacks on off-chain validator infrastructure.

Approximately $764 million stolen from crypto projects in Q2, with 88.3% involving keys, signers, and infrastructure

in its Q2 2026 Security and Compliance Report, Hacken stated that institutional investors are expanding their due diligence scope from smart contract audits to continuous monitoring, signer control, and incident response preparedness. Among the 1,427 projects it tracked, only 9% had third-party monitoring, and 4% had monitoring, active bug bounties, and security audits simultaneously. The report shows that of the approximately $764 million stolen in Q2, 88.3% involved compromised keys, signers, and infrastructure.Hacken noted that 14 projects attacked in Q2 had previously completed audits, but most of the losses originated from areas outside the scope of traditional smart contract reviews. The report states that the affected components included signing devices, cross-chain bridge validators, backend infrastructure, admin keys, and deprecated but still active old contracts. The sample covered 1,427 projects with a market cap exceeding $1 million, listed among the top 50 centralized exchanges on the CoinGecko Trust Score, excluding wrapped assets, stablecoins, and tokenized real-world assets.

In Q1 2026, Web3 projects lost over $460 million due to hacking and scams, with phishing attacks dominating.

According to Cointelegraph, Hacken, a blockchain security firm, released its Q1 2026 report revealing that Web3 projects suffered $464.5 million in losses due to hacking and scams during the quarter. Phishing and social engineering attacks accounted for $306 million—making them the primary source of losses. A hardware wallet scam in January alone caused $282 million in losses, representing 81% of the quarter’s total losses. Smart contract vulnerabilities led to $86.2 million in losses, while failures in access control—including compromised private keys and cloud services—resulted in $71.9 million in losses. The report notes that the largest security incidents predominantly occurred in off-chain operations and infrastructure layers—areas typically beyond the scope of traditional audits. Europe’s regulatory frameworks, MiCA and DORA, are increasingly imposing stricter requirements on security monitoring and incident response, and global regulators are also raising standards for real-time monitoring and emergency response.