星球日报
星球日报|7月 23, 2026 11:35
[In Q2 2026, $764 Million Stolen in Web3 Security Incidents, 88.3% Due to Key and Infrastructure Compromise] Odaily Planet Daily News – According to Hacken's quarterly security and compliance report, funds stolen in 67 Web3 security incidents in Q2 2026 amounted to $764 million, marking the most severe quarter since Q2 2025. Key and infrastructure compromises accounted for 88.3% of the stolen funds, approximately $674.5 million. Smart contract vulnerabilities remain the most common type of attack, with 44 out of the 67 incidents related to them, though the corresponding losses accounted for only about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were breached this quarter. Cysic founder Leo Fan stated that audits are scope assessments of specific codebases at a particular point in time and do not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that remain callable. Genius CTO Samuel Videau pointed out that nearly 90% of the losses were due to keys, signers, and infrastructure. Several security leaders emphasized that Web3 security requires layered defenses, including real-time monitoring, key management, multi-party authorization, and bug bounty programs. Leo Fan predicted that in the second half of 2026, operational access control attacks will continue to dominate losses, including social engineering, credential theft, signer compromise, cloud or CI/CD intrusions, and off-chain validator infrastructure attacks.
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads