Svmuu News: Hacken’s quarterly security and compliance report reveals that 67 security incidents in the Web3 sector during the second quarter of 2026 resulted in $763.9 million in stolen funds, marking the worst quarter since the second quarter of 2025. Compromised keys and infrastructure accounted for 88.3% of the stolen funds, totaling approximately $674.5 million.
Smart contract vulnerabilities remained the most common type of attack, accounting for 44 of the 67 incidents, though the corresponding losses represented about 11% of the total. Approximately 75.5% of the losses stemmed from two incidents attributed to North Korean threat actors, and 14 audited protocols were compromised this quarter.
Leo Fan, founder of Cysic, stated that audits are point-in-time, scope-limited assessments of specific codebases and do not automatically cover signing devices, cloud infrastructure, operational permissions, subsequent upgrades, third-party dependencies, or legacy contracts that remain callable. Samuel Videau, CTO of Genius, pointed out that nearly 90% of losses stemmed from keys, signers, and infrastructure.
Several security leaders noted that Web3 security must incorporate layered defenses such as real-time monitoring, key management, multi-party authorization, and bug bounties. Leo Fan predicts that in the second half of 2026, operational access control attacks will continue to account for the majority of losses, including social engineering, credential theft, compromised signers, cloud or CI/CD breaches, and attacks on off-chain validator infrastructure.