Web3 security incidents increased sharply in the first half of 2026, with 182 publicly disclosed attacks causing about $956 million in losses, even as the dollar total fell nearly 60% from the same period a year earlier. The figures point to a more fragmented threat environment: fewer single, billion-dollar events, but far more compromises involving credentials, supply chains, bridge validation, social engineering and operational failures.
Only about $118 million was recovered or frozen across 18 cases, equal to 12.3% of reported losses. The remaining funds largely moved beyond the reach of affected protocols and enforcement actions, underscoring how quickly attackers can convert stolen tokens into more liquid assets and distribute them across chains and wallets.
The first half of 2025 was skewed by the roughly $1.5 billion Bybit theft, which was linked to compromised signing tooling and a tampered website script. No event of comparable size appeared in 2026. Yet the number of reported cases rose from 121 to 182, an increase of about 50%, suggesting that lower-value but operationally sophisticated attacks have become a more persistent problem.
Bridge failures produced the largest concentration of losses
Cross-chain bridges accounted for 20 incidents but about $346 million in losses, making them one of the most costly categories despite representing a relatively small share of total attacks. Bridges concentrate risk by relying on validators, messaging layers and key management systems to verify that assets locked on one network can be released on another.
KelpDAO recorded the largest single loss described in the reports. Attackers allegedly compromised an internal LayerZero RPC node, launched distributed denial-of-service activity against honest external nodes, and exploited a bridge configuration that used a “1-of-1” validator model. That setup allowed a fabricated message to be accepted, enabling the withdrawal of about 116,500 rsETH.
Around $75 million connected to the incident was later frozen, but the broader consequences extended into lending markets. Tracing linked the attack to the Lazarus-associated TraderTraitor group, which allegedly used stolen assets as collateral to borrow about $236 million in WETH through platforms including Aave. The transaction chain gave the attackers access to more liquid assets while placing pressure on markets connected to the collateral.
Supply-chain attacks ranked first by losses, at about $298 million, ahead of contract vulnerabilities at roughly $152 million and private-key leaks at about $130 million. Contract and logic failures remained the most common category by number of cases, with 85 incidents, but the loss rankings show that compromise of trusted infrastructure can produce larger damage than a conventional smart-contract flaw.
Social engineering reached multisig systems
Drift Protocol’s reported $285 million loss illustrated how a long-running social-engineering campaign can bypass controls designed to protect large treasuries. A multisig signer was reportedly persuaded over six months to pre-sign “durable nonce” transactions, a mechanism that permits a transaction to be signed before it is later submitted to the network.
Attackers then executed 31 withdrawals over 12 minutes during a period in which no timelock restricted the transfers. The episode showed the limitations of multisig arrangements when a signer can be manipulated into authorizing transactions outside a clearly reviewed execution window.
A separate case in Singapore involved an AI-generated video call impersonating senior officials. The victim reportedly transferred about S$4.9 million after joining the spoofed meeting. Synthetic video and voice tools have made impersonation campaigns more convincing, particularly when attackers can imitate familiar executives or colleagues and create a sense of urgency around a transfer request.
Operational access failures appeared repeatedly across other disclosures. Resolv Labs was linked to compromised AWS credentials that enabled the minting of about 80 million unpegged tokens. Step Finance and Humanity Protocol were associated with compromised executive or developer devices that led to private-key exposure and treasury losses.
Software supply chains became a direct target
The Shai-Hulud worm demonstrated the speed at which a compromised package ecosystem can be weaponized. In one episode, it published 637 malicious versions across 317 package names in 22 minutes. The affected package names included components such as echarts-for-react and size-sensor, which had millions of monthly downloads according to the reports.
Its payload sought credentials for AWS, Google Cloud Platform and Microsoft Azure, along with Kubernetes secrets and SSH keys. It also included persistence and self-propagation functions aimed at developer environments using Claude Code and VS Code. Such attacks place the initial compromise upstream of a blockchain application, where malicious code can reach development teams before it encounters conventional on-chain security controls.
In March, the Python library LiteLLM was reportedly compromised through a build-process dependency on Trivy. Attackers allegedly used the compromised security tool to obtain publishing keys and release a malicious package version. The case added to concerns that security tooling itself can become a route into software distribution pipelines.
Implementation errors also continued to generate losses. Taiko lost about $1.7 million on June 22 after a signing key was mistakenly committed to a public GitHub repository, enabling forged Layer 2 state proofs. TAIKO fell more than 20% in the short term following the incident, according to the supplied market account.
SecondFi, formerly associated with Yoroi, lost about $2.4 million between June 21 and June 23 after a signing implementation omitted a random blinding step. The flaw allowed private keys to be derived from a single on-chain signature and affected 374 addresses. Reports linked the issue to an unaudited third-party component added roughly two weeks earlier.
Recovery remains difficult after cross-chain movement
The reported laundering routes show why recovery remained limited. Funds linked to Lazarus were described as moving through privacy protocols including Umbra, cross-chain swaps through THORChain, thousands of new addresses, and mixers such as Sinbad, YoMix and Wasabi. Reports also identified off-ramping channels involving Chinese over-the-counter markets and Russian networks including Garantex and its successor Grinex.
Dune-based tracking cited about $974 million in first-half inflows to major privacy protocols. Tornado Cash accounted for about 71% of the total, while Railgun represented about 23%; nearly 90% of Railgun inflows were described as stablecoins.
Regulators have increasingly targeted points where funds can be obscured or converted. Measures cited in the reports include the European Union’s 20th Russia sanctions round, which bans transactions with Russian crypto service providers; Dubai International Financial Centre restrictions on privacy-coin trading; and a Chinese rule requiring approval for offshore issuance of RMB-pegged stablecoins.
The 2026 incidents place more emphasis on practical controls around people and infrastructure: independently verifying unusual payment requests, separating signing authority from day-to-day devices, reviewing bridge validator configurations, and testing software dependencies before deployment. Smart-contract audits remain necessary, but the half-year’s largest losses repeatedly began before an attacker reached a protocol’s core code.
Want to protect your assets from rising Web3 hacks? Learn key safeguards in crypto safety standards every trader should know today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

