Hacken's quarterly security report, released July 23, logged $763.9 million stolen across 67 Web3 incidents in Q2 2026, making it the worst quarter for the sector since Q2 2025. The number alone is striking. The breakdown behind it is worse.

Operational failures and key management compromises drove 88.3% of all losses, roughly $674.5 million, while smart contract bugs, though present in 44 of the 67 incidents, accounted for only around 11% of stolen funds. Two incidents alone, both attributed to North Korean threat actors, were responsible for 75.5% of total losses.

Audits did not stop the bleeding

Fourteen of the breached protocols had been audited. That detail cuts to the center of what Hacken and several security leaders are calling a persistent industry blind spot: a code audit is a snapshot, not a standing guarantee. Leo Fan, founder of Cysic, put it plainly. "An audit does not automatically cover signer devices, cloud infrastructure, operational permissions, deployed bytecode, later upgrades, third-party dependencies or old contracts that remain callable," he said.

Eric Swartz of Panther Hollow Ventures made the same point from a different angle, noting that an audit captures how a system looked at a single moment. Anything that changes after that moment, a new dependency, an upgraded contract, a reassigned admin key, falls outside the original scope entirely.

The numbers back them up. Only 9% of tracked projects run continuous monitoring, and just 4% combine audits, bug bounties, and live monitoring into a layered approach. Institutional capital appears to be drawing conclusions from Q2: due diligence is shifting toward privileged-access governance and multi-participant authorization rather than point-in-time code reviews. Fan expects threat actors to concentrate on operational controls through the second half of 2026.

This article is for informational purposes only and does not constitute financial or investment advice.