More

    The $763.9 Million Shift: Why Smart Contract Audits Couldn’t Stop Web3’s Worst Quarter


    Key Takeaways

    Q2 2026 Security Breakdown

    The second quarter of 2026 was the most severe period for Web3 security since the second quarter of 2025, with threat actors extracting $763.9 million across 67 security incidents. The quarter’s defining shift was a fundamental change in vulnerability profiles: Code is no longer the primary attack surface; operational controls and key management are.

    More than 88% of total losses stemmed from operational compromises rather than flaws in smart contract logic. Institutional capital is already adjusting, shifting due diligence priorities away from point-in-time audits and toward continuous monitoring, privileged-access governance, and multi-participant authorization frameworks.

    According to Hacken’s quarterly security and compliance report, key and infrastructure compromises accounted for 88.3% of all stolen funds, or about $674.5 million. Smart contract bugs remained the most common attack type — 44 of 67 incidents — but represented only roughly 11% of total losses. About 75.5% of all losses came from just two incidents attributed to North Korean threat actors, while only 9% of tracked projects maintain continuous monitoring and 4% combine audits, bug bounties and live monitoring.

    A core finding from the second quarter is that 14 audited protocols were breached—a stark indicator of the expanding rift between what a smart contract audit actually evaluates and where threat actors actually strike. For security experts, these breaches lay bare the fatal flaw of treating a point-in-time code review as an all-encompassing security shield.

    “The biggest misconception is that an audit is a security certificate,” said Leo Fan, founder of Cysic. “It is actually a scoped assessment of a particular codebase at a particular point in time. An audit does not automatically cover signer devices, cloud infrastructure, operational permissions, deployed bytecode, later upgrades, third-party dependencies or old contracts that remain callable.”

    Eric Swartz, founding general partner and general counsel of Panther Hollow Ventures, echoed that treating audits as a finish line leaves protocols exposed. “An audit tells you how a system looked at a particular moment in time,” Swartz said. “It doesn’t guarantee that future upgrades, operational changes or new attack methods won’t introduce risk. The strongest teams see audits as one part of a much broader security programme.”

    Samuel Videau, CTO at Genius, noted that the scope section of an audit report often reveals what wasn’t evaluated. “Almost 90% of Q2 losses came from keys, signers and infrastructure, all outside that scope section, and 14 audited projects got drained anyway,” Videau said. “The report card is not the security program.”

    Himanshu Sahay, CTO and co-founder of Arch, emphasized that audits cannot stand alone. “An audit is an important point-in-time assessment of the code and architecture that was reviewed, but it cannot account for every operational risk or future change to a system,” Sahay said. “Security needs to be treated as an ongoing process.”

    Bypassing Code: The Soft Underbelly of Off-Chain Infrastructure

    In the meantime, as smart contract defenses mature and on-chain logic has increasingly grown harder to compromise, threat actors have pivoted decisively. Rather than breaking through heavily guarded front doors, attackers are systematically bypassing code entirely to exploit the soft underbelly of off-chain infrastructure.

    “The most underestimated surface is the off-chain control plane: signer devices, key-generation and rotation procedures, cloud identities, CI/CD pipelines, backend services, bridge validators and emergency admin paths,” Fan said. “Teams often secure key storage but pay less attention to how keys are actually used… when compromised, attackers can produce transactions that are technically valid onchain, making prevention and detection much harder.”

    The cloud perimeter itself presents a false sense of security for many Web3 developers.

    “The biggest assumption is that using a major cloud provider makes an application secure by default,” said Jerald David, CEO of Lynq. “Cloud providers secure the underlying infrastructure, but teams are still responsible for how systems are configured, how credentials are managed and who has access.”

    Videau, meanwhile, warned that improper architecture can nullify multisig protection. “The whole operation runs on over-permissioned service roles and CI/CD pipelines that can touch production keys, and if one service account can read your signing key, your multisig is theater,” Videau said. “Deprecated contracts still holding admin rights are another vector: Code you shipped two years ago is a live door, and attackers don’t care what you consider in scope.”

    As institutional allocators recalibrate their risk models, the bar for capital deployment has risen significantly. “Institution-ready” is no longer defined by a clean audit report, but by proof of operational maturity, enterprise-grade governance, and resilient key-management controls.

    “I look first at operational maturity,” David said. “Can the team clearly explain how capital moves through the system, where the key points of control are and how risks are monitored? Institutions need predictability and transparency.”

    Sahay noted that no single control guarantees institutional backing on its own. “Institutions want to understand how critical systems are accessed, how permissions are managed, how activity is monitored and what processes exist if something goes wrong,” Sahay said. “It is the combination of strong controls, transparency and operational discipline that ultimately builds confidence.”

    When evaluating protocols, Fan focuses on the privilege map: who can move assets, replace signers or alter safeguards. “If I had to identify one control most associated with institutional confidence, it would be multiparty authorization across every asset-moving and upgrade path,” Fan said. “Institutions want evidence that unilateral action is impossible.”

    Swartz added that institutions prioritize how teams handle adversity. “Institutions know that no protocol is completely risk-free,” Swartz said. “What matters is whether the team has good governance, strong internal controls, transparency around risk and a clear plan for responding when something goes wrong.”

    The five experts agree that Web3 must adopt layered defense stacks incorporating real-time monitoring, disciplined key management and responsive bug bounties to protect against evolving threats.

    “Digital assets operate around the clock, but parts of the infrastructure supporting them still operate according to traditional financial schedules,” David noted. “As the market becomes more institutional, the infrastructure supporting the movement and settlement of capital needs to become more resilient as well.”

    Looking Ahead to H2 2026: Realigning Defense Stacks

    The experts, meanwhile, warn that the second half of 2026 will bring more of the same. Rather than burning cycles trying to reverse-engineer audited smart contracts, threat actors are expected to keep hammering the path of least resistance: operational controls, human targets, and key infrastructure.

    “I expect operational access-control attacks to continue dominating losses: social engineering, credential theft, signer compromise, cloud or CI/CD intrusion and attacks on off-chain validator infrastructure,” Fan predicted. “Individual smart-contract bugs will continue, but attackers will keep targeting the shortest path to authority.”

    Videau concluded with a call to realign security spending with actual risk: “Spend where the losses are. Nearly 90% of stolen funds moved through keys, signers and infrastructure, yet budgets still pour into contract audits. The worst attacks will be the ones nobody predicted, so build as if your perimeter is already gone.”



    Source link

    Latest stories

    You might also like...