< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Web3 security losses exceed $1.31 billion amid shifting exploit tactics

Web3 security reports indicate that cumulative losses from hundreds of incidents have surpassed $1.31 billion, signaling a shift in how threat actors approach digital asset exploits. Rather than focusing solely on mathematical code bugs, attackers are increasingly targeting cross-chain bridges, internal node configurations, and human credentials.

Key vulnerabilities include the compromise of internal RPC nodes and the manipulation of single-verifier configurations to mint unbacked cryptocurrencies. High-profile incidents involving KelpDAO and Drift Protocol highlight the risks associated with protocols bridging assets across blockchains. Additionally, attackers are bypassing smart contract logic by targeting off-chain elements such as stolen deployer keys, compromised administrator multi-sigs, and social engineering directed at developers.

To evade detection, malicious actors move stolen funds through volatile assets and cross-chain liquidity networks, often utilizing privacy-enhancing mixing services to launder proceeds. According to a CertiK report, wallet compromise was the most costly attack vector in the first half of 2026, with over $444 million stolen across 33 incidents, while phishing attacks accounted for an additional $366 million across 63 incidents.

Entities

CertiK · Drift Protocol · KelpDAO