Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Hacken Q2 2026 Security and Compliance Report

2 min read

By Hacken

Q2 2026 was the worst quarter for Web3 since Q2 2025. Across 67 incidents, adversaries extracted $763.9 million, around 26% below the Q2 2025 total. Most of that value was lost to operational failures rather than flawed code: 88.3% of the total was traced to compromised keys, signers, and infrastructure. Smart contract bugs were the most frequent problem, appearing in 44 of the 67 incidents, but they account for only about 11% of the losses.

The losses were also highly concentrated. Two incidents, both attributed to North Korean actors, make up 75.5% of the quarter's total: a multisig takeover at Drift Protocol ($285M) and a cross-chain bridge breach at KelpDAO ($292M). 

What’s inside?

This report groups the second quarter under a single theme, the Architecture of Trust: how security, compliance, and risk intelligence together decide which counterparties institutions are willing to work with. 

The report is organised into five chapters. It brings together Hacken's own research teams, Extractor, A3, and CORE3, with external contributors including Chainlink, Bybit, Moody's Ratings, 1Money, Sui Foundation, Stellar Development Foundation, Abraxas Capital, Howden, EisnerAmper, DA Insured, SVRN, and Allium.

  • Digital Asset Exploits: breakdown and overview. 
    • Root causes of quarter's incidents and attack overviews. 
    • DPRK operations behind the two largest incidents.
    • The growing role of AI and agentic systems as an attack surface.
    • Exploits of deprecated but still-live on-chain infrastructure.
    • Losses caused by third-party dependencies.
  • Compliance Landscape: EU and US. 
    • How compliant is the industry in the EU now that MiCA/DORA is in force?
    • GENIUS stablecoin rules still being drafted in the US
    • Do regulators set the bar effectively: controls vs. incident causes
    • AI Governance outlook.
  • The Architecture of Trust. 
    • How market participants now assess the parties they work with
    • Why old trust indicators are no longer sufficient 
    • Where current Web3 ecosystem still fails on basic risk controls
    • Framework for continuous, verifiable evidence of controls.
  • Risk Intelligence for Institutions. 
    • What capital allocators look for before committing capital
    • How has due diligence changed in recent quarters? 
  • Conclusions and Q3 Outlook. 
    • Quarter's lessons and looks ahead?
    • How is AI changing the pace at which older vulnerabilities are found?
    • Which controls matter most going into Q3?

👉 Download the full report (PDF)

Hacken LiveWebinarLive Q&A

Go deeper than the report

Live session with the report's contributors — teardowns, walkthroughs, and the parts that matter most to your role. Leave your email and we'll tell you what's coming.

90 min with experts
Live Q&A + recording

Reserve your seat

By registering, you agree to receive event invitations from Hacken. See our Privacy Policy.

Banner image

Subscribe to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img

Table of contents

Tell us about your project

Follow Us