Quarterly report · current cutoff Q2 2026

The State of Web3 Security
2022 – Q2 2026

A quarterly updated empirical analysis of 25,706 published audit findings from 22 firms and 237 real-world exploit incidents totalling US$8.62 billion in losses. Produced by Oak Security in collaboration with rekt.news.

In collaboration with rekt.news Exploit data shared with explicit written permission.
Free download Cover of the Oak Security Web3 Security Report 2022 to Q2 2026
25,706
Published audit findings analysed across 22 firms
237
Documented real-world exploit incidents (rekt.news)
$8.62B
Aggregate user-funds losses, 2022 – Q2 2026
50%
Of total losses caused by human-vector attacks, not bugs
New · Q2 2026 data update
The dataset now runs through 30 June 2026. The quiet, code-vector-led first quarter did not last: Q2 brought US$854M across 18 incidents, with key compromise and bridge exploits back on top and 17 of 18 exploited protocols previously audited.
Explore the data dashboard
Data partnership

In collaboration with rekt.news

rekt.news has documented Web3 exploits from the perspective of the victims since 2021, building the most comprehensive public archive of incident data in the industry. For this report we were granted explicit written permission to ingest, classify and analyse the entire rekt.news archive of incidents from 2022 through Q2 2026.

rekt.news

The most thorough public archive of Web3 exploits

237 incidents totalling US$8.62 billion form the exploit-side ground truth in this report. We thank the rekt.news team for the data-sharing arrangement that made this analysis possible.

Visit rekt.news
Key findings

Six observations from four and a half years of data

The numbers below summarise the most material patterns across audit output and exploit incidents. Detailed methodology, charts and citations are provided in the full report.

Headline
50%

Human-vector attacks dominate financial losses

Private-key compromise, phishing, supply-chain compromise and governance attacks now account for half of all user-fund losses — surpassing every code-level defect category combined.

Severity
16%

Critical & High share is essentially flat

The combined Critical+High share of audit findings has remained near 16% for four consecutive years — protocol code is not measurably improving in absolute terms despite the maturing audit market.

Concentration
46.6%

Eight incidents drive nearly half of all losses

The loss distribution is strongly heavy-tailed: the top 8 of 237 incidents account for 46.6% of aggregate damage. The top 20 reach 68.6%. Tail risk dominates the ecosystem.

Audit gap
6/ 10

Most top exploit causes never make the top audit list

There is real overlap — access control, oracle issues, logic errors and integer arithmetic appear prominently on both sides. But six of the ten largest exploit-loss categories — including private-key compromise, phishing and supply-chain attacks — sit outside the top audit categories, because they cannot be found through code review.

Concentration
92%

Ethereum & BNB Chain absorb 92% of losses

Two chains carry the overwhelming majority of incidents (88%) and losses (92%) — a function of TVL concentration and EVM tooling maturity rather than chain-specific weakness.

Trend
3×

Audit volume tripled — losses did not

Published audit findings grew from 2,526 in 2022 to 7,454 in 2024 as the audit market matured. Annual loss totals across the same window show no corresponding decline. More auditing has not translated, in aggregate, into a measurably safer ecosystem.

Wide attack surface

Web3 security is not a code problem alone

Securing a protocol means securing far more than its smart contracts. The data shows two distinct classes of exposure — code-vector defects auditable in source, and human-vector compromises that bypass the code entirely.

Code-vector

What lives in the source

The traditional smart-contract audit surface — defects discoverable through code review, fuzzing and formal methods.

  • Logic errors and broken business invariants
  • Access-control and authorisation gaps
  • Input validation and arithmetic bugs
  • Initialisation and upgradeability hazards
  • Reentrancy and call-ordering issues
  • Oracle / price-manipulation paths
  • Bridge and cross-chain message handling
49.9%
Share of total losses
(2022 – Q2 2026)
Human-vector

What lives outside the source

The operational, organisational and social surface — out of reach of any contract-only audit.

  • Private-key theft (signers, multisig, EOAs)
  • Phishing of admin accounts and front-end users
  • Supply-chain compromise (dependencies, infra, CI/CD)
  • Domain & DNS hijacks; front-end injection
  • Insider threats and social engineering
  • Governance capture & vote-buying attacks
  • Cloud, RPC and key-management mis-configuration
50.1%
Share of total losses
(2022 – Q2 2026)
Share of US$8.62B in aggregate losses
2022 – Q2 2026
Code-vector · 49.9%
Human-vector · 50.1%
Bottom line: a protocol that has been thoroughly audited at the source level can still be drained the next day through a compromised signer key, a poisoned NPM package, or a phished front-end domain. Ship-grade Web3 security must extend well beyond the codebase.
Spotlight · Operational security

The biggest gap in Web3 security is operational, not technical

For four consecutive years, attackers earned more from compromising people, processes and infrastructure than from breaking smart-contract logic. The trend is consistent; the response from the ecosystem has not been.

Hardening operational security — signer hygiene, dependency review, domain controls, incident playbooks, employee onboarding — is now at least as important as a thorough code audit.

See our advisory services
Loss share by root cause
US$ millions
K
Private-key compromise
Signer / multisig theft, leaked keys, malicious extensions
26.5%
P
Phishing & social engineering
Admin and end-user phishing, fake dApp pages, signer deception
17.5%
A
Access-control failures
Missing checks, mis-configured permissions, stale admins
11.7%
B
Bridge exploits
Cross-chain message validation, lock/mint accounting
10.9%
O
Oracle & price manipulation
Spot-price reads, low-liquidity pairs, broken TWAPs
7.8%
Methodology

How the report was built

The full PDF carries the complete methodology, source citations and per-firm attribution — below is a summary of the four data pillars.

01

Audit-side dataset

25,706 published findings ingested from 22 audit firms’ public reports, 2022 – Q2 2026.

02

Exploit-side dataset

237 real-world incidents from the rekt.news archive, used with explicit written permission.

03

Classification

Findings and incidents normalised into a unified severity, category and root-cause taxonomy.

04

Analysis

Year-over-year trend, Pareto / heavy-tail, mean-vs-median, chain and stack concentration.

Read the full 31-page report

Twelve charts, ten numbered sections and the complete methodology — including everything we left out of this page. Free, CC BY-ND 4.0.