Web3 Security Trends

Updated 15 Sep 2026About these numbers
More filters
Reset
01 Sep 2025–31 Aug 2026compared with 01 Sep 2024–31 Aug 2025
Reported loss$2.72B ↓ 71% vs prior period 347/354 loss amounts reported
Reported attacks354 ↑ 55% vs prior period
Median incident loss$679K ↑ 3% vs prior period

Attacks and losses over time

Scroll to see every period

View chart as a table
PeriodReported lossAttacksKnown amounts
Sep 2025$176.5M2222 of 22
Oct 2025$51.6M1515 of 15
Nov 2025$288.4M1818 of 18
Dec 2025$79.5M2020 of 20
Jan 2026$405.4M3030 of 30
Feb 2026$36.8M1414 of 14
Mar 2026$77.8M3028 of 30
Apr 2026$951.7M3938 of 39
May 2026$112.5M5050 of 50
Jun 2026$93.9M4141 of 41
Jul 2026$299.4M4242 of 42
Aug 2026$145.2M3329 of 33

What changed

  1. Compared with the previous period, reported loss fell by $6.50B while incident count rose by 125.

    See incidents
  2. Drift Trade drove 11% of known reported loss in this period.

    Open incidentSource
  3. Incorrect Share Accounting was the most frequently recorded attack method, appearing in 14 incidents.

    Open incidentSource

Attack methods

  1. Incorrect Share Accounting14
  2. Access Control13
  3. Spot Price Manipulation13
  4. Improper Access Control11
  5. Phishing7
  6. Forged Proof6
  7. Oracle Issue6
  8. Private Key Compromised6
  1. Phishing$372.9M
  2. Access Control$352.0M
  3. Compromised Admin + Fake Token Price Manipulation / Proxy Upgrade Hijack$295.0M
  4. Access Control / Cross-Chain Message Spoofing$293.0M
  5. Other / Weak Key Generation$130.0M
  6. Composable Stable Pools Exploit / Access Control / Rounding Error$128.0M
  7. Oracle Issue / Donation Attack$75.0M
  8. Delegatecall Exploit / Access Control / Delegatecall Hijack$48.0M

Affected sectors

200 uncategorized incidents excluded

  1. DeFi applications115
  2. Other21
  3. Bridges12
  4. Centralized services4
  5. Wallets2
  1. DeFi applications$788.7M
  2. Other$167.5M
  3. Bridges$60.1M
  4. Centralized services$43.5M
  5. Wallets$8.6M

Affected chains

68 unnamed-chain incidents excluded. Multi-chain counts and losses overlap.

  1. Ethereum102
  2. BNB Chain61
  3. Base35
  4. Arbitrum33
  5. Solana20
  6. Polygon14
  7. Bitcoin7
  8. Sui6
  9. Avalanche6
  10. Optimism4
  1. Ethereum$849.4M
  2. Arbitrum$555.7M
  3. Solana$474.1M
  4. Base$204.8M
  5. Bitcoin$176.5M
  6. Polygon$134.2M
  7. Optimism$130.2M
  8. Sonic$128.1M
  9. BNB Chain$96.4M
  10. Cronos$75.0M

Incidents behind this view

39 matching records · 2026-04 selected · Clear selection

Full incident database
DateIncident and attack methodChainReported lossEvidence
14 Apr 2026CoW SwapDNS HijackEthereum$1.2M
14 Apr 2026Zerion WalletHot Wallet Compromise via Social Engineering / PhishingNot recorded$100KSource
13 Apr 2026DangoDonate Negative Amounts Hack / Missing Input Validationdango$1.9MSource
13 Apr 2026MONABurnAddress Accounting Exploit / Incorrect Share AccountingBNB Chain$61KSource
12 Apr 2026HyperbridgeFake State Proof / Other / Forged ProofArbitrum, Base, BNB Chain, Ethereum$2.5MSource
12 Apr 2026SubQuery NetworkAcces Control Exploit / Improper Access ControlBase$134KSource
09 Apr 2026AethirAcces Control Exploit / Other / Improper Access ControlBNB Chain$423KSource
09 Apr 2026HyperliquidOtherNot recorded$1.5MSource
07 Apr 2026SquidMulticall Approval ExploitationAccess Control / Improper Access ControlArbitrum, Avalanche, Base, BNB Chain, Optimism$517KSource
05 Apr 2026DenariaLP accounting rounding asymmetry and unsafe signed-to-unsigned conversionLinea$166KSource
04 Apr 2026BSC TMM/USDTReserve Manipulation Attack / Improper Access ControlBNB Chain$1.7MSource
03 Apr 2026Silo V2Misconfigured Oracle Exploit / Oracle MisconfigurationArbitrum$392KSource
01 Apr 2026Drift TradeCompromised Admin + Fake Token Price Manipulation / Proxy Upgrade HijackSolana$295.0MSource
01 Apr 2026Drift ProtocolAccess ControlNot recorded$280.0MSource

About these numbers

Updated 15 Sep 2026, 23:40 UTC

Incident selection

This dashboard covers reported incidents, not every attack or the relative safety of a chain. Each verified canonical incident is counted once. Unverified, rejected, merged duplicate, pending-review, and future-dated records are excluded. Late reports and corrections can change recent periods.

Loss and outliers

Reported loss sums known positive USD amounts. Missing amounts stay unknown, not zero. Median incident loss uses only incidents with a known amount. “Exclude the largest incident” removes the largest known-loss event from both the selected and comparison periods.

Missing classifications

Sector and chain labels come from the incident record. Uncategorized incidents are excluded from sector charts; incidents without a named chain are excluded from chain charts. A multi-chain incident appears under each named chain, so those counts overlap.

Limitations

Reliable malicious-actor attribution is not consistently available, so this page does not rank actor groups. Timing alone cannot show that AI caused an attack, so there is no AI-involvement metric. Confirmed returned funds are too sparsely documented for a recovery trend: 2 of 354 incidents in this view have comparable reviewed accounting, totaling $1.9M.

Cite this view

Smart Contract Hacking (SCH), “Web3 Security Trends: 2025-09-01 to 2026-08-31,” method 2026-09-15.1, view 4877e750d4f5, accessed 15 September 2026. https://smartcontractshacking.com/tools/web3-security-trends?bucket=2026-04&page=2

Live view. Figures may change as incident records are updated.