Web3 projects lost $482.6 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 76% decline from Q1 2025's $2 billion in losses, but the underlying shift in attack vectors carries structural implications for protocol se...
"The most expensive failures happen outside the code layer." — Yev Broshevan, CEO, Hacken
Web3 projects lost $482.6 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 76% decline from Q1 2025's $2 billion in losses, but the underlying shift in attack vectors carries structural implications for protocol security spending.
Phishing and social engineering accounted for $306 million — 63% of total losses — while smart contract exploits contributed $86.2 million (18%) and access control failures added $71.9 million (15%). The quarter's two largest incidents, a $282 million hardware wallet phishing attack in January and the $286 million Drift Protocol exploit on April 1, both targeted human and operational layers rather than on-chain code. DeFi-specific smart contract exploit losses fell 89% year-over-year, per Sherlock's parallel Q1 report, which tracked 145 incidents totaling approximately $450 million.
Six audited protocols — including Resolv Labs (18 separate audits) and Venus Protocol (five audit firms) — collectively lost $37.7 million, averaging $6.3 million per incident versus $4.3 million for unaudited projects. The data implies that audit coverage at the code layer is improving measurably, but threat migration toward infrastructure, cloud key management, and social engineering has outpaced defensive investment.
Hacken's Q1 2026 Blockchain Security & Compliance Report identifies 44 distinct incidents across the quarter. The distribution:
| Attack Vector | Losses (USD) | Share of Total | Notable Incidents | |---|---|---|---| | Phishing / Social Engineering | $306M | 63.4% | $282M hardware wallet scam (Jan); Step Finance ($40M) | | Smart Contract Exploits | $86.2M | 17.9% | Venus Protocol ($3.7M); Truebit ($26.4M) | | Access Control / Key Compromise | $71.9M | 14.9% | Resolv Labs ($25M); IoTeX | | Other | $18.5M | 3.8% | Various | | Total | $482.6M | 100% | 44 incidents |
For context, Q1 2025 saw approximately $2 billion in losses, driven primarily by the $1.4 billion Bybit hack. Excluding that single outlier, Q1 2026 losses are broadly comparable to the prior year's baseline. The structural difference is in composition: social engineering and infrastructure-layer attacks now dominate, while pure smart contract exploits have receded.
Sherlock's independent Q1 2026 report tracked 145 incidents (a broader count that includes smaller events) at approximately $450 million in total losses, confirming the directional trend. Smart contract exploit losses dropped roughly 89% year-over-year, per Sherlock's methodology.
Date: April 1, 2026 Chain: Solana Loss: $270M–$286M (estimates vary by tracker) Attribution: DPRK-linked actors, per Elliptic and TRM Labs
The Drift Protocol exploit — the largest DeFi hack of 2026 through mid-April — did not involve a smart contract vulnerability or a stolen private key in the conventional sense. Elliptic calculated combined stolen assets at $286 million; on-chain confirmations placed the initial drain at $270 million.
Attack timeline:
The exploit underscores a specific design risk: durable nonces, while useful for offline signing and scheduled transactions, create an indefinite execution window that bypasses the temporal security assumptions of standard Solana transactions. Combined with a reduced multisig threshold and no timelock, the attacker's pre-signed transactions had zero-delay execution authority.
Bloomberg reported the incident as a "$285 million exploit," making it the second-largest security incident in the Solana ecosystem after the $326 million Wormhole bridge exploit in February 2022.
Date: March 22, 2026 Chain: Ethereum Loss: ~$25M in ETH Vector: Cloud infrastructure compromise (AWS KMS)
The Resolv Labs exploit demonstrated how off-chain infrastructure failures can produce on-chain catastrophes. According to Chainalysis's post-mortem, the attacker compromised Resolv's AWS Key Management Service (KMS) environment, where the protocol's privileged minting key was stored.
Attack flow:
Resolv Labs had undergone 18 separate security audits, according to Hacken's report. None of the audits would have been expected to cover AWS infrastructure configuration or key management practices, as they focused on Solidity code. The incident cost $25 million. A code-level audit would not have prevented it.
Date: March 15, 2026 Chain: BNB Chain Loss: $3.7M extracted; $2.15M in bad debt remaining Vector: Donation attack on Compound-fork lending logic
The Venus Protocol exploit involved a known vulnerability class — donation attacks on Compound-forked lending protocols — that had been flagged during a Code4rena security audit. The protocol's team declined to remediate, stating that donations were "an intentional feature with no negative side effects."
Attack timeline:
getCashPrior function, which reads the contract's token balance rather than minted supply. This allowed borrowing ~$14.9 million in assets.The incident is notable not for its scale but for its preventability. Five separate audit firms reviewed Venus Protocol. At least one flagged the exact vulnerability that was exploited. The finding was dismissed.
Two bridge exploits in Q1 2026 reinforced the sector's persistent vulnerability to message validation failures.
Hyperbridge (April 13, 2026): An attacker exploited a flaw in Hyperbridge's Ethereum gateway contract to mint 1 billion bridged DOT tokens. According to BlockSec's analysis, the contract failed to bind the submitted request payload to the validated proof — the system checked that a request hash had not been reused but did not verify whether the proof matched the message it authenticated. By manipulating index parameters, the attacker bypassed root computation, forged a cross-chain message, elevated to administrator status, and minted 1 billion DOT.
Despite the theoretical value exceeding $1 billion, shallow liquidity in the Ethereum DOT pool limited actual proceeds to approximately $237,000. Polkadot's core network was unaffected. The exploit arrived less than two weeks after Hyperbridge published an April Fools' Day joke claiming a $37 million breach — a coincidence that drew significant commentary.
CrossCurve (January 31, 2026): A missing validation check in CrossCurve's ReceiverAxelar contract allowed anyone to call the expressExecute function with a spoofed cross-chain message, bypassing gateway validation and triggering unauthorized token unlocks. The PortalV2 contract was drained of approximately $3 million across multiple chains.
Both incidents involve the same fundamental weakness: insufficient binding between cross-chain message authentication and message content. Bridge protocols continue to represent a disproportionate share of per-incident losses relative to their TVL, a pattern consistent with historical data going back to the $600 million Ronin bridge exploit of 2022.
Hacken's Q1 data presents an uncomfortable finding for the audit industry: six audited protocols lost $37.7 million, averaging $6.3 million per incident, while unaudited projects averaged $4.3 million per incident.
This does not mean audits cause losses. The correlation reflects selection bias — higher-TVL protocols are both more likely to commission multiple audits and more likely to attract sophisticated attackers. But the data does suggest that the current audit model, focused primarily on Solidity/smart contract code review, is misaligned with the threat landscape as it has evolved in 2026.
The attack surface has migrated:
| Layer | Q1 2025 Dominant Threat | Q1 2026 Dominant Threat | |---|---|---| | Smart Contract Code | ~$800M+ in exploit losses | $86.2M (↓89% YoY) | | Infrastructure / Key Mgmt | Moderate | $71.9M (rising) | | Human / Social Engineering | $300M+ (Bybit) | $306M (sustained) |
Smart contract audits address roughly 18% of Q1 2026 losses by dollar value. The remaining 82% occurs at layers that standard audits do not cover: employee device security, cloud infrastructure, multisig governance practices, and social engineering resilience.
Five days after the Drift exploit, the Solana Foundation announced two security initiatives:
STRIDE Program: A structured evaluation framework led by Asymmetric Research that assesses Solana DeFi protocols against eight security pillars. Protocols with more than $10 million in TVL that pass the evaluation receive ongoing operational security monitoring and active threat detection, funded by Solana Foundation grants. Protocols managing more than $100 million in TVL are eligible for foundation-funded formal verification — mathematical proofs that check every possible execution path in a smart contract.
SIRN (Solana Incident Response Network): A membership-based consortium of security firms and researchers focused on real-time crisis response.
The STRIDE program is notable because it extends security evaluation beyond code to operational practices — a direct response to the Drift exploit's attack vector. Whether other Layer 1 foundations adopt similar models remains to be seen. The Ethereum ecosystem's security budget is more decentralized and has no equivalent centralized program, though the Ethereum Foundation's parallel work on audit subsidies (covered in prior webthreepedia analysis) addresses the code-layer component.
Step Finance, which lost $40 million in January 2026 to a device compromise targeting executive team members, subsequently shut down its core platform along with SolanaFloor and Remora Markets. The team recovered approximately $4.7 million using Solana's Token22 protections.
The Q1 2026 data describes a security landscape in transition. The industry's multi-year investment in smart contract auditing, formal verification, and bug bounties appears to be producing measurable results: pure code exploit losses dropped 89% year-over-year. That is a defensible claim based on consistent data from both Hacken and Sherlock.
The threat has not diminished. It has migrated upward in the stack. Social engineering, cloud infrastructure compromise, and governance manipulation now account for the majority of dollar losses. These attack vectors are not addressed by standard code audits, and protocols that have completed extensive audit programs are not measurably safer against them.
The economic implication is straightforward: security spending in Web3 is misallocated. Protocols spend heavily on Solidity audits — the layer where losses are declining — and underinvest in operational security, employee training, key management infrastructure, and governance design — the layers where losses are concentrated.
The Solana Foundation's STRIDE program represents one model for closing this gap, extending security evaluation to operational practices and funding it through foundation grants. Whether the broader ecosystem follows this direction or continues to rely primarily on code-level audits will likely determine the loss trajectory for the rest of 2026.