Web3 protocols lost $450 million across 145 security incidents in Q1 2026, according to data compiled by Sherlock and DefiLlama. The figure is down from $1.58 billion in Q1 2025, a 72% year-over-year decline in aggregate losses. But the composition of those losses has shifted in a way that should...
"In the five years that I've been in crypto, it is sad that security is still the story. How is this the future of finance?" — Ann Irvina Ravinther, Former Marketing Lead, Drift Labs
Web3 protocols lost $450 million across 145 security incidents in Q1 2026, according to data compiled by Sherlock and DefiLlama. The figure is down from $1.58 billion in Q1 2025, a 72% year-over-year decline in aggregate losses. But the composition of those losses has shifted in a way that should concern every protocol operator and allocator in the space: smart contract exploit losses fell 89% year-over-year, while social engineering and infrastructure-level attacks now account for the majority of value extracted.
The quarter's defining incident — the $285 million Drift Protocol exploit on April 1 — involved zero lines of vulnerable code. Suspected DPRK-linked actors spent six months building relationships with multisig signers, tricked them into pre-authorizing transactions via Solana's durable nonce mechanism, and drained the protocol's core vaults in 12 minutes. The attack has triggered a class action investigation by Gibbs Mura, the launch of the Solana Foundation's STRIDE security program, and a broader industry reckoning with the gap between code audits and operational security.
The data is unambiguous: DeFi's primary attack surface has migrated from the smart contract layer to the human layer.
Total Q1 2026 losses break down as follows, according to Sherlock's Q1 2026 Web3 Security Report and DefiLlama tracking data:
| Metric | Q1 2026 | Q1 2025 | Change | |--------|---------|---------|--------| | Total losses | $450M+ | $1.58B | -72% | | DeFi protocol exploits | $169.4M (55 incidents) | ~$1.5B | -89% | | Social engineering/phishing | $290M | Not separately tracked | N/A | | Private key compromise share | 43% of losses (6 incidents) | Dominant vector | Structural shift | | Novel zero-day exploits | 0 | Multiple | -100% |
January alone accounted for $105.4 million in DeFi protocol losses. Notable incidents included Step Finance ($40 million, private key compromise), Resolv Labs ($24.5 million, cloud key management compromise), and Truebit ($26.4 million). March saw a 96% jump from February, reaching $52 million across 20 incidents according to PeckShield.
The zero novel zero-day figure across all 55 protocol-level exploits is notable. Every exploit in Q1 used known vulnerability classes. Missing access control was the most common finding in audits for the second consecutive year.
On April 1, 2026, at 16:05:18 UTC, the first of two pre-signed transactions hit Solana mainnet. One second later, at 16:05:19 UTC, a second transaction approved and executed the transfer of Drift Protocol's admin key to attacker-controlled address H7PiGqqUaanBovwKgEtreJbKmQe6dbq6VTrw6guy7ZgL.
What followed took 12 minutes. The attacker:
Drift's TVL fell from approximately $550 million to under $300 million in under an hour. The DRIFT token dropped more than 40%.
The attack chain began six months earlier. According to TRM Labs and Elliptic, suspected DPRK-affiliated actors built relationships with Drift team members, met them in person at conferences, and posed as representatives of a legitimate trading organization. The social engineering campaign mapped multisig signers using publicly available LinkedIn, GitHub, and X data, then manufactured urgency to get signers to pre-sign transactions they did not fully understand.
A critical operational failure preceded the exploit. On March 26 — five days before the attack — Drift migrated to a new 2-of-5 threshold Security Council multisig with zero timelock, eliminating the delay window that could have allowed detection and intervention.
The attack exploited Solana's durable nonce feature, a legitimate mechanism that allows transactions to be pre-signed and held as live authorization keys until the attacker chooses to execute them. As CoinDesk reported, the feature "designed for convenience" enabled an attacker to "drain $270 million from Drift."
Sherlock's Q1 2026 report identifies the following top vulnerability classes, ranked by severity:
CRITICAL:
HIGH:
MEDIUM:
The taxonomy reveals a structural shift. In 2024 and early 2025, smart contract bugs dominated loss statistics. In Q1 2026, 43% of all losses came from just six infrastructure failures — none involving code vulnerabilities in the traditional sense.
As David Schwed, COO of security firm SVRN, told DL News: "I don't see the effort being put in. They don't have the budgets of the bank, they don't have the maturity of the bank."
The Sherlock report published a breakdown of typical protocol security spending that quantifies the problem:
| Security Layer | Typical Budget | Adequacy | |---------------|---------------|----------| | Smart contract audit (primary) | $50K–$150K | Standard | | Second audit | $30K–$80K | Common | | Bug bounty allocation | $50K–$500K | Variable | | Formal verification | $100K–$300K | Rare | | Operational security training | $0–$5K | Negligible | | Multisig signer vetting | Informal or nonexistent | Absent | | Key management audit | Almost never conducted | Absent |
The bottom three rows explain Q1 2026's loss distribution. Protocols spend six figures on code review and near-zero on the human processes that manage the keys controlling hundreds of millions in deposits.
The Sherlock report frames this as a four-layer security model, with the most neglected layer listed first:
The industry has invested heavily in Layer 4. Losses are now concentrated in Layer 1.
Deddy Lavid, CEO and co-founder of security firm Cyvers, stated: "The core issue is not the number of signers, but the lack of understanding of transaction intent. This is why security needs to move beyond signer-based trust toward transaction-level verification."
On April 7, 2026 — six days after the Drift exploit — the Solana Foundation announced two programs:
STRIDE (Solana Trust, Resilience and Infrastructure for DeFi Enterprises)
Led by Asymmetric Research, STRIDE is a structured evaluation program assessing Solana DeFi protocols against eight security pillars. Coverage is tiered by TVL:
Assessment findings will be published in a public repository.
SIRN (Solana Incident Response Network)
A membership-based group of security firms and researchers focused on real-time crisis response coordination. Founding members include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow. Open to all Solana protocols, prioritized by TVL.
Drift Protocol itself announced it would participate in STRIDE, working with Asymmetric Research and OpenSec on recovery and security overhaul.
The STRIDE model represents a shift from the pre-launch audit paradigm toward continuous security evaluation. Whether other ecosystems adopt similar structures remains to be seen. Ethereum's security infrastructure remains fragmented across private firms, with no equivalent foundation-level coordination.
On April 7, 2026, Gibbs Mura, A Law Group, announced a class action investigation into the Drift Protocol exploit. The investigation examines potential claims on two fronts:
The Circle angle introduces a novel legal question for DeFi: if a centralized infrastructure provider has demonstrated the technical ability to freeze stolen funds and has done so in other contexts, does inaction constitute negligence?
A legal expert quoted by The Coin Republic described the Drift incident as a potential "civil negligence case," distinct from prior hack-related litigation which has typically focused on code defects.
TRM Labs and Elliptic attributed the Drift exploit to DPRK-linked actors, citing laundering patterns and on-chain timestamps consistent with Lazarus Group tradecraft. If confirmed, Drift joins a growing ledger of DPRK-attributed crypto theft:
| Year | DPRK-Attributed Crypto Theft | Notable Incidents | |------|-------|-------------------| | 2025 | $2.02B | Bybit ($1.5B), multiple DeFi exploits | | Q1 2026 | $309M (12 incidents) | Drift Protocol ($285M) | | All-time cumulative | ~$6.75B | ~270 documented incidents |
According to BlockEden.xyz research, DPRK's cumulative crypto theft across approximately 270 documented incidents totals an estimated $6.75 billion. The United Nations and multiple intelligence agencies have concluded that these operations serve as a primary funding mechanism for North Korea's ballistic missile and nuclear development programs.
The Drift attack used a six-month campaign involving fake identities, in-person meetings across multiple countries, and "carefully cultivated trust," according to CoinDesk reporting. This level of human intelligence tradecraft — applied to DeFi protocol operations — represents a threat model that code audits, bug bounties, and formal verification cannot address.
OFAC targeted DPRK IT workers using crypto in a March 2026 action, according to Chainalysis. But enforcement actions have not demonstrably deterred the operational tempo.
The Q1 2026 data documents a structural shift in DeFi's threat landscape. The industry's multi-year investment in smart contract auditing, formal verification, and bug bounties has measurably reduced code-level exploit losses. That progress is real.
But the attack surface has migrated. The humans who hold admin keys, sign multisig transactions, and manage governance processes are now the primary target. Protocols that spend $150,000 on code audits and $0 on signer vetting are optimizing for the wrong threat model.
The Drift incident is the starkest illustration. A protocol with $550 million in TVL was drained in 12 minutes — not because its code failed, but because its human processes did. The migration to a zero-timelock multisig five days before the attack, the lack of signer vetting procedures, and the absence of transaction intent verification created a gap that a nation-state threat actor exploited with precision.
The Solana Foundation's STRIDE program and the Gibbs Mura class action represent two distinct feedback mechanisms — one market-driven, one legal — pushing protocols toward operational security maturity. Whether they prove sufficient depends on whether the rest of the industry recognizes that the threat is no longer in the code.