← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Q1 Hacks Hit $482M as Attacks Shift From Code to People

Zephyra|April 15, 2026|BPF
EXECUTIVE SUMMARY

Web3 projects lost $482 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 67% decline from Q1 2025's $1.46 billion, but the composition of losses has changed in ways that challenge the industry's security model. Phi...

"The most expensive failures happen outside the code layer." — Yev Broshevan, CEO, Hacken

Executive Summary

Web3 projects lost $482 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 67% decline from Q1 2025's $1.46 billion, but the composition of losses has changed in ways that challenge the industry's security model. Phishing and social engineering accounted for $306 million — 63% of total damage — led by a single $282 million hardware wallet scam in January. Smart contract exploits contributed $86.2 million. Access control failures, including compromised keys and cloud services, added $71.9 million.

The data, corroborated by Sherlock's parallel Q1 report tracking 145 incidents totaling approximately $450 million, confirms a structural shift. Attackers are no longer primarily targeting code. They are targeting people, cloud infrastructure, and the operational seams between protocols. Six projects that had undergone formal audits — including Resolv Labs with 18 audits and Venus Protocol with five separate audit firms — still lost a combined $37.7 million. Meanwhile, a new phenomenon Sherlock labels "shadow contagion" demonstrates that a single exploit can cascade across composable DeFi markets, generating losses at protocols that were never directly attacked.

The Ethereum Foundation responded on April 14 by launching a $1 million audit subsidy program. Whether audit subsidies address the right problem — when 63% of losses stem from social engineering rather than code flaws — remains an open question.

Table of Contents

  1. Q1 2026 by the Numbers
  2. The Social Engineering Supercycle
  3. Audits Fail to Prevent Losses
  4. Shadow Contagion: The Resolv Case Study
  5. North Korean Operations Scale Up
  6. The Recovery Problem
  7. Security Economics: Cost vs. Damage
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

Q1 2026 by the Numbers

Hacken's report recorded 44 incidents with $482 million in total losses. Sherlock, using a broader methodology, counted 145 incidents at approximately $450 million. The discrepancy is methodological — Hacken includes off-chain phishing losses while Sherlock focuses on protocol-level exploits — but both converge on the same structural finding: the attack surface has migrated from smart contracts to infrastructure and human targets.

Monthly distribution:

  • January: $340–400 million across the majority of incidents. The $282 million hardware wallet social engineering attack dominated the month, accounting for over 80% of January's damage.
  • February: $26.5 million across 15 incidents, a 69% month-over-month decrease and the quarter's low point.
  • March: $52 million across 20 incidents, a 96% increase from February, driven by the Resolv Labs exploit ($25 million) and Truebit ($26.4 million).

Attack vector breakdown by dollar loss:

| Vector | Loss ($ millions) | Share | |--------|-------------------|-------| | Phishing / Social Engineering | 306.0 | 63.5% | | Smart Contract Exploits | 86.2 | 17.9% | | Access Control / Key Compromise | 71.9 | 14.9% | | Other | 17.9 | 3.7% |

According to Sherlock, smart contract exploit losses declined 89% year-over-year. The code is getting harder to attack. The people operating the code are not.

The Social Engineering Supercycle

The $282 million Trezor hardware wallet scam in January set the tone for the quarter. A single victim lost the funds through a social engineering campaign that bypassed all technical safeguards. No smart contract was exploited. No protocol was compromised. The attacker convinced the target to authorize transactions.

This pattern repeated at scale. Step Finance lost $40 million after a team member joined a video call with what turned out to be a North Korea-linked threat actor posing as a venture capitalist. The call installed malware that compromised private keys. Bitrefill suffered an infrastructure breach attributed to the same cluster of DPRK-affiliated groups.

The FBI reported 180,000 crypto-related complaints in 2025, with an average loss per victim of $62,604. These figures reflect retail-level phishing. The Q1 2026 data shows the same tactics applied at institutional scale, with per-incident damage in the tens of millions.

Hacken CEO Yev Broshevan stated that the industry's "most expensive failures happen outside the code layer." The data supports this assessment. Social engineering produced 3.5 times more dollar damage than smart contract exploits despite representing a smaller share of total incidents by count.

Audits Fail to Prevent Losses

Q1 2026 produced an uncomfortable data point for the security audit industry: audited projects lost more per incident than unaudited ones. According to Hacken's data, audited projects averaged $6.3 million in losses per incident, compared to $4.3 million for unaudited projects.

Six audited projects accounted for $37.7 million in losses. Resolv Labs had undergone 18 separate audits before an attacker compromised its AWS Key Management Service credentials and minted 80 million unbacked USR tokens. Venus Protocol, audited by five separate firms, fell to a donation attack — a pattern documented in academic literature since 2022.

Truebit lost $26.4 million to a Solidity contract bug that had been deployed approximately five years earlier. The vulnerability predated the project's most recent audits but was never caught.

The audit market in 2026 charges $5,000 for simple token contracts and up to $500,000 for complex protocols, according to Sherlock's pricing survey. A mid-complexity DeFi protocol budgets $60,000 to $120,000 for pre-launch audits. The industry rule of thumb allocates 5–10% of total development cost to security reviews. Blue-chip protocols with meaningful TVL routinely spend $150,000 to $500,000 annually on security.

These are not trivial sums. Yet the Q1 data suggests that audits, as currently structured, address a shrinking portion of the actual threat surface. When 63% of losses come from social engineering and 15% from access control failures, a code review — however thorough — covers at most 18% of realized risk.

The Ethereum Foundation's $1 million audit subsidy program, launched April 14, aims to make security reviews accessible to smaller teams. The program partners with Nethermind, Chainlink Labs, and Areta, and includes access to over 20 audit providers. The foundation frames this as part of its "Trillion Dollar Security" initiative. But the Q1 loss data raises a question the subsidy does not answer: what happens when the threat is not in the code?

Shadow Contagion: The Resolv Case Study

Sherlock's Q1 report introduces the term "shadow contagion" to describe a pattern that may define the next phase of DeFi risk: losses at protocols that were never directly exploited.

On March 22, an attacker compromised Resolv Labs' AWS KMS credentials and used the SERVICE_ROLE signing authority to mint 80 million unbacked USR stablecoins across two transactions. USR's price collapsed from $1.00 to $0.03. The attacker extracted approximately $23 million (11,409 ETH) in profits.

The direct damage was substantial. But the indirect damage was larger.

Fifteen lending vaults across Morpho Blue, Euler, Fluid, Venus, Lista, and other protocols had accepted USR or wrapped stUSR (wstUSR) as collateral. When USR depegged, oracles continued pricing wstUSR near $1.13. Traders bought depegged wstUSR on the open market at a fraction of face value, deposited it as collateral at the oracle's stale price, borrowed USDC against it, and withdrew. The lending markets were left holding worthless collateral.

Downstream damage:

  • Curve Finance LPs: $17 million in losses
  • Fluid / Instadapp: $17.5 million in potential bad debt, $300 million in outflows
  • Inverse Finance (DOLA): $340,000 backing hole
  • Morpho Blue: Bad debt across multiple vaults

Risk curators — including Gauntlet, Re7, MEV Capital, and others — had allocated capital to USR-collateralized vaults as yields spiked post-exploit. Automated allocation systems amplified exposure. According to Protos, a nearly identical pattern occurred in November 2025 when Stream Finance's $93 million loss crashed xUSD by 75%, but no systemic reforms followed.

The total cascading impact: a $23 million exploit generated over $500 million in combined liquidations and outflows across the composable DeFi stack. The ratio of direct exploit to cascading damage was approximately 1:22.

North Korean Operations Scale Up

DPRK-linked threat actors — tracked under designations UNC4736, AppleJeus, Citrine Sleet, and Gleaming Pisces — were attributed to the Drift Protocol attack ($285 million, which occurred April 1 and falls just outside the Q1 boundary) and the Step Finance compromise ($40 million). TRM Labs and Elliptic provided attribution for the Drift incident. The FBI's IC3 unit confirmed Lazarus Group's role in the 2025 Bybit hack ($1.5 billion).

According to Hacken, DPRK-linked clusters extracted approximately $2.04 billion from the crypto sector in 2025. Their playbook — fake VC outreach, malicious video call software, compromised employee endpoints — maps directly to the social engineering dominance observed in Q1 2026. These are not code exploits. They are intelligence operations that happen to target crypto infrastructure.

The Drift attack demonstrated the scale of patience involved: a six-month social engineering campaign culminated in a 12-minute execution window. The attacker fabricated collateral positions to drain protocol funds. This operational tempo — months of preparation for minutes of execution — makes conventional security tooling largely irrelevant.

The Recovery Problem

Immunefi's analysis of 425 publicly known incidents from 2021 to 2025 quantifies the long-term damage. Across 82 hacked tokens tracked in the study, the median price declined 61% within six months of a breach. 83.9% of hacked tokens remained below their pre-hack price after six months.

Fund recovery rates have deteriorated. In Q1 2026, only $6.5 million of stolen funds were recovered — from 1inch ($5 million) and Moby Trade ($1.5 million) — representing 0.4% of total losses. In Q1 2025, 21.2% of stolen funds were recovered. The decline is steep.

Immunefi CEO Mitchell Amador noted: "The stolen funds are only the first layer of damage. What follows is often more destructive: sustained token price suppression, reduced treasury capacity, leadership disruption, lost development time, and erosion of user trust."

Immunefi's data shows the industry lost $11.9 billion across 425 incidents from 2021 to 2025. The top five exploits in 2024–2025 accounted for 62% of all losses. Centralized exchange hacks produced $2.55 billion across just 20 incidents — 55% of two-year combined losses. The concentration of damage in a handful of events means prevention at the top of the distribution matters more than broad-based security improvements.

Security Economics: Cost vs. Damage

The Q1 data creates an uncomfortable arithmetic for protocol security budgets:

  • Average audit cost (mid-complexity DeFi): $60,000–$120,000
  • Average loss per audited project (Q1 2026): $6.3 million
  • Average loss per smart contract exploit (four-year average): $1.9 million
  • Total annual security budget (blue-chip protocol): $150,000–$500,000
  • Total Q1 2026 losses from non-code vectors: $377.9 million (78% of total)

The security industry is structured around code review. The threat has moved to infrastructure, operations, and social engineering. This creates a gap: protocols spend hundreds of thousands on audits while the majority of losses occur in areas those audits do not cover.

The SEC brought over 30 crypto-related enforcement actions in 2025, producing $2.6 billion in penalties and restitution — the highest total for the sector. The CFTC's digital asset cases comprised nearly half its enforcement docket, generating over $17 billion in monetary relief. Regulatory pressure is adding compliance costs — estimated at 5–10% of operating budgets for licensed entities — on top of security spending.

For protocols with meaningful TVL, the combined security and compliance burden now routinely exceeds $500,000 annually. Whether this spending is allocated against the right risks is the question Q1 2026 forces into the open.

Key Takeaways

  • $482 million lost in Q1 2026 across 44 incidents (Hacken), with 63% from social engineering and phishing — not code exploits.
  • Smart contract exploit losses fell 89% year-over-year (Sherlock), confirming the threat has migrated from on-chain code to off-chain operations.
  • Audited projects lost more per incident ($6.3M) than unaudited ones ($4.3M), raising questions about whether current audit models address the actual threat surface.
  • Shadow contagion from the $23M Resolv exploit generated $500M+ in cascading liquidations and outflows across 15 DeFi vaults that were never directly attacked.
  • DPRK-linked actors remain the most consistent operational threat, with $2.04 billion extracted in 2025 and continued operations in Q1 2026.
  • Fund recovery dropped to 0.4% of losses, down from 21.2% in Q1 2025. 83.9% of hacked tokens remain below pre-hack prices after six months.
  • The Ethereum Foundation launched a $1M audit subsidy on April 14, though code audits address at most 18% of Q1's realized loss surface.

Conclusion

Q1 2026 produced less total damage than Q1 2025 — $482 million versus $1.46 billion — but the composition of that damage is more concerning for the industry's security model. The attack surface has migrated from smart contracts to the people and infrastructure operating them. Audits, which consume the majority of protocol security budgets, covered at most 18% of the quarter's realized risk.

The Resolv incident demonstrated that DeFi composability, the feature that enables capital efficiency across lending markets, also enables loss propagation at a ratio of 1:22 between direct exploit and cascading damage. No protocol in the downstream blast radius was itself compromised. They were compromised by their integration with a compromised asset.

The industry's security spending is structured for a threat that is shrinking. The threat that is growing — social engineering, infrastructure compromise, and composability-driven contagion — receives a fraction of the attention and budget. Until that allocation changes, the gap between security spending and actual risk will continue to widen.

Sources & References

  1. Web3 Projects Lost $464.5M in Q1 2026 as Hacks Shift Beyond Code: Hacken — CoinTelegraph, April 14, 2026
  2. Web3 Hacks Drive $482M in Q1 Losses as Phishing Leads Attacks: Hacken — FinanceFeeds, April 14, 2026
  3. The Sherlock Web3 Security Report Q1 2026: Every Major Hack, Exploit, and Trends — Sherlock, April 2026
  4. Web3 Hacks Hit $482M in Q1 2026 as Attackers Target Infrastructure Over Code — Blockchain.News, April 2026
  5. REPORT: Web3 Hacks Hit Over $480M in Losses in Q1 2026 — BitKE, April 2026
  6. Crypto Hacks Average $25 Million as Largest Exploits Skew Losses: Immunefi — The Block, April 2026
  7. Hacked Crypto Tokens Drop 61% on Average and Rarely Recover: Immunefi — CoinTelegraph, April 2026
  8. 84% of Hacked Tokens Still Down Six Months Later: Immunefi — CoinMarketCap, April 2026
  9. Resolv Hack Shows DeFi Learned Nothing From Last Contagion — Protos, March 2026
  10. Ethereum Foundation Unveils $1M Audit Subsidy Program — CoinDesk, April 14, 2026
  11. Compliance Is Crypto's New Cost of Doing Business — PYMNTS, 2026
  12. Smart Contract Audit Pricing: A Market Reference for 2026 — Sherlock, 2026
  13. $52M Crypto Hacks in March Trigger 'Shadow Contagion' Across DeFi — CoinGape, March 2026