Web3 projects lost $482 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 67% decline from Q1 2025's $1.46 billion, but the composition of losses has changed in ways that challenge the industry's security model. Phi...
"The most expensive failures happen outside the code layer." — Yev Broshevan, CEO, Hacken
Web3 projects lost $482 million across 44 incidents in Q1 2026, according to Hacken's quarterly security report published April 14. The figure represents a 67% decline from Q1 2025's $1.46 billion, but the composition of losses has changed in ways that challenge the industry's security model. Phishing and social engineering accounted for $306 million — 63% of total damage — led by a single $282 million hardware wallet scam in January. Smart contract exploits contributed $86.2 million. Access control failures, including compromised keys and cloud services, added $71.9 million.
The data, corroborated by Sherlock's parallel Q1 report tracking 145 incidents totaling approximately $450 million, confirms a structural shift. Attackers are no longer primarily targeting code. They are targeting people, cloud infrastructure, and the operational seams between protocols. Six projects that had undergone formal audits — including Resolv Labs with 18 audits and Venus Protocol with five separate audit firms — still lost a combined $37.7 million. Meanwhile, a new phenomenon Sherlock labels "shadow contagion" demonstrates that a single exploit can cascade across composable DeFi markets, generating losses at protocols that were never directly attacked.
The Ethereum Foundation responded on April 14 by launching a $1 million audit subsidy program. Whether audit subsidies address the right problem — when 63% of losses stem from social engineering rather than code flaws — remains an open question.
Hacken's report recorded 44 incidents with $482 million in total losses. Sherlock, using a broader methodology, counted 145 incidents at approximately $450 million. The discrepancy is methodological — Hacken includes off-chain phishing losses while Sherlock focuses on protocol-level exploits — but both converge on the same structural finding: the attack surface has migrated from smart contracts to infrastructure and human targets.
Monthly distribution:
Attack vector breakdown by dollar loss:
| Vector | Loss ($ millions) | Share | |--------|-------------------|-------| | Phishing / Social Engineering | 306.0 | 63.5% | | Smart Contract Exploits | 86.2 | 17.9% | | Access Control / Key Compromise | 71.9 | 14.9% | | Other | 17.9 | 3.7% |
According to Sherlock, smart contract exploit losses declined 89% year-over-year. The code is getting harder to attack. The people operating the code are not.
The $282 million Trezor hardware wallet scam in January set the tone for the quarter. A single victim lost the funds through a social engineering campaign that bypassed all technical safeguards. No smart contract was exploited. No protocol was compromised. The attacker convinced the target to authorize transactions.
This pattern repeated at scale. Step Finance lost $40 million after a team member joined a video call with what turned out to be a North Korea-linked threat actor posing as a venture capitalist. The call installed malware that compromised private keys. Bitrefill suffered an infrastructure breach attributed to the same cluster of DPRK-affiliated groups.
The FBI reported 180,000 crypto-related complaints in 2025, with an average loss per victim of $62,604. These figures reflect retail-level phishing. The Q1 2026 data shows the same tactics applied at institutional scale, with per-incident damage in the tens of millions.
Hacken CEO Yev Broshevan stated that the industry's "most expensive failures happen outside the code layer." The data supports this assessment. Social engineering produced 3.5 times more dollar damage than smart contract exploits despite representing a smaller share of total incidents by count.
Q1 2026 produced an uncomfortable data point for the security audit industry: audited projects lost more per incident than unaudited ones. According to Hacken's data, audited projects averaged $6.3 million in losses per incident, compared to $4.3 million for unaudited projects.
Six audited projects accounted for $37.7 million in losses. Resolv Labs had undergone 18 separate audits before an attacker compromised its AWS Key Management Service credentials and minted 80 million unbacked USR tokens. Venus Protocol, audited by five separate firms, fell to a donation attack — a pattern documented in academic literature since 2022.
Truebit lost $26.4 million to a Solidity contract bug that had been deployed approximately five years earlier. The vulnerability predated the project's most recent audits but was never caught.
The audit market in 2026 charges $5,000 for simple token contracts and up to $500,000 for complex protocols, according to Sherlock's pricing survey. A mid-complexity DeFi protocol budgets $60,000 to $120,000 for pre-launch audits. The industry rule of thumb allocates 5–10% of total development cost to security reviews. Blue-chip protocols with meaningful TVL routinely spend $150,000 to $500,000 annually on security.
These are not trivial sums. Yet the Q1 data suggests that audits, as currently structured, address a shrinking portion of the actual threat surface. When 63% of losses come from social engineering and 15% from access control failures, a code review — however thorough — covers at most 18% of realized risk.
The Ethereum Foundation's $1 million audit subsidy program, launched April 14, aims to make security reviews accessible to smaller teams. The program partners with Nethermind, Chainlink Labs, and Areta, and includes access to over 20 audit providers. The foundation frames this as part of its "Trillion Dollar Security" initiative. But the Q1 loss data raises a question the subsidy does not answer: what happens when the threat is not in the code?
Sherlock's Q1 report introduces the term "shadow contagion" to describe a pattern that may define the next phase of DeFi risk: losses at protocols that were never directly exploited.
On March 22, an attacker compromised Resolv Labs' AWS KMS credentials and used the SERVICE_ROLE signing authority to mint 80 million unbacked USR stablecoins across two transactions. USR's price collapsed from $1.00 to $0.03. The attacker extracted approximately $23 million (11,409 ETH) in profits.
The direct damage was substantial. But the indirect damage was larger.
Fifteen lending vaults across Morpho Blue, Euler, Fluid, Venus, Lista, and other protocols had accepted USR or wrapped stUSR (wstUSR) as collateral. When USR depegged, oracles continued pricing wstUSR near $1.13. Traders bought depegged wstUSR on the open market at a fraction of face value, deposited it as collateral at the oracle's stale price, borrowed USDC against it, and withdrew. The lending markets were left holding worthless collateral.
Downstream damage:
Risk curators — including Gauntlet, Re7, MEV Capital, and others — had allocated capital to USR-collateralized vaults as yields spiked post-exploit. Automated allocation systems amplified exposure. According to Protos, a nearly identical pattern occurred in November 2025 when Stream Finance's $93 million loss crashed xUSD by 75%, but no systemic reforms followed.
The total cascading impact: a $23 million exploit generated over $500 million in combined liquidations and outflows across the composable DeFi stack. The ratio of direct exploit to cascading damage was approximately 1:22.
DPRK-linked threat actors — tracked under designations UNC4736, AppleJeus, Citrine Sleet, and Gleaming Pisces — were attributed to the Drift Protocol attack ($285 million, which occurred April 1 and falls just outside the Q1 boundary) and the Step Finance compromise ($40 million). TRM Labs and Elliptic provided attribution for the Drift incident. The FBI's IC3 unit confirmed Lazarus Group's role in the 2025 Bybit hack ($1.5 billion).
According to Hacken, DPRK-linked clusters extracted approximately $2.04 billion from the crypto sector in 2025. Their playbook — fake VC outreach, malicious video call software, compromised employee endpoints — maps directly to the social engineering dominance observed in Q1 2026. These are not code exploits. They are intelligence operations that happen to target crypto infrastructure.
The Drift attack demonstrated the scale of patience involved: a six-month social engineering campaign culminated in a 12-minute execution window. The attacker fabricated collateral positions to drain protocol funds. This operational tempo — months of preparation for minutes of execution — makes conventional security tooling largely irrelevant.
Immunefi's analysis of 425 publicly known incidents from 2021 to 2025 quantifies the long-term damage. Across 82 hacked tokens tracked in the study, the median price declined 61% within six months of a breach. 83.9% of hacked tokens remained below their pre-hack price after six months.
Fund recovery rates have deteriorated. In Q1 2026, only $6.5 million of stolen funds were recovered — from 1inch ($5 million) and Moby Trade ($1.5 million) — representing 0.4% of total losses. In Q1 2025, 21.2% of stolen funds were recovered. The decline is steep.
Immunefi CEO Mitchell Amador noted: "The stolen funds are only the first layer of damage. What follows is often more destructive: sustained token price suppression, reduced treasury capacity, leadership disruption, lost development time, and erosion of user trust."
Immunefi's data shows the industry lost $11.9 billion across 425 incidents from 2021 to 2025. The top five exploits in 2024–2025 accounted for 62% of all losses. Centralized exchange hacks produced $2.55 billion across just 20 incidents — 55% of two-year combined losses. The concentration of damage in a handful of events means prevention at the top of the distribution matters more than broad-based security improvements.
The Q1 data creates an uncomfortable arithmetic for protocol security budgets:
The security industry is structured around code review. The threat has moved to infrastructure, operations, and social engineering. This creates a gap: protocols spend hundreds of thousands on audits while the majority of losses occur in areas those audits do not cover.
The SEC brought over 30 crypto-related enforcement actions in 2025, producing $2.6 billion in penalties and restitution — the highest total for the sector. The CFTC's digital asset cases comprised nearly half its enforcement docket, generating over $17 billion in monetary relief. Regulatory pressure is adding compliance costs — estimated at 5–10% of operating budgets for licensed entities — on top of security spending.
For protocols with meaningful TVL, the combined security and compliance burden now routinely exceeds $500,000 annually. Whether this spending is allocated against the right risks is the question Q1 2026 forces into the open.
Q1 2026 produced less total damage than Q1 2025 — $482 million versus $1.46 billion — but the composition of that damage is more concerning for the industry's security model. The attack surface has migrated from smart contracts to the people and infrastructure operating them. Audits, which consume the majority of protocol security budgets, covered at most 18% of the quarter's realized risk.
The Resolv incident demonstrated that DeFi composability, the feature that enables capital efficiency across lending markets, also enables loss propagation at a ratio of 1:22 between direct exploit and cascading damage. No protocol in the downstream blast radius was itself compromised. They were compromised by their integration with a compromised asset.
The industry's security spending is structured for a threat that is shrinking. The threat that is growing — social engineering, infrastructure compromise, and composability-driven contagion — receives a fraction of the attention and budget. Until that allocation changes, the gap between security spending and actual risk will continue to widen.