For most of the past decade, Web3 security work centered on smart contracts: patch the code, audit the logic, and look for exploitable bugs. A long-form analysis published by Foresight argues that the battlefield has changed. Attackers are no longer focused only on code. They are going after the trust chain around it.
The article opens with Bitget. On Sept. 24, 2026, Bitget lost about $387.5 million from its hot and warm wallets. According to the piece, the attackers breached backend systems, inserted fake transaction data, and triggered the exchange’s own approval process. Bitget’s CEO later said in a public statement, 「自家系统批准了转账」, translated as “our own system approved the transfer.” Private keys were not exposed, and the cold wallet was untouched.
Five months earlier, on April 18, 2026, KelpDAO saw roughly $290 million worth of rsETH minted out of thin air after an RPC node returned manipulated data. Foresight says the contract code itself was not wrong. The attackers obtained the RPC list used by LayerZero’s Decentralized Verifier Network, or DVN, compromised two separate clusters, and replaced op-geth with a malicious version. Those nodes returned false data only to DVN IP addresses while serving correct data to monitoring tools. A DDoS attack then pushed the system into failover mode and onto the poisoned nodes. DVN confirmed a transaction that never happened, and the bridge released 116,500 rsETH without a real burn.
Two weeks before that, on April 1, 2026, Drift lost about $285 million in 12 minutes after a member of its security council pre-signed a blank transaction. Foresight says the attackers had spent months building trust. Starting in the fall of 2025, they posed as a quantitative trading firm, met core contributors in person at international conferences, and even deposited more than $1 million of real funds into the Ecosystem Vault. Once that trust was in place, they persuaded a signer to approve what looked like a harmless governance transaction. The transfer of control was hidden with Solana’s durable nonce mechanism. Drift had also just changed its multisig to zero delay and removed the timelock, leaving no time to reverse course.
The article then points back to Bybit. On Feb. 21, 2025, about $1.45 billion was moved out of the exchange’s cold wallet, which Foresight describes as the largest publicly acknowledged theft in crypto to date. The attackers did not break Ethereum cryptography, did not find a bug in the Safe multisig contract, and did not directly touch private keys. Instead, they compromised a Safe{Wallet} developer machine and injected JavaScript into the signing interface. Three signers saw what appeared to be a routine cold-to-hot wallet transfer and approved it.
Across those four cases, losses add up to more than $2.4 billion. Foresight’s point is that none of them relied on an undiscovered smart contract 0day. The code had been audited. Formal verification had been done. Multisigs were in place. Cold wallets were separated. The money still disappeared.
Lower headline losses do not mean the threat is fading
The article says some people have argued that security improved in 2026 because industry losses in the first half ranged from $956 million to $1.39 billion, roughly half the prior year. Foresight pushes back on that reading. Remove the $1.45 billion Bybit outlier from 2025, and the picture changes: CertiK’s figures show losses up 28% year over year, SlowMist’s event count rose 50%, and the median loss per incident climbed 60.6% to $169,000.
In other words, the numbers look better mainly because 2026 did not produce another once-in-a-cycle mega theft. The article says attackers did not stop. They spread out. There were more incidents, and each one became more expensive.
Beyond signatures: the target is now the person behind them
Cryptography can prove that a signature is valid. It cannot prove why someone signed.
Foresight says 33 wallet compromise incidents in the first half of 2026 caused $445 million in losses, while 204 code vulnerability incidents caused $152 million. It also cites Hacken’s Q2 report, which said 88% of losses came from operational compromise and only 11% from smart contract flaws. Out of 67 incidents in that dataset, 44 were contract bugs, yet they accounted for less than one-tenth of the money lost.
Drift is presented as the clearest example. The attackers spent half a year building trust, then persuaded a security council member to sign what looked like a routine management transaction. Foresight describes Solana’s durable nonce as the equivalent of a signed blank check that can be cashed later. The result was 31 withdrawals in 12 minutes and the loss of more than half of the locked assets.
The article says North Korea’s Lazarus has industrialized this model. Fake resumes. Fake companies. LinkedIn profiles that look real. Entry into target firms. Access to SSO and VPN. Months of quiet movement until they reach the machine that signs. SlowMist’s figures, as cited by Foresight, show North Korea-linked groups stole $2.837 billion between January 2024 and September 2025. In 2025 alone, they stole $2.02 billion, or 76% of service-provider losses. Only 13.2% was recovered. One year after the Bybit theft, just 3.54% had been frozen.
The article’s conclusion is simple: attackers are not primarily looking for code bugs anymore. They are looking for people who can authorize transfers. Finding a signer is cheaper than finding an exploit.
The chain was not hacked. The dependencies around it were.
Foresight uses KelpDAO to make a broader point: the blockchain itself was not compromised. The surrounding infrastructure was.
The KelpDAO contracts were not written incorrectly, the article says, but the case became the first major loss directly caused by false data returned from an RPC node. That exposed a weakness the industry already knew about but often treated as background noise. Many so-called decentralized applications still rely on a small number of cloud providers and RPC vendors for reads. MetaMask defaults to Infura. dApp backends use Alchemy and QuickNode. L2 sequencers depend on the same node providers. Many of those services run on AWS us-east-1. A chain can have a thousand validators, Foresight argues, but if everyone trusts data from two or three cloud-backed RPC providers, the decentralization story is incomplete.
TRM Labs data cited in the article sharpens the point. Infrastructure and operational incidents account for only about 15% of events, yet they contribute about 76% of losses. SlowMist’s first-half data, also cited by Foresight, says supply chain attacks ranked third by incident count but first by dollars lost at about $298 million. KelpDAO alone made up $290 million of that total.
The article also says traditional hackers have started using blockchains as infrastructure for their own operations. Chainalysis described the pattern in a September 2026 report as “Blockchain Dead Drops.” Malicious code and command instructions are no longer stored only on servers. They are written into BSC smart contracts and Bitcoin transactions. Shut down a domain or pull a server offline, and the data still remains on-chain. Any infected machine that can query the chain can retrieve fresh instructions. Foresight says this activity grew 420% over the past 12 months, with North Korea- and Iran-linked groups responsible for about two-thirds of new activity.
Google Threat Intelligence also observed UNC5342 using the EtherHiding technique from February 2025 onward to target crypto developers through fake recruiting campaigns. The code was hidden in smart contracts on TRON, Aptos, and BNB Chain. In Foresight’s framing, blockchain immutability — one of the technology’s strongest properties — is being repurposed as a durable command-and-control layer.
Permissions have become the attack surface
Foresight says Web3 has moved from an exploit economy to a permission economy.
The old sequence was straightforward: find a bug, exploit the bug, move the funds. The new sequence is different: find the person with signing authority, persuade that person to sign, and move the funds through a transaction that is technically valid.
Bybit and Bitget are the clearest pair in the article. In the Bybit case, signers believed they were moving funds to a hot wallet for liquidity management. In reality, they approved a transfer to the attackers. In the Bitget case, the attackers did not even need to alter the front end. They entered backend systems, inserted false transaction data, and let the exchange’s own approval flow classify the transfer as a normal internal movement. The system signed it out by itself.
Both losses were “legitimate” in a narrow technical sense, the article argues. The multisig process completed. The signatures were real. The contracts executed according to the rules. The real question is not who can break the system, but who has the authority to approve a transfer and what data they rely on when they do it. If the signing interface can be altered, if approval systems can be fed false data, and if all signers depend on the same poisoned RPC or the same cloud provider, then 3-of-5 is decentralized only on paper.
Foresight calls this pseudo-decentralization. A protocol may achieve mathematical 3-of-5 decentralization at the contract layer, while the infrastructure layer still runs on one cloud provider, one RPC source, and one browser operated by one person.
The article lists several 2026 examples. KelpDAO used a 1-of-1 single DVN setup. Drift had a 2-of-5 zero-delay multisig plus what the article describes as a blank-check signing pattern. Resolv Labs relied on a single AWS KMS key. Wasabi had one external account holding all admin permissions. None of those cases involved a new vulnerability. All of them were known configuration risks and single points of failure.
Dune data cited by Foresight says 47% of applications in the LayerZero ecosystem still use a 1-of-1 DVN, 45% use two, and only 5% use three or more. The article says the danger of single points is widely understood, but many teams leave them in place because fixing them is inconvenient. Fifteen months before the KelpDAO incident, a developer had already urged the team on the Aave governance forum to add more validators. Nothing changed. After the incident, the parties ended up in court, and LayerZero later said it would no longer sign for any application using a 1-of-1 configuration.
The article’s warning is blunt: the most dangerous transactions often look the most compliant.
AI is changing the economics of attack
Foresight argues that AI has not made attacks inherently smarter. It has made them scalable.
In the past, a scammer might spend a month building a social engineering setup for one target. That was expensive, so phishing relied on broad distribution and low conversion. Now AI can generate fake identities, fake websites, phishing copy, target lists, and code scans at machine speed.
The article cites a North Korea-linked operation called HexagonalRodent, which allegedly stole 26,584 wallets from 2,726 developer machines in three months. Its backend reportedly included a live infostealer view, VNC-style remote control, a browser file manager, and a wallet “performance dashboard” organized by team and member. Delivery came through VS Code tasks.json with runOn: “folderOpen,” meaning the payload executed as soon as a developer opened the project folder, with no extra click required.
Foresight says attackers used ChatGPT and Cursor to write malicious code, used AI to generate fake companies and executive profiles, and even checked whether backdoors could evade antivirus tools before deployment. It cites a TRM Labs AI crime index that rose from 28 in 2024 to 54, nearly doubling. Deepfake scam losses in 2026, the article says, had already reached 263% of the full-year 2025 total.
The piece also points to SCONE-bench, a benchmark created by researchers from Anthropic and MATS using 405 real-world attacked smart contracts. According to the article, AI agents reproduced attacks worth $4.6 million in a simulator. When screening 2,849 new contracts with no known vulnerabilities, they found two 0days worth $3,694 at an API cost of $3,476, for an ROI of about 1.06x. That return is barely above break-even, Foresight notes, but it sees the direction as more important than the current number. If model capability improves by another generation, or if the contract universe grows by another order of magnitude, “AI scanning the chain and monetizing automatically” could become a profitable business line.
Defenders are using AI too. Foresight says someone used Claude Opus 4.8 one day after release to identify a soundness flaw in the ZK circuit of Zcash’s Orchard privacy pool, a bug that had been present for four years. An attacker could have minted unlimited ZEC without detection. Zcash responded by activating an emergency hard fork to isolate the risk. The article also notes that Zcash’s turnstile mechanism checks accounting across pools, so even if Orchard had an internal failure, total supply would not inflate without bound. Foresight presents that as an example of runtime protection catching what cryptography alone did not.
The broader point is that AI is shifting cost onto defenders. A highly customized phishing email can now be produced in seconds. A convincing fake video meeting can be assembled in minutes. Scanning thousands of old contracts is no longer expensive. Defenders must secure every entry point. Attackers need only one success. Foresight says four social engineering attacks caused $310 million in losses, accounting for 85% of phishing losses. The net effect is a move away from mass phishing and toward high-value targeting.
Old code is back in scope as well. Code vulnerability incidents rose from 78 in the first quarter of 2026 to 126 in the second, according to the article. Attackers are systematically revisiting contracts that were deployed years ago and never re-audited. On BNB Chain alone, Foresight says there were 33 attacks on old tokens in the first half, with losses ranging from tens of thousands to hundreds of thousands of dollars. The article attributes that pattern to AI-assisted batch scanning.
AI agents themselves are becoming a new target. Because agents can read context, call tools, and sign transactions, a malicious instruction hidden inside otherwise normal input can turn into a direct financial loss. After EIP-7702 went live, a USENIX 2026 study found that 63% of malicious delegations pointed to malicious contracts. Foresight says account abstraction gives users convenience, but it also widens the entry point for attackers. In the future, the threat is not only a human hacker. It is also an agent that receives a poisoned prompt and then efficiently, lawfully, and disastrously sends money to the wrong place.
The limits of audits are becoming clearer
Foresight cites CoinGecko’s 2026 Crypto Security Report, which recorded 245 incidents and $3.63 billion in total losses. Of that, 147 independently audited protocols accounted for 88.44% of the losses. Only 11% of attacks hit contract flaws that audits were designed to cover. Supply chain and infrastructure weaknesses caused more than $1.8 billion.
The article does not argue that audits are useless. It argues that audits are aimed at a shrinking share of where attackers strike. Audits review contract code at deployment. The major attacks of 2026 hit deployment keys, RPC dependencies, multisig processes, supply chains, and code added after the audit was complete. Foresight compares it to checking the quality of a door lock when the thief came through the window.
Supply chain attacks ranked first by losses in 2026, at $298 million by SlowMist’s measure. A malicious npm package with massive weekly downloads can move from front ends to SDKs to wallets and cause users to sign the wrong transaction. The attacker does not need to break the system if the user installs the payload voluntarily. Foresight says North Korean operators set up a fake company called Veltrix Capital, sent offers to open-source maintainers, and planted 24 malicious packages on npm and 12 on PyPI.
The article says the old security playbook was simple: write code, audit it, launch a bug bounty, go live, and pause the contract if something breaks. That model assumed the biggest risk was a bug in the code. If the biggest risk is somewhere else, the model no longer covers the field.
Defense has to follow the attack surface
Foresight says the first diagram a security team should draw is no longer just the smart contract architecture. It should be the full path of money from entry to exit. From the user wallet to the treasury, which signing nodes are involved, which admins, which oracles, which bridges? At every point, the questions should be practical: if this node is compromised, how much can move? How many signatures are required? Can it execute automatically? Is there a timelock? Is there a second place to verify the action? Can the system be stopped immediately? The article says that exercise is more useful than one more contract audit.
It then argues against concentrating dependencies in one failure domain. The key question is not how many signers exist, but whether those signers rely on the same trust source. If five signers all use the same cloud provider, the same browser, the same hardware wallet brand, and the same RPC feed, then 3-of-5 remains a single point in practice. Real multisig separation, in Foresight’s view, means hardware from different vendors, networks from different carriers, keys split across jurisdictions, and a clean separation between offline and online signing.
The article points to a July 2026 Solana incident as a reminder that infrastructure concentration matters. TeraSwitch released a flawed interconnect route that spread through a route reflector in Amsterdam. As a result, 28.83% of staked SOL went offline at the same time, leaving the network only about 4.5 percentage points away from the 33.34% finality threshold. About 90 validators were affected, and recovery took roughly 40 minutes. Solana had 699 staked validators on-chain, but a single autonomous system, AS20326, carried about 27.34% of staked SOL. Validator decentralization on-chain, the article says, is not the same as decentralization in hosting and upstream routing.
That is why “more decentralization” is now extending from the consensus layer to the dependency layer. Shared sequencers, multiple DVNs, and failure-domain independence are the kinds of changes Foresight says actually break single points apart.
On RPC, the article says trust should not be automatic. Systems that touch large amounts of money — oracles, bridges, liquidations, governance, treasuries — should not make decisions from one RPC response. At minimum, they should cross-check data across three providers. If the responses diverge, the event should be treated as a possible attack, not dismissed as a network glitch. High-value paths should run their own full nodes rather than rely entirely on third parties. After KelpDAO, Foresight says, verifiable RPCs that can return cryptographic proofs may move from a product differentiator to an institutional requirement.
Wallets also need to check more than signature validity. They need to check whether the transaction matches the user’s intent. If a user says “swap 1,000 USDC for ETH with slippage no greater than 0.5%,” the wallet should simulate the transaction, run it through a risk engine, and confirm that the action actually does that before asking for a signature. Malicious calldata, unlimited approvals, address substitution, and front-end tampering can often be stopped at that layer.
A four-layer defense model
Foresight lays out four layers of defense.
The first is permission governance. Ban 1-of-1 configurations, whether for DVNs, multisigs, or ADMIN_ROLE. Force timelocks on all high-privilege actions. Separate deployment keys from runtime keys, and transfer the deployer EOA immediately after deployment instead of leaving it with long-term admin power.
The second is infrastructure hardening. Production systems should connect to at least two RPC providers on different cloud vendors for failover. Critical decisions — withdrawals, minting, oracle updates — should verify block headers or Merkle proofs rather than trust eth_call output directly.
The third is runtime protection: circuit breakers, rate limits, and alerts for abnormal transfer sizes. Foresight says the goal is to reduce “maximum possible loss” from total value locked to “time window multiplied by limit.” It points to THORChain’s Solvency Checker and Outbound Delay as a model. Observer nodes compare actual balances on the underlying native chain with the protocol’s internal state machine in real time. Even if on-chain logic or an RPC node is compromised and assets are fabricated inside the state machine, a mismatch in reconciliation can suspend large outbound transfers and use time as a physical brake.
The fourth is continuous review instead of one-time auditing. Attack methods evolve faster than launch-day audits. Monitoring matters because it observes what the system is doing now, not what the code looked like three months ago.
The article also says teams should accept that compromise will happen. The goal should not be “never get breached.” It should be “do not let one breach empty the treasury.” A treasury should not allow a single transaction to move $100 million. Small transfers can be automated. Larger ones should trigger a timelock. Very large ones should require manual review. On-chain monitoring should continuously watch transaction behavior, permission changes, oracle deviations, RPC inconsistencies, and gas anomalies. Security, in the article’s framing, is not one thing. It is prevention, detection, blocking, and tracing at the same time.
Insurance and capital will price security architecture
Foresight closes by discussing shared risk. Hours after the KelpDAO incident, Aave froze the rsETH market, and several protocols helped absorb bad debt. The article says decentralized insurance is not only about paying claims after the fact. It spreads risk across network participants and gives token holders a reason to care about protocol security.
It notes that Nexus Mutual is planning OpSec Failure Cover, while OpenCover has launched Covered Vaults that embed risk transfer into vault products. It also points to a more complex capital structure in which the same restaked capital can both secure a network and insure DeFi treasury risk. If something goes wrong, the paired capital can be slashed automatically to compensate depositors.
In that framework, insurance pricing becomes a market price for security architecture. An insurer deciding whether to underwrite a protocol will ask how many multisig signers it has, whether there is a timelock, whether RPC is a single point of failure, how many independent oracle sources exist, what the treasury’s maximum transfer size is, and whether circuit breakers are in place. That is no longer just a security team’s internal checklist. It is capital markets assigning a value to the protocol’s security design.
From finding bugs to finding trust
Foresight’s retrospective runs across three years. In 2024, total losses reached $2.36 billion, and phishing overtook private key leaks as the biggest threat, forcing the industry to confront the human layer. In February 2025, the $1.45 billion Bybit theft pushed annual losses to $3.35 billion and made front-end supply chain risk and signing interfaces impossible to ignore. In 2026, KelpDAO, Drift, and Bitget together accounted for more than $900 million, turning RPC trust and permission design into the main battleground while AI pushed attacks toward assembly-line scale.
The route attackers have taken is now clear, the article says: from attacking code to attacking people, from attacking on-chain logic to attacking off-chain infrastructure, and from searching for vulnerabilities to searching for trust relationships. Across seven major public chains, direct losses at the consensus and execution layers over the past three years were close to zero. The chains themselves have become harder targets. The biggest losses are happening around them — in people, process, configuration, and infrastructure.
That leads to Foresight’s final claim. Web3 has not simply become “unsafe.” The most valuable attack surface has moved from inside the code to outside it. Cryptography can prove that a signature is real, that a transaction was not altered, and that on-chain records cannot be erased. It cannot prove that the signer was not deceived, that the data shown to the signer was accurate, that an approval request was genuine, or that the balance returned by an RPC actually existed on-chain. Those are not cryptography problems. They are trust problems.
Future Web3 security, in this view, is not just about code. It is about the whole system and the full trust chain around it. The design goal is not “we will never be breached.” It is “even if one person is compromised, one RPC is poisoned, one dependency is backdoored, one signer is deceived, or one agent makes the wrong call, the entire system’s funds still cannot be moved in one shot.”
The question the industry used to ask was whether a contract had a vulnerability. The question Foresight says it should ask next is different: who can move the money, what data do they rely on, can that data be trusted, and who catches the failure if something goes wrong?


