Web3 lost $1.32 billion in H1 2026 as attackers shifted from code to people and operations
Web3 security losses reached about $1.32 billion across 344 incidents in the first half of 2026, according to a Foresight News report citing CertiK, TRM Labs and SlowMist. The sharpest damage no longer came from smart contract bugs alone. Instead, major losses clustered around operational failures such as key management, credential compromise, social engineering and supply-chain attacks. CertiK said that, excluding Bybit’s $1.46 billion single incident from the prior year, H1 incidents still rose 28% year over year. SlowMist said operational failures accounted for 53 of 182 cases it tracked, or 29.1%, yet represented 76.6% of losses. TRM Labs reported a similar split, with infrastructure and operational weaknesses making up only about 15% of incidents but roughly 76% of total losses. The report argues that AI is changing the economics of attacks by lowering cost, speeding up exploit development and widening the range of viable targets. Researchers and security firms interviewed by Foresight News said that trend is compressing response windows and pushing the industry beyond one-off code audits toward continuous operational security, key controls, monitoring and incident readiness.








