Web3 Security Losses Hit $1.3 Billion in H1 2026 Across 344 Incidents, Down Year-Over-Year Due to Historical 2025 Outliers
According to the latest CertiK Hack3D report, the Web3 ecosystem suffered roughly $1.3 billion in losses across 344 security incidents during the first half of 2026, marking a 46.8% decrease in stolen funds compared to the same period in 2025. While this decline might appear positive on the surface, security experts emphasize that this figure is misleading. The dramatic year-over-year reduction is entirely driven by a massive, anomalous $1.45 billion breach of the bybit exchange that occurred in early 2025, which heavily skewed historical data.
When excluding that specific 2025 outlier for a more accurate comparison, the underlying Web3 security losses actually surged by approximately 28%. This indicates that the ecosystem has not become significantly safer, but rather that malicious actors are evolving their tactics. The data reveals that while incident volume may fluctuate, the financial impact remains high as hackers focus on more complex, high-value targets rather than simpler smart contract exploits.
Modern attackers are increasingly shifting toward targeted infrastructure compromises and private key vulnerabilities. This trend serves as a stark reminder that operational security and infrastructure protection remain the weakest links in the Web3 landscape.