Q2 2026 Web3 Exploit Report
Back to Blog

Q2 2026 Web3 Exploit Report

CD Security
Reports
Jul 9, 2026
3 min read

How Protocols Got Drained

The second quarter of 2026 is the most damaging quarter in Web3 security so far this year. CD Security tracked every protocol-level exploit across April, May, and June - no scams, no phishing, no rug pulls. Just the technical failures that drained real funds from real protocols.

Here's what the data shows.

📥 Download the full report: Q2 2026 Web3 Exploit Report (PDF)


$780.7M lost across 92 incidents in 90 days

92 protocol exploits. $780.7M gone. Two incidents alone — Drift Trade ($295M) and Kelp ($293M) — account for 75% of that total. Both were infrastructure failures, not smart contract bugs.

April was the worst month by far, recording $644.85M in losses in a single month — the most damaging month across the entire first half of 2026. Strip out Drift and Kelp, and the quarter looks entirely different: 90 incidents, $192.7M lost. Context matters.

q2 2026 web3 exploit report 39fa406e


The two categories that matter

Protocol Logic failures drove 83% of incidents — access control exploits, bridge verification bypasses, flash loan manipulation, fake proof attacks. These are not new patterns. They keep appearing because protocols keep deploying unaudited code.

Infrastructure failures — private key compromises, admin key exploits, compromised signing setups — accounted for only 17% of incidents but caused $651.5M in losses, 83% of the quarter's total damage. Six private key compromises hit in May alone. Once an attacker has valid signatures, the on-chain code behaves exactly as designed. There is no last line of defense.

The math is brutal: infrastructure failures are rare but almost always catastrophic.

q2 2026 web3 exploit report 5c32ba03


Q2 2026 vs Q2 2025 — what changed

Smart contract exploit losses fell 53% year-over-year — from $276M in Q2 2025 to $129M in Q2 2026. That is genuine progress on code security.

Infrastructure losses moved in the opposite direction: up 248%, from $187M to $651.5M. The industry is getting better at writing safer contracts and worse at protecting the keys that control them. The attack surface shifted from code to operations.
q2 2026 web3 exploit report faceb97e


The three biggest hacks

Drift Trade — $295M (April 1). Admin key compromise combined with social engineering, durable nonce transactions, and a fake collateral asset on Solana. The contracts worked exactly as designed. The attacker became the admin.

Kelp — $293M (April 18). LayerZero OFT bridge exploit via a compromised 1-of-1 DVN verification layer. The on-chain transactions were valid. The bridge accepted a forged cross-chain state because one verifier became a single point of failure. Kelp paused contracts fast enough to block a second $95M attempt.

Humanity — $32M (June 8). Spear-phishing attack on a director's laptop recovered enough multisig keys to cross the signing threshold. Malicious contract upgrades followed. The protocol later sunsetted the token and launched a recovery process.


What this means for protocol teams

The average Protocol Logic loss in Q2 2026 was $1.7M. The average Infrastructure loss was $40.7M. The cost of a quality audit and proper key management is a fraction of either number.

The full report includes complete incident logs for all 92 exploits, chain breakdown, attack technique analysis, and a Q2 2025 vs Q2 2026 comparison.

📥 Download the Q2 2026 Web3 Exploit Report →



CD Security is a specialized Web3 security firm with over three years of experience auditing smart contracts and protecting high-value protocols across the ecosystem. 150+ completed audits, senior auditors only, start as early as 24h after the request.

Book an audit at cdsecurity.io