Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Why Smart Contract Audits Couldn’t Stop Web3’s Worst Quarter

CryptoExpert by CryptoExpert
July 23, 2026
in Bitcoin News
0
Why Smart Contract Audits Couldn't Stop Web3's Worst Quarter
  • Facebook
  • Twitter
  • Pinterest


Key Takeaways

Hacken reported $763.9 million extracted across 67 Web3 security incidents in Q2 2026.Over 88% of total losses shifted from smart contract flaws to operational and key management compromises.Security leaders like Leo Fan expect threat actors to target operational controls rather than code in H2 2026.

Q2 2026 Security Breakdown

The second quarter of 2026 was the most severe period for Web3 security since the second quarter of 2025, with threat actors extracting $763.9 million across 67 security incidents. The quarter’s defining shift was a fundamental change in vulnerability profiles: Code is no longer the primary attack surface; operational controls and key management are.

More than 88% of total losses stemmed from operational compromises rather than flaws in smart contract logic. Institutional capital is already adjusting, shifting due diligence priorities away from point-in-time audits and toward continuous monitoring, privileged-access governance, and multi-participant authorization frameworks.

According to Hacken’s quarterly security and compliance report, key and infrastructure compromises accounted for 88.3% of all stolen funds, or about $674.5 million. Smart contract bugs remained the most common attack type — 44 of 67 incidents — but represented only roughly 11% of total losses. About 75.5% of all losses came from just two incidents attributed to North Korean threat actors, while only 9% of tracked projects maintain continuous monitoring and 4% combine audits, bug bounties and live monitoring.

A core finding from the second quarter is that 14 audited protocols were breached—a stark indicator of the expanding rift between what a smart contract audit actually evaluates and where threat actors actually strike. For security experts, these breaches lay bare the fatal flaw of treating a point-in-time code review as an all-encompassing security shield.

okex

“The biggest misconception is that an audit is a security certificate,” said Leo Fan, founder of Cysic. “It is actually a scoped assessment of a particular codebase at a particular point in time. An audit does not automatically cover signer devices, cloud infrastructure, operational permissions, deployed bytecode, later upgrades, third-party dependencies or old contracts that remain callable.”

Eric Swartz, founding general partner and general counsel of Panther Hollow Ventures, echoed that treating audits as a finish line leaves protocols exposed. “An audit tells you how a system looked at a particular moment in time,” Swartz said. “It doesn’t guarantee that future upgrades, operational changes or new attack methods won’t introduce risk. The strongest teams see audits as one part of a much broader security programme.”

Samuel Videau, CTO at Genius, noted that the scope section of an audit report often reveals what wasn’t evaluated. “Almost 90% of Q2 losses came from keys, signers and infrastructure, all outside that scope section, and 14 audited projects got drained anyway,” Videau said. “The report card is not the security program.”

Himanshu Sahay, CTO and co-founder of Arch, emphasized that audits cannot stand alone. “An audit is an important point-in-time assessment of the code and architecture that was reviewed, but it cannot account for every operational risk or future change to a system,” Sahay said. “Security needs to be treated as an ongoing process.”

Bypassing Code: The Soft Underbelly of Off-Chain Infrastructure

In the meantime, as smart contract defenses mature and on-chain logic has increasingly grown harder to compromise, threat actors have pivoted decisively. Rather than breaking through heavily guarded front doors, attackers are systematically bypassing code entirely to exploit the soft underbelly of off-chain infrastructure.

“The most underestimated surface is the off-chain control plane: signer devices, key-generation and rotation procedures, cloud identities, CI/CD pipelines, backend services, bridge validators and emergency admin paths,” Fan said. “Teams often secure key storage but pay less attention to how keys are actually used… when compromised, attackers can produce transactions that are technically valid onchain, making prevention and detection much harder.”

The cloud perimeter itself presents a false sense of security for many Web3 developers.

“The biggest assumption is that using a major cloud provider makes an application secure by default,” said Jerald David, CEO of Lynq. “Cloud providers secure the underlying infrastructure, but teams are still responsible for how systems are configured, how credentials are managed and who has access.”

Videau, meanwhile, warned that improper architecture can nullify multisig protection. “The whole operation runs on over-permissioned service roles and CI/CD pipelines that can touch production keys, and if one service account can read your signing key, your multisig is theater,” Videau said. “Deprecated contracts still holding admin rights are another vector: Code you shipped two years ago is a live door, and attackers don’t care what you consider in scope.”

As institutional allocators recalibrate their risk models, the bar for capital deployment has risen significantly. “Institution-ready” is no longer defined by a clean audit report, but by proof of operational maturity, enterprise-grade governance, and resilient key-management controls.

“I look first at operational maturity,” David said. “Can the team clearly explain how capital moves through the system, where the key points of control are and how risks are monitored? Institutions need predictability and transparency.”

Sahay noted that no single control guarantees institutional backing on its own. “Institutions want to understand how critical systems are accessed, how permissions are managed, how activity is monitored and what processes exist if something goes wrong,” Sahay said. “It is the combination of strong controls, transparency and operational discipline that ultimately builds confidence.”

When evaluating protocols, Fan focuses on the privilege map: who can move assets, replace signers or alter safeguards. “If I had to identify one control most associated with institutional confidence, it would be multiparty authorization across every asset-moving and upgrade path,” Fan said. “Institutions want evidence that unilateral action is impossible.”

Swartz added that institutions prioritize how teams handle adversity. “Institutions know that no protocol is completely risk-free,” Swartz said. “What matters is whether the team has good governance, strong internal controls, transparency around risk and a clear plan for responding when something goes wrong.”

The five experts agree that Web3 must adopt layered defense stacks incorporating real-time monitoring, disciplined key management and responsive bug bounties to protect against evolving threats.

“Digital assets operate around the clock, but parts of the infrastructure supporting them still operate according to traditional financial schedules,” David noted. “As the market becomes more institutional, the infrastructure supporting the movement and settlement of capital needs to become more resilient as well.”

Looking Ahead to H2 2026: Realigning Defense Stacks

The experts, meanwhile, warn that the second half of 2026 will bring more of the same. Rather than burning cycles trying to reverse-engineer audited smart contracts, threat actors are expected to keep hammering the path of least resistance: operational controls, human targets, and key infrastructure.

“I expect operational access-control attacks to continue dominating losses: social engineering, credential theft, signer compromise, cloud or CI/CD intrusion and attacks on off-chain validator infrastructure,” Fan predicted. “Individual smart-contract bugs will continue, but attackers will keep targeting the shortest path to authority.”

Videau concluded with a call to realign security spending with actual risk: “Spend where the losses are. Nearly 90% of stolen funds moved through keys, signers and infrastructure, yet budgets still pour into contract audits. The worst attacks will be the ones nobody predicted, so build as if your perimeter is already gone.”

You might also like

Bitcoin, US Stocks Show Little Weakness Despite Fresh US-Iran Escalation

Cathie Wood Says SpaceX Could Become ‘the Most Important Company in History’ Despite 48% Stock Slide

Foundry asks Bitcoin miners to vote on BIP-110 support



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Bitcoin
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin, US Stocks Show Little Weakness Despite Fresh US-Iran Escalation

by CryptoExpert
July 23, 2026
0
Cointelegraph

Bitcoin (BTC) held higher on Wednesday as crypto and risk assets continued to brush off US-Iran war tensions.Key points:Bitcoin limits its comedown from five-week highs despite fresh escalation...

Read more

Cathie Wood Says SpaceX Could Become ‘the Most Important Company in History’ Despite 48% Stock Slide

by CryptoExpert
July 22, 2026
0
Cathie Wood Says SpaceX Could Become 'the Most Important Company in History' Despite 48% Stock Slide

Key TakeawaysCathie Wood, CEO of Ark Invest, said SpaceX could become “the most important company in history.”Shares traded at $116.95, about 48% below their $225.64 peak and 13%...

Read more

Foundry asks Bitcoin miners to vote on BIP-110 support

by CryptoExpert
July 22, 2026
0
Cointelegraph

Foundry USA asked its mining customers to signal their support for BIP-110, an actively debated proposal seeking to shrink the amount of data that can be stored in...

Read more

7 in 10 Crypto Traders Would Let AI Run Their Portfolios — But They Want an Emergency Off Switch

by CryptoExpert
July 22, 2026
0
7 in 10 Crypto Traders Would Let AI Run Their Portfolios — But They Want an Emergency Off Switch

Key TakeawaysAbout 70% of surveyed traders would let AI manage their portfolios autonomously or within preset risk limits.Real-time alerts and instant permission revocation were the most requested safeguards.Regulators...

Read more

Bitcoin Has Exited Capitulation Regime as Momentum Rebuilds: Analysts

by CryptoExpert
July 21, 2026
0
ETFs, Macro Trends, and $114 Billion Futures Boom Drive Bitcoin Liquidity

Bitcoin prices are at a five-week high, and the asset has moved out of its capitulation zone, according to analysts. Bitcoin momentum is rebuilding, but confirmation has...

Read more
Next Post
Cointelegraph

Mirae Asset completes Korbit acquisition, becomes largest shareholder

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 64,917.00
ethereum
Ethereum (ETH) $ 1,892.76
tether
Tether (USDT) $ 0.999441
bnb
BNB (BNB) $ 567.08
usd-coin
USDC (USDC) $ 0.999792
xrp
XRP (XRP) $ 1.11
solana
Solana (SOL) $ 76.32
tron
TRON (TRX) $ 0.32648
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?