Hacks
Learning & Information
The $900 Million Loss Baseline
Aug 5, 2026 | 5 min read
Between 01 January and 30 June 2026, the Web3 enterprise ecosystem suffered total financial losses of $905,741,758.58 across 105 recorded security incidents. While this baseline demonstrates the clear scale of the threat, aggregate loss metrics only confirm that a problem exists without explaining how to execute a technical fix.
Between 01 January and 30 June 2026, the Web3 enterprise ecosystem suffered total financial losses of $905,741,758.58 across 105 recorded security incidents. While this baseline demonstrates the clear scale of the threat, aggregate loss metrics only confirm that a problem exists without explaining how to execute a technical fix.
Our dataset operates under a strict evidentiary boundary. We do not ingest unverified third-party public forum scrapes, unconfirmed social media feeds, or secondary macro-aggregations. Every incident, transaction, and metric recorded across our systems must be real, repeatable, and forensically verified by our team. If a transaction or asset loss cannot be definitively validated through primary data, it is excluded from our metrics. We prioritize absolute technical defensibility over unverified data volume.
This briefing is built on primary access. zeroShadow was retained to manage the incident response, tracing, or containment for over 83% of these verified ecosystem losses. Working directly alongside victims and law enforcement provides our team with granular details and first-hand telemetry that cannot be replicated from the sidelines. We share these validated findings to isolate the most critical threats impacting our ecosystem, highlighting the exact architectural defenses needed to protect your ecosystems.
Inside the breach
Our findings come straight from the source. Our global team responds immediately during a crisis, often stepping in while an exploit is still active. To help victims right away, we provide up to 5 hours of free support. This gives teams time to figure out their next steps. If they decide a longer contract is not a good financial fit, we hand over our technical findings at no cost. When teams do hire us, we trace the stolen funds from the very first address to the last, working to freeze as much as possible along the way.
This hands-on approach is how we capture accurate, real-world data across a massive number of global incidents. Because we handle nearly 90% of all known stolen enterprise capital, we do not rely on guesswork or second-hand reports. Instead, we work directly with the victim to review the entire incident from start to finish. This close partnership gives us access to privileged data, allowing us to learn real lessons from how the attack actually happened.
The data below compares our active caseload against total global losses, showing the depth of our coverage:

When a crisis scales
The largest exploits in the industry cause severe, lasting damage, frequently draining protocols and fracturing entire communities. These are the complex, existential breaches that every team works hard to avoid. While they bring devastating risks, they also generate the most critical lessons for Web3 security due to the massive volume of data they reveal.
When a security incident scales to this level, our team is consistently trusted to step in and help handle the crisis. Throughout this half-year, exactly five global exploits crossed the $20 million threshold. zeroShadow was recommended and retained to help lead the response for every single one.
Investigating these large-scale exploits requires a 24/7 team with deep threat experience and specialized tools. Yet, technical skill is only half the battle. Newer teams often fall short because they lack a true network footprint. A major hack cannot be solved in isolation: successfully freezing stolen capital requires immediate coordination with global exchanges, law enforcement, and security peers. We have spent years cultivating these relationships, giving our clients an unbuyable network effect the moment a crisis hits.
This level of coordination demands uncompromised ethics. While some opportunistic firms treat a compromised protocol as a predatory money-making opportunity, we focus entirely on stabilizing the assets first, establishing transparent commercial terms only after delivering initial results. This victim-first approach is exactly why we maintained a 100% retention rate across H1's largest exploits.
Anatomy of a breach
Managing these massive exploits first-hand provides an unfiltered look at how adversaries actually operate. While the stolen capital ultimately moves on-chain, the structural vulnerabilities that let attackers through the door are overwhelmingly off-chain.
To help our partners isolate their own vulnerabilities, we categorize H1 2026’s root causes into these two distinct domains:
- OFF-CHAIN (OPSEC): Malware, DNS hijackings, Web2 supply chain compromises, malicious interview schemes, etc.
- ON-CHAIN (SMART CONTRACT & LOGIC): Price oracle manipulations, access control failures, input validation errors, cryptographic logic gaps, etc.
The data below maps out these root causes, illustrating where the industry's real defensive gaps lie:

The data highlights a stark asymmetry: while on-chain (49) and off-chain (53) incident counts are nearly identical, the financial damage from off-chain failures is vastly larger. This proves that smart contract audits, while essential, cannot protect a protocol if its team or Web2 infrastructure is left exposed. You can deploy perfectly audited code and still get completely drained through a single compromised developer laptop.
To move past high-level charts and show you exactly how to secure both sides of this equation, future blogs will break down our front-line findings and operational frameworks. Use these upcoming sections to understand how projects are actually being compromised and to review the practical defenses needed to protect your ecosystem:
- TIPzs (Ecosystem Protection): Leveraging live threat intelligence to identify malicious actors and keep illicit assets out of your platform.
- Incident Response: Case studies, granular, forensic breakdowns straight from our active caseload, exposing exactly how modern threat actors operate.
- Aftercare: How our partnership works with Coinbase and other ecosystems, giving a voice and support to retail victims.
- vSOC: Deploying active, real-time observation and monitoring to intercept smart contract exploits or wallet security breaches before assets can be stolen.
- Security Consulting: How to harden your operational perimeter using the defensive blueprints and framework standards developed alongside the SEAL team.