Skip to main content
zeroShadow

Hacks

Learning & Information

The $900 Million Loss Baseline

Aug 5, 2026 | 5 min read

Between 01 January and 30 June 2026, the Web3 enterprise ecosystem suffered total financial losses of $905,741,758.58 across 105 recorded security incidents. While this baseline demonstrates the clear scale of the threat, aggregate loss metrics only confirm that a problem exists without explaining how to execute a technical fix.

cityscape with different losses mapped to buildings

Between 01 January and 30 June 2026, the Web3 enterprise ecosystem suffered total financial losses of $905,741,758.58 across 105 recorded security incidents. While this baseline demonstrates the clear scale of the threat, aggregate loss metrics only confirm that a problem exists without explaining how to execute a technical fix.

Our dataset operates under a strict evidentiary boundary. We do not ingest unverified third-party public forum scrapes, unconfirmed social media feeds, or secondary macro-aggregations. Every incident, transaction, and metric recorded across our systems must be real, repeatable, and forensically verified by our team. If a transaction or asset loss cannot be definitively validated through primary data, it is excluded from our metrics. We prioritize absolute technical defensibility over unverified data volume.

This briefing is built on primary access. zeroShadow was retained to manage the incident response, tracing, or containment for over 83% of these verified ecosystem losses. Working directly alongside victims and law enforcement provides our team with granular details and first-hand telemetry that cannot be replicated from the sidelines. We share these validated findings to isolate the most critical threats impacting our ecosystem, highlighting the exact architectural defenses needed to protect your ecosystems.

Inside the breach

Our findings come straight from the source. Our global team responds immediately during a crisis, often stepping in while an exploit is still active. To help victims right away, we provide up to 5 hours of free support. This gives teams time to figure out their next steps. If they decide a longer contract is not a good financial fit, we hand over our technical findings at no cost. When teams do hire us, we trace the stolen funds from the very first address to the last, working to freeze as much as possible along the way.

This hands-on approach is how we capture accurate, real-world data across a massive number of global incidents. Because we handle nearly 90% of all known stolen enterprise capital, we do not rely on guesswork or second-hand reports. Instead, we work directly with the victim to review the entire incident from start to finish. This close partnership gives us access to privileged data, allowing us to learn real lessons from how the attack actually happened.

The data below compares our active caseload against total global losses, showing the depth of our coverage:

Horizontal bar chart titled "Active Enterprise Caseload vs Global Loss Baseline" by zeroShadow comparing H1 2026 stolen capital in USD. Global Ecosystem Losses equal $905.7M (100%), Total Active zS Caseload equals $810.8M (89.51%), Retained Investigations equal $758.4M (83.731%), External Market Incidents equal $95.0M (10.49%), and Initial Scoping & Triage equals $52.4M (5.78%).

When a crisis scales

The largest exploits in the industry cause severe, lasting damage, frequently draining protocols and fracturing entire communities. These are the complex, existential breaches that every team works hard to avoid. While they bring devastating risks, they also generate the most critical lessons for Web3 security due to the massive volume of data they reveal.

When a security incident scales to this level, our team is consistently trusted to step in and help handle the crisis. Throughout this half-year, exactly five global exploits crossed the $20 million threshold. zeroShadow was recommended and retained to help lead the response for every single one.

Investigating these large-scale exploits requires a 24/7 team with deep threat experience and specialized tools. Yet, technical skill is only half the battle. Newer teams often fall short because they lack a true network footprint. A major hack cannot be solved in isolation: successfully freezing stolen capital requires immediate coordination with global exchanges, law enforcement, and security peers. We have spent years cultivating these relationships, giving our clients an unbuyable network effect the moment a crisis hits.

This level of coordination demands uncompromised ethics. While some opportunistic firms treat a compromised protocol as a predatory money-making opportunity, we focus entirely on stabilizing the assets first, establishing transparent commercial terms only after delivering initial results. This victim-first approach is exactly why we maintained a 100% retention rate across H1's largest exploits.

Anatomy of a breach

Managing these massive exploits first-hand provides an unfiltered look at how adversaries actually operate. While the stolen capital ultimately moves on-chain, the structural vulnerabilities that let attackers through the door are overwhelmingly off-chain.

To help our partners isolate their own vulnerabilities, we categorize H1 2026’s root causes into these two distinct domains:

The data below maps out these root causes, illustrating where the industry's real defensive gaps lie:

attacks in H1 2025 divided by operational security failures vs smart contract flaws

The data highlights a stark asymmetry: while on-chain (49) and off-chain (53) incident counts are nearly identical, the financial damage from off-chain failures is vastly larger. This proves that smart contract audits, while essential, cannot protect a protocol if its team or Web2 infrastructure is left exposed. You can deploy perfectly audited code and still get completely drained through a single compromised developer laptop.

To move past high-level charts and show you exactly how to secure both sides of this equation, future blogs will break down our front-line findings and operational frameworks. Use these upcoming sections to understand how projects are actually being compromised and to review the practical defenses needed to protect your ecosystem:

Share this post