Backpack News

CertiK Reports Web3 Losses Exceeded $1.31B in H1 2026, Up 28% Year-over-Year

Web3 security incidents cost the industry more than $1.31 billion across 344 events in the first half of 2026, according to CertiK's Hack3D H1 2026 Report, published Monday. The blockchain security firm reported that net losses stood near $1.2 billion after frozen and recovered funds were accounted for. The headline totals represent a 28% increase year-over-year when excluding the Bybit baseline, signaling a troubling upward trend in both the frequency and severity of attacks targeting the decentralized ecosystem.

Key Findings from the Hack3D H1 2026 Report

CertiK, one of the most prominent blockchain security and smart contract auditing firms in the world, released its semi-annual Hack3D report covering the first half of 2026. The report provides a comprehensive overview of every documented security incident in the Web3 ecosystem, offering critical insights into the evolving threat landscape facing cryptocurrency projects, DeFi protocols, and blockchain infrastructure.

$1.31 billion in total gross losses

344 security incidents recorded

~$1.2 billion in net losses after recovery

+28% year-over-year increase (excluding Bybit baseline)

The report classifies the documented incidents under the Layer2 category, with NEAR mentioned among the affected assets. This classification highlights that Layer2 scaling solutions and alternative network layers were a significant area of focus for security events during the reporting period.

Breaking Down the $1.31 Billion in Losses

The figure of 344 security incidents in just six months underscores the relentless frequency with which malicious actors target the Web3 ecosystem. These events span a wide range of attack vectors, including smart contract exploits, flash loan attacks, phishing campaigns, cross-chain bridge compromises, and private key theft.

The gross total of $1.31 billion represents a substantial amount of capital lost to malicious activity. However, it is noteworthy that net losses were reduced to approximately $1.2 billion thanks to the coordinated efforts of incident response teams, security audits, and fund-freezing mechanisms implemented by exchanges and DeFi protocols. This means that roughly $110 million was either recovered or frozen, demonstrating the growing maturity of the industry's incident response capabilities.

While this recovery rate offers some encouragement, the sheer scale of remaining losses makes clear that preventative security measures remain far more effective than post-incident remediation. The industry must shift its focus toward proactive security hardening rather than relying on reactive damage control after an attack has already occurred.

The 28% Year-over-Year Increase: What It Means

The 28% increase in losses, calculated after excluding the Bybit baseline, is a particularly revealing data point. The decision to exclude Bybit from the baseline calculation suggests that the report aims to isolate structural security trends from extraordinary large-scale incidents that could skew the overall picture. Even without those atypical events factored in, the 28% upward trend indicates that the volume and sophistication of attacks are growing at an alarming rate.

Several converging factors likely contribute to this increase. First, the growing adoption of DeFi protocols and the rising total value locked (TVL) across Layer2 networks create a larger attack surface for malicious actors to target. Second, the technical complexity of Layer2 scaling solutions introduces novel vulnerability vectors that have not yet been fully audited or stress-tested. Third, attackers themselves are becoming increasingly sophisticated, leveraging advanced smart contract analysis tools to identify and exploit vulnerabilities before they can be patched.

NEAR and the Layer2 Ecosystem Under Scrutiny

The mention of NEAR among the affected assets and the classification of the report under the Layer2 category draw attention to a concerning pattern: Layer2 scaling solutions and alternative layer networks are becoming increasingly attractive targets for attackers. This makes sense from an attacker's perspective, as these networks often house significant amounts of value while being newer and less battle-tested than Ethereum mainnet.

The Layer2 ecosystem has experienced explosive growth in recent years, with a massive increase in TVL and user adoption. However, this growth has in many cases outpaced the available security auditing and monitoring capabilities. Protocol developers building on Layer2 networks must prioritize security from the design phase, implementing independent audits, bug bounty programs, and continuous on-chain monitoring in production environments.

For NEAR specifically, its inclusion in the report serves as a reminder that even well-funded and technically advanced blockchain projects are not immune to security incidents. The NEAR ecosystem has been growing rapidly, with increasing numbers of decentralized applications and DeFi protocols deploying on the network. As the ecosystem expands, so too does the attack surface available to malicious actors.

CertiK's Role in Web3 Security

CertiK has established itself as one of the most important players in the blockchain security ecosystem. The firm utilizes formal verification techniques, static analysis, and manual auditing to identify vulnerabilities in smart contracts before they are deployed. Its Hack3D reports have become an essential reference for investors, developers, and regulators seeking to understand the threat landscape in Web3.

The regular publication of these reports serves a critical transparency function for the industry. By publicly documenting security incidents, CertiK enables the community to identify patterns, share lessons learned, and develop best practices. This transparency is essential for building trust in an ecosystem that, by its decentralized nature, lacks traditional regulatory oversight mechanisms.

CertiK also operates the Skynet platform, which provides real-time security monitoring for blockchain projects. This tool allows users to assess the security posture of smart contracts and protocols before interacting with them, adding an additional layer of protection for informed users.

Implications for Crypto Investors and Everyday Users

For individual investors and everyday crypto users, the figures in the Hack3D H1 2026 Report serve as a stark reminder of the inherent risks in the Web3 ecosystem. The loss of $1.31 billion in six months equates to a substantial amount of investor capital that was compromised by malicious attacks.

Best practices for security include: only interacting with platforms and protocols that have completed verified security audits from reputable firms like CertiK; diversifying investments to limit exposure to any single protocol; staying informed about known vulnerabilities through resources like CertiK's Skynet; and using hardware wallets for long-term storage of digital assets. Additionally, investors should exercise particular caution with emerging Layer2 protocols that lack an established security track record.

Choosing the right exchange is also a critical component of a comprehensive security strategy. Platforms that invest heavily in security infrastructure, maintain insurance funds, and undergo regular third-party audits provide an additional layer of protection for user assets. As the Web3 ecosystem continues to grow and evolve, the platforms that prioritize security will be best positioned to earn and maintain user trust over the long term.

Frequently Asked Questions

How much did Web3 security incidents cost in the first half of 2026?

According to CertiK's Hack3D H1 2026 Report, Web3 security incidents cost the industry more than $1.31 billion across 344 events. Net losses stood near $1.2 billion after frozen and recovered funds were accounted for.

What is the CertiK Hack3D Report?

Hack3D is a semi-annual report published by CertiK, a leading blockchain security firm, that documents and analyzes all security incidents in the Web3 ecosystem, including smart contract exploits, phishing scams, and bridge attacks.

Why is the Bybit baseline excluded from the 28% increase figure?

The Bybit baseline is excluded to isolate structural security trends from extraordinary large-scale incidents. Even without the Bybit event factored in, losses increased 28% year-over-year, indicating a rising trend in the volume and severity of Web3 attacks.

Which assets and categories were affected according to the report?

The report classifies incidents under the Layer2 category, with NEAR mentioned among the affected assets. This highlights that Layer2 scaling solutions and alternative network layers were a significant focus of security events documented in the report.

How can crypto users protect themselves from Web3 security threats?

Users should only interact with platforms that have completed verified security audits from firms like CertiK, diversify their holdings, use hardware wallets for long-term storage, stay informed about known vulnerabilities, and exercise caution with emerging Layer2 protocols that lack an established security track record.

Trade Securely with Backpack Exchange

Protect your digital assets on a platform built with security-first principles. Backpack Exchange offers a seamless, secure trading experience for crypto enthusiasts worldwide. Sign up now with referral code «luckybitcoin» to unlock exclusive benefits.

Sign Up on Backpack (Code: luckybitcoin)

The market carries risks and investment requires caution. This article does not constitute personal financial advice and does not take into account individual users' specific investment objectives, financial situations, or needs. Users should consider whether any opinions, perspectives, or conclusions in this article align with their particular circumstances. The responsibility for investing based on this information lies with the user.