Institutional Web3 Market Shifts to Continuous Security Verification

July 23, 2026 · 2 min read
Institutional Web3 Market Shifts to Continuous Security Verification

Institutional participants in the digital asset market are relying less on one time security audits and increasingly on continuous verification of system, infrastructure, and operational security, as losses tied to code vulnerabilities accounted for only about 11% of total damages from security incidents.

Web3 cybersecurity firm Hacken recorded 67 security incidents in Q2 2026, with total losses reaching $763.97 million. The company found that 88.3% of stolen funds resulted from compromised keys, signers, and infrastructure rather than coding errors. Against this backdrop, Hacken observed a shift in how institutional market participants assess trust, with firms moving toward continuous verification of their systems’ security posture.

According to the report, the quarter was the most severe for the Web3 industry since Q2 2025. Total losses increased 58.3% from Q1 2026, when they stood at $482.7 million, and declined 25.9% compared with Q2 2025. Smart contract vulnerabilities remained the most common type of incident, accounting for 44 of the 67 cases. However, they caused just $87.7 million in losses, or about 11% of the total.

The largest incidents stemmed from infrastructure failures and operational issues. The biggest cases included:

  1. KelpDAO: $292 million
  2. Drift Protocol: $285 million
  3. Humanity Protocol: $31 million

Hacken also highlighted the first confirmed case of a prompt injection attack that resulted in unauthorized fund transfers involving the Grok AI agent and the Bankr platform, ultimately leading to the transfer of tokens worth approximately $174,000.

The report emphasized that traditional trust signals, including completed security audits, a project’s operating history, and high total value locked, didn’t prove to be reliable indicators of risk. The affected projects included both platforms that underwent multiple security audits and projects with years of operating history. Against this backdrop, Hacken argued for a broader approach to security that considers not only code reliability, but also the resilience of critical infrastructure and essential third party components, along with the effectiveness of monitoring, incident response readiness, and the ability to withstand operational disruptions.

Just days ago, CoinsPaid Media published a new episode of the Money Rewired podcast, in which Hacken CEO and Co-Founder Yev Broshovan discussed how cybersecurity for Web3 projects is evolving as real world institutional use cases continue to expand.