$763M Heist Exposes Flaw in Smart Contract Audits: Threat Actors Shift Focus
The second quarter of 2026 was one of the most severe periods for Web3 security, with $763.9 million stolen across 67 incidents.
This is a stark reminder that smart contract audits are not foolproof, as 14 audited protocols were breached during this time.
The majority of losses came from operational and key management compromises, rather than flaws in smart contract logic.
Security experts warn that threat actors will continue to target operational controls and key infrastructure, rather than code.




