Multisig Failures Dominate as $2B Is Lost in Web3 Hacks in the First Half
Cryptocurrency investors suffered staggering losses during the first half of the year, with approximately $2 billion lost to various hacks. This figure is particularly alarming given that the first quarter alone surpassed the total losses incurred throughout all of 2024. A report from security firm Hacken reveals a concerning trend: multisignature wallets, designed to enhance security by requiring multiple approvals for transactions, were frequently compromised. This vulnerability highlights a critical weakness in a system intended to be highly secure.
The most significant incident involved the breach of centralized exchange Bybit, resulting in a massive $1.46 billion loss. This breach, attributed to a compromised safe-wallet interface, underscores the susceptibility of even sophisticated security measures to sophisticated attacks. Remarkably, this marked the third consecutive quarter where the largest hack stemmed from multisig failures, emphasizing the urgent need for improved security protocols.
Beyond multisig exploits, other attack vectors contributed significantly to the overall losses. Rug pulls, a deceptive practice where developers abandon a project and abscond with investors’ funds, accounted for an additional $300 million in losses. Phishing and social engineering campaigns, leveraging deception and manipulation, added nearly $100 million to the total. In contrast, smart contract vulnerabilities played a minor role, accounting for less than 2% of the total losses.
The report’s analysis points to a recurring theme: access-control issues. These issues were responsible for over 80% of all stolen funds, emphasizing the critical need to strengthen access controls across the board. Hacken strongly advocates for a shift from a reactive auditing approach to a proactive, real-time security strategy. The firm recommends the implementation of AI-powered monitoring systems capable of continuously validating multisig transactions, detecting anomalous signer activity, and triggering automated safeguards. Furthermore, the report stresses the importance of treating signer protocols, multisig front-ends, and human workflows as critical security infrastructure, recommending improvements through automation, comprehensive training, and robust governance frameworks. The report’s recommendations highlight the necessity for a holistic approach to security, encompassing both technological advancements and improved human practices.

