Multisig Failures Dominate as $3.1B Is Lost in Web3 Hacks in the First Half
Cryptocurrency investors suffered staggering losses during the first half of the year, with approximately $3.1 billion stolen through various exploits, according to a new report from cybersecurity firm Hacken. This figure surpasses the total losses incurred throughout all of 2024, highlighting a significant surge in crypto-related crime.
A surprising trend emerged: the frequent compromise of multisignature wallets, a security measure requiring multiple approvals for transactions. These breaches were primarily attributed to manipulated user interfaces and mismanagement of authorized signers. The colossal $1.46 billion hack of Bybit in Q1 serves as a prime example, where a compromised safe-wallet interface tricked authorized signers into approving fraudulent transactions. This marked the third consecutive quarter where the largest single hack stemmed from multisig vulnerabilities.
Beyond multisig exploits, rug pulls accounted for an additional $300 million in losses during the first half of the year. Phishing and social engineering attacks also contributed significantly, resulting in nearly $100 million in stolen funds. Interestingly, smart contract vulnerabilities played a minimal role, accounting for less than 2% of total losses. This contrasts with the second quarter of 2025, where smart contract bugs, such as the $223 million Cetus overflow, dominated attacks.
The overarching theme remains access-control issues, responsible for over 80% of all stolen funds in 2026. Hacken’s report emphasizes the urgent need to shift from a reactive auditing approach to real-time operational security. They strongly advocate for AI-powered monitoring systems capable of continuously validating multisig transactions, detecting anomalous signer activity, and automatically triggering safeguards. The report stresses the critical importance of treating signer protocols, multisig front-ends, and human workflows as security-critical infrastructure, demanding enhanced automation, comprehensive training, and stricter governance across both centralized (CeFi) and decentralized (DeFi) finance projects. This proactive approach is crucial to mitigate future attacks and protect investor funds.

