Q3 2026 Web3 Exploit Report
Back to Blog

Q3 2026 Web3 Exploit Report

CD Security
General
October 1, 2026
4 min read

How Protocols Got Drained

The third quarter of 2026 is the most damaging quarter in Web3 security so far this year. CD Security tracked 146 security incidents across July, August, and September - protocol exploits, infrastructure breaches, wallet compromises, bridge failures, and other technical attacks that resulted in real losses.

Here's what the data shows.

📥 Download the full report: Q3 2026 Web3 Exploit Report (PDF)


$1.24B lost across 146 incidents in 92 days

146 security incidents. $1.24B gone. Three incidents alone - Bitget ($387.5M), Liquid Network (~$320M), and Tectonic ($120.4M affected) - account for roughly 67% of the quarter's total losses.

September was the worst month by far, recording $747.2M in known losses in a single month - more than July and August combined. July recorded $252.3M across 39 incidents, August $238.4M across 54, and September $747.2M across 53. Q3 losses were roughly 59% higher than Q2 2026.

q3 2026 web3 exploit report 83cf675a


The two categories that matter

Protocol Logic failures drove 78% of incidents - bridge and cross-chain bugs, oracle manipulation, access control failures, accounting errors, governance exploits, and other contract-level failures. 114 incidents caused approximately $636.6M in known losses.

Infrastructure failures - wallet compromises, signing infrastructure breaches, compromised validators, operational security failures, and backend authorization attacks - accounted for only 22% of incidents but caused approximately $601.3M in losses.

Bitget is the clearest example. The private keys themselves were not compromised. Attackers compromised the infrastructure around the signing process and caused legitimate systems to execute fraudulent withdrawals.

The lesson is simple: secure smart contracts are not enough, and secure keys are not enough. The entire path from transaction creation to authorization, signing, and execution has to be protected.


q3 2026 web3 exploit report aff3e8e8


Q3 2026 vs Q3 2025 - what changed

On a like-for-like technical incident basis, total losses increased from approximately $317M in Q3 2025 to $1.24B in Q3 2026 - almost 4x higher year-over-year.

Smart contract and protocol losses increased from $101.5M to $636.6M. Infrastructure and key-related losses increased from $215.6M to approximately $599.2M.

Unlike Q2, where smart contract exploit losses had improved year-over-year, Q3 deteriorated across both sides of the security stack. More protocol failures, more infrastructure failures, and significantly larger losses when critical assumptions broke.

q3 2026 web3 exploit report 2065a7d2


The three biggest hacks

1. Bitget - $387.5M (September 24).

Attackers exploited vulnerabilities in third-party security products, gained privileged access to Bitget's production wallet environment, and forged withdrawal requests that were processed through normal wallet infrastructure. Bitget stated that the private keys themselves were not compromised. The surrounding authorization system was.

2. Liquid Network - ~$320M (September 6).

A critical flaw in Elements' rangeproof verification cache caused federation nodes to accept roughly 4,000 unbacked LBTC as legitimate. Once consensus accepted the counterfeit assets, the normal peg-out mechanism released approximately 4,000 real BTC. The attacker later identified themselves as a white hat and returned most of the funds.

3. Tectonic - $120.4M affected (August 30).

The attacker manipulated the price of TONIC, a thinly traded token accepted as collateral, deposited the inflated asset, and used the artificial valuation to borrow real assets across Tectonic markets. Cronos validators later rolled the chain back by 10,961 blocks, reversing most of the affected value.


What this means for protocol teams

The average Protocol Logic incident in Q3 2026 caused approximately $5.6M in known losses. The average Infrastructure incident caused approximately $18.8M.

The cost of a quality audit, hardened signing infrastructure, proper monitoring, conservative collateral design, and strong operational controls is a fraction of either number.

The full report includes complete incident logs for all 146 incidents, monthly breakdowns, chain data, attack technique analysis, a Q3 2025 vs Q3 2026 comparison, and detailed analysis of Bitget, Liquid Network, and Tectonic.

📥 Download the Q3 2026 Web3 Exploit Report →


CD Security is a specialized Web3 security firm with over three years of experience auditing smart contracts and protecting high-value protocols across the ecosystem. 200+ completed audits, senior auditors only, start as early as 24h after the request.

Book an audit at cdsecurity.io