New: the Q2 2026 data update is out — the quiet quarter ended. US$854M in losses, keys and bridges back on top. Read the analysis →

Research

Security research,
published openly.

Reports, open methodologies, and articles from our researchers. It's how we think out loud about protecting Web3, in public.

Flagship report · updated July 2026

The State of Web3 Security 2022 – Q2 2026

Four and a half years of data: 25,706 published audit findings from 22 firms, and 237 real-world exploit incidents worth US$8.62 billion in losses. Built with rekt.news, updated quarterly.

25,706
audit findings analysed
237
exploit incidents documented
$8.62B
aggregate losses
50%
of losses are human-vector
Open methodology · CC BY 4.0

TRACE. Threat modelling for organisations without a perimeter.

Threat actors, Roles, Assets, Critical invariants, Edges. One method, applied across protocols, systems, and organisations. We built it through our Web3 work, but it fits any team that no longer has a clean security perimeter.

Explore the framework GitHub repository

Looking for our audit reports?

Every final audit report is transparently published to our GitHub repository.

Published audit reports

Subscribe to our newsletter

Security research, audit insights, and ecosystem analysis — straight to your inbox.