The audit gap, updated: Q2 2026 joins four years of data, and the quiet quarter ends
Our Web3 security dataset now runs through 30 June 2026: 25,706 audit findings, 237 incidents, US$8.62B in losses. Q1 looked like a rotation in attacker behaviour. Q2 ended that theory.
The TRACE paper is out
Our threat modelling methodology, written up as a paper: why perimeter-era methods miss the failures that actually happen, and what TRACE does instead.
Most Web3 losses don't start in the code
A perfectly audited contract won't help you if the deployer key leaks. Here's what an operational security review actually looks at.
The State of Web3 Security 2022 – Q1 2026: six key findings
What 23,818 audit findings and 218 exploit incidents tell us about where Web3 actually loses money.
Introducing TRACE: threat modelling without a perimeter
Why we built our own threat modelling methodology, what the five model objects are, and why it works beyond Web3.