Hack3d: The Web3 Security Quarterly Report - Q3 2023

리서치 보안 보고서
Hack3d: The Web3 Security Quarterly Report - Q3 2023

Welcome to Hack3d: The Web3 Security Report for Q3 2023. Hack3d serves as an essential resource and record of statistics for understanding security challenges and vulnerabilities in the Web3 space. It equips stakeholders with the knowledge and insights needed to fortify their defenses and make informed decisions in an increasingly high-stakes environment.

With more than $699 million lost across 184 security incidents, Q3 has been 2023’s most eventful quarter. For reference, Q1 saw a total of $320 million lost and Q2 $313 million, meaning Q3’s losses eclipse those throughout all of H1 2023.

One of the most dominant threat actors in Web3 is the North Korean state-affiliated Lazarus Group. Lazarus is responsible for at least $291 million in confirmed losses this year. The group's sophisticated tactics have evolved to target Web3 personnel specifically, leveraging social engineering methods to compromise multiple platforms’ security. We’ll take a close look at Lazarus in this report.

Private key compromises have been another significant source of losses, accounting for $204 million in losses across 14 incidents. The Mixin and Multichain incidents together were responsible for $325 million in losses, possibly through private key compromises, but more accurately through centralized points of control that allowed for the takeover of the protocols. The centralized control of private keys has proven to be a critical vulnerability, and one that is particularly rankling to users who had been promised (though not provably delivered) decentralization. To address this, we’ve worked with a key partner to develop a new verification mechanism that helps users ensure projects have adopted enhanced private key management solutions.

The lack of universal standards for software development remains a major issue in the Web3 space. An extensive amount of hacks and smart contract exploits can be traced back to this void of standards. For example, the rampant use of copy-paste forks without proper due diligence (from both developers and users) causes consistent losses. These standards would provide a framework for ensuring consistent security measures, reducing vulnerabilities and increasing the resilience of the entire Web3 world.

On the bright side, major financial institutions are beginning to meaningfully integrate on-chain technologies, indicating a shift towards blockchain adoption. However, this transition also brings new types of risks that must be carefully managed. We give our predictions for what the meaningful maturation of the industry may look like over the next, six, twelve, and eighteen months.

CertiK regularly publishes a variety of technical and educational resources, and we’ll cover a selection of Q3’s highlights at the end of this report.

Until then, read on to arm yourself with the insights you need to navigate the Web3 world in safety.

관련 블로그

CertiK Intel3D 2026년 상반기 렌치 공격 보고서
새로운 · Report Review ·Intel3D

CertiK Intel3D 2026년 상반기 렌치 공격 보고서

CertiK은 2026년 상반기 전 세계적으로 총 52건의 검증된 렌치 공격 사건을 확인했으며, 이는 2025년 상반기 39건 대비 33.3% 증가한 수치입니다. 또한 기록된 자금 위험 노출 규모는 약 1.241억 달러로 2025년 상반기 1,050만 달러 대비 약 11.8배 증가한 수준입니다.

CertiK Hack3D: H1 2026 Report

CertiK Hack3D: H1 2026 Report

Web3 security losses exceeded $1.31 billion in H1 2026 across 344 incidents, with wallet compromise emerging as the most financially destructive attack vector and phishing shifting toward fewer, higher-value social engineering attacks.

Introducing CertiK Hunt, The Invite-Only Security Platform for Web3 Projects and Top Security Researchers

Introducing CertiK Hunt, The Invite-Only Security Platform for Web3 Projects and Top Security Researchers

CertiK Hunt is an invite-only platform connecting elite security researchers with web3 projects through bug bounty programs, audit competitions, and AI challenges.