Over $870 million was lost to web3 hacks and breaches in the second quarter of the year, according to CertiK’s Web3 Quarterly Security Report for Q2 2022.
In the first half of 2022, the total amount of money lost due to hacks and breaches of web3 platforms has exceeded $2 billion, surpassing the entire number of breaches seen globally in 2021. Crypto and blockchain hacks might increase 3.23x year over year (YoY) this year, according to US-based cyber security firm CertiK, with no signs of slowing down.
Over $870 million was lost to web3 hacks and breaches in the second quarter of 2022, according to CertiK’s Web3 Quarterly Security Report for Q2 2022. It’s interesting to note that there was a significant increase in flash loan breaches during this quarter. While Q1 showed a loss of $14.2 million due to flash loan assaults, over $308 million was lost over the months of April and June.
Flash loans are immediate, uncollateralized cryptocurrency loans made available through blockchain networks. These networks employ smart contracts to specify a set of requirements that a borrower must meet. In the event that this is not done, the smart contract fails, and the loan is voided.

The rapid increase in flash loan attacks is mostly due to breaches like the $182 million attack on the stablecoin project Beanstalk Farms and the $79 million hack of another stablecoin project Fei Protocol.
Decentralized finance (DeFi) platforms offer flash lending services, and the intrusions indicate an increasing number of breaches of such services, which cyber security experts around the world have stated is a growing threat stemming from code faults in these platforms.
Speaking to Mint, Akshat Jain, co-founder and chief technology officer (CTO) of cyber security company Cyware, said that the absence of security measures in DeFi platforms, blockchain networks, and cryptocurrency wallets is a primary reason why such breaches have been continuously increasing.
However, this also implied that, with the exception of a small number, the majority of them made little effort in the security area. Some organizations do not even now have an information security officer, according to Jain.
He continued by saying that as a result, attackers were free to use zero-day assaults as they pleased.
Jain further said that despite some users having made significant investments, most users’ contributions to web3—particularly in India—have been modest. According to him, “this frequently results in customers falling victim to phishing and social engineering schemes, where attackers offer ‘too good to be true returns in order to acquire crypto wallet keys.
These assaults are also reflected in CertiK’s report, which stated that in Q2 of this year, losses from rug-pulls, in which attackers acquire a user’s trust before vanishing with their money, were $37.5 million.