OKX report says Web3 attacks shifted in H1 2026 as 5.7 million risky transactions were blocked

OKX report says Web3 attacks shifted in H1 2026 as 5.7 million risky transactions were blocked

A new OKX security review says publicly disclosed incidents rose while losses fell, with attackers moving from major smart contract exploits toward supply chain compromises, social engineering and AI-linked threats.

Fact Check
The official OKX Web3 Security Report: H1 2026 confirms publicly disclosed incidents rose (~50% YoY to 182) while total losses fell (~60% YoY to ~$956M), and that attacks shifted from smart-contract exploits toward supply chain compromises, social engineering, and AI-linked threats. The 5.7 million blocked risky transactions figure is corroborated by PANews and BlockBeats (both citing 570万), consistent with the interception activity described in the official report. All claim elements align with the primary source and independent reporting.
Summary

Web3 attack patterns in H1 2026 continued to move away from smart contract vulnerabilities and toward signing flows, user devices, infrastructure and AI agents, according to security research released by OKX. The company previously said it blocked more than 5.7 million high-risk transactions, including about 2.41 million tied to hacks and theft, 1.48 million related to phishing and 990,000 linked to scams. In a separate semiannual review produced with SlowMist and OtterSec, OKX said 182 publicly disclosed security incidents caused $956 million in losses in the first half, up 50% from 121 events a year earlier, while total losses fell about 60% from $2.373 billion. The report said the drop reflected the absence of an outlier event like the roughly $1.5 billion Bybit supply-chain attack in February 2025 and showed losses were led less by contract bugs than by supply chain compromises, social engineering, cloud key theft and single-point validation failures. Supply chain attacks accounted for about $298 million in losses, followed by contract logic issues at $152 million and private key leaks at $130 million. The report also highlighted AI-related risks, including the Bankr incident involving a prompt injection sent to xAI’s Grok that was forwarded to @bankrbot and led to transfers of about $150,000 to $200,000 on Base.

Terms & Concepts
  • smart contract: Self-executing code on a blockchain.
  • phishing: Fraud that tricks users into revealing credentials or approving transactions.
  • supply chain attacks: Breaches that target software, service providers or other upstream dependencies rather than the main platform itself.