Web3 Security Weekly Data Report — August 17–23, 2026

What does the data say about the week of Aug 17–23, 2026?

Tracked losses reached ~$96M, up 12% week-over-week, with ~4,700 affected addresses. Contract exploits remain the largest vector at 46%, phishing rose to a monthly-high 14%, and the w/w mix shows losses, event counts and affected addresses all climbing.

Overview — What Happened This Week

Week of August 17–23 saw tracked losses rise to ~$96M (+12% w/w). The increase is broad rather than spike-driven: event counts (+20%), affected addresses (+18%) and the largest single event (+21%) all rose together, while top-3 concentration fell from 74% to 57%. The most consequential shift is in the mix — phishing now carries 14% of losses (up from 11% last week), the clearest weekly move in the distribution.

Indicator Map

The indicator set is mapped from the standard TRON ecosystem metrics to a Web3 security lens. Each row shows the source metric, what I actually track for this site, and this week's value:

TRON indicatorWeb3 Security metricThis week
Active AddressesAffected / phished / victim wallet counts~4.7K affected
TransactionsMalicious tx volume / attack tx / suspicious share~310 attack txs (1.8%)
TVLLosses vs affected protocol TVL~$46M DeFi-related
Stablecoin SupplyStolen stablecoins (USDT/USDC/DAI)~$18.2M
USDT SupplyUSDT frozen / blacklisted (Tether actions)~$2.2M
TRX PriceToken prices used for loss conversionspot rates mid-Aug
Market CapAffected project valuationsn/a this week
DeFi VolumeDeFi attack amounts / fee theft~$46.0M
Energy PriceKey/seed trade cost, transfer gas (Tron link)stable
Energy DemandAudit demand / incident-response calloutsup slightly
StakingAttacked staking pools / victim stakes~$2.0M
FeesMalicious contract / phishing gas, scam deployselevated

Two rows need explanation. 'Affected addresses' counts unique addresses that lost funds or signed a malicious approval — it is a victim count, not a transaction count. 'Malicious transactions' counts the attack transactions themselves, which is why the two move independently.

Week-over-Week Changes

Comparing this week (Aug 17–23) against last week (Aug 10–16):

MetricThis weekLast weekChange
Tracked loss total~$96.0M~$86.0M+12%
Attack-type mixC 46% / K 28% / P 14%C 48% / K 26% / P 11%phishing +3 pts
Affected addresses~4.7K~4.0K+18%
Max single event~$23.5M~$19.5M+21%
Compromised projects1210+20%
Key-leak vs contract share28% vs 46%26% vs 48%keys +2 pts
Unrecovered share~89%~90%–1 pt

Reading the table as a whole: every absolute metric rose, but the two most informative moves are structural — the phishing share (+3 pts, the largest single move) and the key-leak share (+2 pts). Money is rotating toward smaller, human-targeted and key-based attacks.

Analysis

Which indicators grew fastest?

Phishing share grew fastest in relative terms: 11% → 14% of losses (+3 pts w/w, the largest move in the mix). In absolute terms the max single event rose fastest (+21% to ~$23.5M), followed by compromised projects (+20%) and affected addresses (+18%).

Which indicators declined?

Contract-exploit share declined for the fourth consecutive week, from 48% to 46% (−2 pts) — absolute contract losses still rose, the share fell. Regulatory share also eased (−2 pts) as no large new freeze cycle matched last week's, and the unrecovered share improved one point to ~89%.

Are there any anomalies?

No single metric triggered an anomaly threshold this week: the largest w/w move was +21% (max single event), below the ~30% threshold I treat as a red flag. The one item I flag despite the numbers is directional: phishing share has now risen in each of the past four weeks, and this week's +3 pts is the steepest single step.

Key Takeaways

Key Takeaways
  • Losses rose ~12% w/w to ~$96M — broad growth, with concentration falling from 74% to 57%.
  • The mix is the story: phishing share hit a monthly-high 14% and key-leak share rose to 28%.
  • No statistical anomaly this week, but the sustained phishing climb is the trend to act on.

Frequently Asked Questions

Where does the weekly loss data come from?

From whitelisted sources — Chainalysis, SlowMist, CertiK, PeckShield, Immunefi, rekt.news, block explorers and official statements — cross-checked where the trail is public.

Why do you track affected addresses separately from losses?

Because they answer different questions. Losses measure money moved; affected addresses measure people harmed. This week phishing had most of the victims but only 14% of the losses.

What does the unrecovered share mean?

It is 100% minus the preliminary recovery rate (funds frozen, labeled or returned). This week recovery was ~$11M on ~$96M, so ~89% remains unrecovered — consistent with recent weeks.

Which numbers are estimates?

Three figures are estimates, not exact counts: ~310 malicious transactions, ~$18.2M in stolen stablecoins, and 12 compromised projects. They are derived from whitelist sources and may revise as investigations close. Everything else — the ~$96M total, category split, shares and week-over-week changes — is computed from the same shared dataset and sums exactly.

Is this financial advice?

No. This is a data research report for informational purposes only, not investment or security advice.

Sources & Methodology

Sources

  1. Chainalysis - on-chain threat intelligence & loss data.
  2. SlowMist - security monitoring and incident advisories.
  3. CertiK & PeckShield - smart-contract incident analyses.
  4. TRONSCAN & main block explorers - on-chain verification.
  5. Project official blogs / X / GitHub - incident statements.
  6. Mainstream industry media, cross-checked against the whitelist.
  7. Figures labeled 'unconfirmed / under investigation' where the trail is not public.

Strengthening your defenses? See how transaction fees and energy costs scale on Tron at Tronsell.io.