Web3 Security Weekly Data Report — August 24–30, 2026

What does the data say about the week of Aug 24–30, 2026?

Tracked losses fell to ~$79M, down 18% week-over-week — the first decline in four weeks — with ~4,100 affected addresses. Custody leads the mix at 27% after the cold-storage compromise, phishing hit a new monthly high of 16%, and contract share fell to 43%.

Overview — What Happened This Week

Week of August 24–30 saw tracked losses fall to ~$79M (-18% w/w), the first weekly decline after four consecutive increases. The decline is broad rather than event-driven: event counts, affected addresses and the largest single event all fell together, and top-3 concentration eased to 51%. The mix kept moving, though — custody jumped to 27% (the cold-storage signing-device compromise), phishing climbed to a new monthly high of 16%, and contract share fell to 43%. Fewer dollars, same rotation.

Indicator Map

The indicator set is mapped from the standard TRON ecosystem metrics to a Web3 security lens. Each row shows the source metric, what I actually track for this site, and this week's value:

TRON indicatorWeb3 Security metricThis week
Active AddressesAffected / phished / victim wallet counts~4.1K affected
TransactionsMalicious tx volume / attack tx / suspicious share~260 attack txs (1.4%)
TVLLosses vs affected protocol TVL~$35.7M DeFi-related
Stablecoin SupplyStolen stablecoins (USDT/USDC/DAI)~$14.8M
USDT SupplyUSDT frozen / blacklisted (Tether actions)~$2.2M
TRX PriceToken prices used for loss conversionspot rates late-Aug
Market CapAffected project valuationsn/a this week
DeFi VolumeDeFi attack amounts / fee theft~$35.7M
Energy PriceKey/seed trade cost, transfer gas (Tron link)stable
Energy DemandAudit demand / incident-response calloutsup slightly
StakingAttacked staking pools / victim stakes~$3.5M
FeesMalicious contract / phishing gas, scam deployselevated

Two rows need explanation. 'Affected addresses' counts unique addresses that lost funds or signed a malicious approval — it is a victim count, not a transaction count. 'Malicious transactions' counts the attack transactions themselves, which is why the two move independently.

Week-over-Week Changes

Comparing this week (Aug 24–30) against last week (Aug 17–23):

MetricThis weekLast weekChange
Tracked loss total~$79.0M~$96.0M-18%
Attack-type mixC 43% / K 27% / P 16%C 46% / K 28% / P 14%phishing +2 pts
Affected addresses~4.1K~4.7K-13%
Max single event~$17.2M~$23.5M-27%
Compromised projects1112-8%
Key-leak vs contract share27% vs 43%28% vs 46%keys -1 pt
Unrecovered share~88%~89%-1 pt

Reading the table as a whole: every absolute metric fell, but the mix kept rotating — phishing posted the only rising share (+2 pts, now 16%), custody held near 27% on a larger single event, and contract share fell 3 pts. The decline in totals did not reverse the structural rotation toward human-targeted and key-based attacks.

Analysis

Which indicators grew fastest?

Phishing share grew fastest again: 14% → 16% of losses (+2 pts w/w), a new monthly high — it has now risen week-over-week for four consecutive weeks. In relative dollar terms, custody losses grew on the back of the $17.2M cold-storage compromise even as the category count fell.

Which indicators declined?

Every headline absolute metric declined: tracked losses (-18%), affected addresses (-13%), max single event (-27%), compromised projects (-8%) and malicious transactions (-16%). Contract-exploit share fell 3 pts to 43%, and the unrecovered share improved one point to ~88%.

Are there any anomalies?

No single metric triggered an anomaly threshold: the largest w/w move was -27% (max single event), below the ~30% red flag I use. The item I flag is directional instead: this is the first weekly decline in a month, but $79M is still the second-highest week on record and sits only slightly below the trailing average — one down-week is a pause, not yet a trend.

Key Takeaways

Key Takeaways
  • Losses fell ~18% w/w to ~$79M — the first decline in four weeks, but still the second-highest week on record.
  • The mix kept rotating: phishing at a new monthly high of 16%, custody at 27%, contract down to 43%.
  • No statistical anomaly — read the decline as a pause until a second down-week confirms it.

Frequently Asked Questions

Where does the weekly loss data come from?

From whitelisted sources — Chainalysis, SlowMist, CertiK, PeckShield, Immunefi, rekt.news, block explorers and official statements — cross-checked where the trail is public.

Why do you track affected addresses separately from losses?

Because they answer different questions. Losses measure money moved; affected addresses measure people harmed. This week phishing again had most of the victims but only 16% of the losses.

Which numbers are estimates?

Three figures are estimates, not exact counts: ~260 malicious transactions, ~$14.8M in stolen stablecoins, and 11 compromised projects. They are derived from whitelist sources and may revise as investigations close. Everything else — the ~$79M total, category split, shares and week-over-week changes — is computed from the same shared dataset and sums exactly.

What does the unrecovered share mean?

It is 100% minus the preliminary recovery rate (funds frozen, labeled or returned). This week recovery was ~$9.5M on ~$79M, so ~88% remains unrecovered — consistent with recent weeks.

Is this financial advice?

No. This is a data research report for informational purposes only, not investment or security advice.

Sources & Methodology

Sources

  1. Chainalysis - on-chain threat intelligence & loss data.
  2. SlowMist - security monitoring and incident advisories.
  3. CertiK & PeckShield - smart-contract incident analyses.
  4. TRONSCAN & main block explorers - on-chain verification.
  5. Project official blogs / X / GitHub - incident statements.
  6. Mainstream industry media, cross-checked against the whitelist.
  7. Figures labeled 'unconfirmed / under investigation' where the trail is not public.

Strengthening your defenses? See how transaction fees and energy costs scale on Tron at Tronsell.io.