Web3 Security Weekly Data Report — August 24–30, 2026
Tracked losses fell to ~$79M, down 18% week-over-week — the first decline in four weeks — with ~4,100 affected addresses. Custody leads the mix at 27% after the cold-storage compromise, phishing hit a new monthly high of 16%, and contract share fell to 43%.
- Tracked losses$79M
- Affected addresses4.1K
- Largest event$17.2M
- Unrecovered share~88%
Overview — What Happened This Week
Week of August 24–30 saw tracked losses fall to ~$79M (-18% w/w), the first weekly decline after four consecutive increases. The decline is broad rather than event-driven: event counts, affected addresses and the largest single event all fell together, and top-3 concentration eased to 51%. The mix kept moving, though — custody jumped to 27% (the cold-storage signing-device compromise), phishing climbed to a new monthly high of 16%, and contract share fell to 43%. Fewer dollars, same rotation.
Indicator Map
The indicator set is mapped from the standard TRON ecosystem metrics to a Web3 security lens. Each row shows the source metric, what I actually track for this site, and this week's value:
| TRON indicator | Web3 Security metric | This week |
|---|---|---|
| Active Addresses | Affected / phished / victim wallet counts | ~4.1K affected |
| Transactions | Malicious tx volume / attack tx / suspicious share | ~260 attack txs (1.4%) |
| TVL | Losses vs affected protocol TVL | ~$35.7M DeFi-related |
| Stablecoin Supply | Stolen stablecoins (USDT/USDC/DAI) | ~$14.8M |
| USDT Supply | USDT frozen / blacklisted (Tether actions) | ~$2.2M |
| TRX Price | Token prices used for loss conversion | spot rates late-Aug |
| Market Cap | Affected project valuations | n/a this week |
| DeFi Volume | DeFi attack amounts / fee theft | ~$35.7M |
| Energy Price | Key/seed trade cost, transfer gas (Tron link) | stable |
| Energy Demand | Audit demand / incident-response callouts | up slightly |
| Staking | Attacked staking pools / victim stakes | ~$3.5M |
| Fees | Malicious contract / phishing gas, scam deploys | elevated |
Two rows need explanation. 'Affected addresses' counts unique addresses that lost funds or signed a malicious approval — it is a victim count, not a transaction count. 'Malicious transactions' counts the attack transactions themselves, which is why the two move independently.
Week-over-Week Changes
Comparing this week (Aug 24–30) against last week (Aug 17–23):
| Metric | This week | Last week | Change |
|---|---|---|---|
| Tracked loss total | ~$79.0M | ~$96.0M | -18% |
| Attack-type mix | C 43% / K 27% / P 16% | C 46% / K 28% / P 14% | phishing +2 pts |
| Affected addresses | ~4.1K | ~4.7K | -13% |
| Max single event | ~$17.2M | ~$23.5M | -27% |
| Compromised projects | 11 | 12 | -8% |
| Key-leak vs contract share | 27% vs 43% | 28% vs 46% | keys -1 pt |
| Unrecovered share | ~88% | ~89% | -1 pt |
Reading the table as a whole: every absolute metric fell, but the mix kept rotating — phishing posted the only rising share (+2 pts, now 16%), custody held near 27% on a larger single event, and contract share fell 3 pts. The decline in totals did not reverse the structural rotation toward human-targeted and key-based attacks.
Analysis
Phishing share grew fastest again: 14% → 16% of losses (+2 pts w/w), a new monthly high — it has now risen week-over-week for four consecutive weeks. In relative dollar terms, custody losses grew on the back of the $17.2M cold-storage compromise even as the category count fell.
Every headline absolute metric declined: tracked losses (-18%), affected addresses (-13%), max single event (-27%), compromised projects (-8%) and malicious transactions (-16%). Contract-exploit share fell 3 pts to 43%, and the unrecovered share improved one point to ~88%.
No single metric triggered an anomaly threshold: the largest w/w move was -27% (max single event), below the ~30% red flag I use. The item I flag is directional instead: this is the first weekly decline in a month, but $79M is still the second-highest week on record and sits only slightly below the trailing average — one down-week is a pause, not yet a trend.
Key Takeaways
- Losses fell ~18% w/w to ~$79M — the first decline in four weeks, but still the second-highest week on record.
- The mix kept rotating: phishing at a new monthly high of 16%, custody at 27%, contract down to 43%.
- No statistical anomaly — read the decline as a pause until a second down-week confirms it.
Frequently Asked Questions
Where does the weekly loss data come from?
From whitelisted sources — Chainalysis, SlowMist, CertiK, PeckShield, Immunefi, rekt.news, block explorers and official statements — cross-checked where the trail is public.
Why do you track affected addresses separately from losses?
Because they answer different questions. Losses measure money moved; affected addresses measure people harmed. This week phishing again had most of the victims but only 16% of the losses.
Which numbers are estimates?
Three figures are estimates, not exact counts: ~260 malicious transactions, ~$14.8M in stolen stablecoins, and 11 compromised projects. They are derived from whitelist sources and may revise as investigations close. Everything else — the ~$79M total, category split, shares and week-over-week changes — is computed from the same shared dataset and sums exactly.
What does the unrecovered share mean?
It is 100% minus the preliminary recovery rate (funds frozen, labeled or returned). This week recovery was ~$9.5M on ~$79M, so ~88% remains unrecovered — consistent with recent weeks.
Is this financial advice?
No. This is a data research report for informational purposes only, not investment or security advice.
Strengthening your defenses? See how transaction fees and energy costs scale on Tron at Tronsell.io.