Web3 Security Weekly Data Report — August 17–23, 2026
Tracked losses reached ~$96M, up 12% week-over-week, with ~4,700 affected addresses. Contract exploits remain the largest vector at 46%, phishing rose to a monthly-high 14%, and the w/w mix shows losses, event counts and affected addresses all climbing.
- Tracked losses$96M
- Affected addresses4.7K
- Largest event$23.5M
- Unrecovered share~89%
Overview — What Happened This Week
Week of August 17–23 saw tracked losses rise to ~$96M (+12% w/w). The increase is broad rather than spike-driven: event counts (+20%), affected addresses (+18%) and the largest single event (+21%) all rose together, while top-3 concentration fell from 74% to 57%. The most consequential shift is in the mix — phishing now carries 14% of losses (up from 11% last week), the clearest weekly move in the distribution.
Indicator Map
The indicator set is mapped from the standard TRON ecosystem metrics to a Web3 security lens. Each row shows the source metric, what I actually track for this site, and this week's value:
| TRON indicator | Web3 Security metric | This week |
|---|---|---|
| Active Addresses | Affected / phished / victim wallet counts | ~4.7K affected |
| Transactions | Malicious tx volume / attack tx / suspicious share | ~310 attack txs (1.8%) |
| TVL | Losses vs affected protocol TVL | ~$46M DeFi-related |
| Stablecoin Supply | Stolen stablecoins (USDT/USDC/DAI) | ~$18.2M |
| USDT Supply | USDT frozen / blacklisted (Tether actions) | ~$2.2M |
| TRX Price | Token prices used for loss conversion | spot rates mid-Aug |
| Market Cap | Affected project valuations | n/a this week |
| DeFi Volume | DeFi attack amounts / fee theft | ~$46.0M |
| Energy Price | Key/seed trade cost, transfer gas (Tron link) | stable |
| Energy Demand | Audit demand / incident-response callouts | up slightly |
| Staking | Attacked staking pools / victim stakes | ~$2.0M |
| Fees | Malicious contract / phishing gas, scam deploys | elevated |
Two rows need explanation. 'Affected addresses' counts unique addresses that lost funds or signed a malicious approval — it is a victim count, not a transaction count. 'Malicious transactions' counts the attack transactions themselves, which is why the two move independently.
Week-over-Week Changes
Comparing this week (Aug 17–23) against last week (Aug 10–16):
| Metric | This week | Last week | Change |
|---|---|---|---|
| Tracked loss total | ~$96.0M | ~$86.0M | +12% |
| Attack-type mix | C 46% / K 28% / P 14% | C 48% / K 26% / P 11% | phishing +3 pts |
| Affected addresses | ~4.7K | ~4.0K | +18% |
| Max single event | ~$23.5M | ~$19.5M | +21% |
| Compromised projects | 12 | 10 | +20% |
| Key-leak vs contract share | 28% vs 46% | 26% vs 48% | keys +2 pts |
| Unrecovered share | ~89% | ~90% | –1 pt |
Reading the table as a whole: every absolute metric rose, but the two most informative moves are structural — the phishing share (+3 pts, the largest single move) and the key-leak share (+2 pts). Money is rotating toward smaller, human-targeted and key-based attacks.
Analysis
Phishing share grew fastest in relative terms: 11% → 14% of losses (+3 pts w/w, the largest move in the mix). In absolute terms the max single event rose fastest (+21% to ~$23.5M), followed by compromised projects (+20%) and affected addresses (+18%).
Contract-exploit share declined for the fourth consecutive week, from 48% to 46% (−2 pts) — absolute contract losses still rose, the share fell. Regulatory share also eased (−2 pts) as no large new freeze cycle matched last week's, and the unrecovered share improved one point to ~89%.
No single metric triggered an anomaly threshold this week: the largest w/w move was +21% (max single event), below the ~30% threshold I treat as a red flag. The one item I flag despite the numbers is directional: phishing share has now risen in each of the past four weeks, and this week's +3 pts is the steepest single step.
Key Takeaways
- Losses rose ~12% w/w to ~$96M — broad growth, with concentration falling from 74% to 57%.
- The mix is the story: phishing share hit a monthly-high 14% and key-leak share rose to 28%.
- No statistical anomaly this week, but the sustained phishing climb is the trend to act on.
Frequently Asked Questions
Where does the weekly loss data come from?
From whitelisted sources — Chainalysis, SlowMist, CertiK, PeckShield, Immunefi, rekt.news, block explorers and official statements — cross-checked where the trail is public.
Why do you track affected addresses separately from losses?
Because they answer different questions. Losses measure money moved; affected addresses measure people harmed. This week phishing had most of the victims but only 14% of the losses.
What does the unrecovered share mean?
It is 100% minus the preliminary recovery rate (funds frozen, labeled or returned). This week recovery was ~$11M on ~$96M, so ~89% remains unrecovered — consistent with recent weeks.
Which numbers are estimates?
Three figures are estimates, not exact counts: ~310 malicious transactions, ~$18.2M in stolen stablecoins, and 12 compromised projects. They are derived from whitelist sources and may revise as investigations close. Everything else — the ~$96M total, category split, shares and week-over-week changes — is computed from the same shared dataset and sums exactly.
Is this financial advice?
No. This is a data research report for informational purposes only, not investment or security advice.
Strengthening your defenses? See how transaction fees and energy costs scale on Tron at Tronsell.io.