Beosin: 36 Major Security Incidents in May Resulting in Over $76 Million in Losses
In May 2026, the Web3 ecosystem suffered over $76.15 million in losses across 36 major security incidents, according to Beosin Alert. The primary causes were contract vulnerabilities and private key leaks.
The top loss involved the Verus-Ethereum Bridge, which lost $11.58 million due to a cross-chain message validation flaw—a vulnerability type historically responsible for massive losses at Wormhole and Nomad. The Echo Protocol attack, resulting from a private key leak, saw the minting of 1,000 eBTC (nominal value ~$76.7M), with the attacker netting ~$5.13 million due to liquidity constraints.
Cross-chain bridges were the hardest-hit category, accounting for $27.995 million in losses. DeFi protocols were the most frequently targeted, with 14 attacks. Ethereum saw the highest chain-specific losses at over $48.76 million, followed by BNB Chain, Monad, and TON, indicating a multi-chain attack landscape.
A detailed analysis highlighted three key incidents:
1. **Verus-Ethereum Bridge**: A flaw where the bridge contract verified proof from the Verus chain but failed to validate the underlying asset value, allowing fake outputs.
2. **Trusted Volumes**: A signature parameter defect in its RFQ system allowed an attacker to manipulate authorization checks and drain assets from the Resolver contract.
3. **Private Key Leaks (e.g., StablR)**: Operational failures, including inadequate multi-signature wallet thresholds and lack of timelocks, led to losses exceeding $25 million across multiple projects.
The report concludes that the Web3 security threat landscape is expanding systemically. Risks now span code, infrastructure, interoperability, and human processes, moving beyond code audits alone. Projects are urged to enhance operational security, review old contracts, and users should regularly revoke unnecessary approvals.
marsbit06/10 09:26