Cointime

Download App
iOS & Android

Major Web3 Security Incidents in 2022

Validated Individual Expert

In early January, a major study “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research” was published. It was jointly created by the companies Beosin, Buidler DAO, Legal DAO and Footprint Analytics. The study consisted of an overview of the ten largest security incidents of 2022 in Web3, global statistics on crypto crimes and regulatory policies of different countries in relation to crypto. Also, this document contains instructions that will help protect yourself in Web3 and the authors’ forecasts for 2023.

According to the study, in 2022 there were more than 167 major attacks in Web3. The total losses from attacks of all types were about $3.6 billion, which is 47.4% higher than in 2021 (approximately $2.44 billion). Most of the losses were caused by attacks on cross-chain bridges — 12 incidents with losses totalling $1.89 billion. And most other attacks (113) were directed at the DeFi sector.

Loss Amount & Count by Project Type. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

If we take into account all crimes related to crypto, including pyramid schemes, scams, money laundering, attacks/exploits and others (without financial crimes), the losses for 2022 amount to more than $13.7 billion.

2022 Crypto Crimes. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

The report linked the decrease of global TVL in 2022 to these events. As we can see from the graph below, the events such as Beanstalk, Luna Crash, Harmony, Nomad, Tornado Cash Sanction, The Merge, Wintermute, BNB Chain, Mango Markets, FTX collapse were all followed by withdrawal of capital from the crypto markets.

2022 TVL Trend. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

Furthermore, the study presents a list of the ten largest security incidents for 2022. We have summarised this list, highlighting data about the type of attack and the amount of losses incurred:

  1. Ronin Network (Loss: $624 Million; Attack Type: Social engineering)
  2. BSC Token Hub (BNB Chain) (Loss: $560 Million; Attack Type: Blockchain vulnerability)
  3. FTX hack (Loss: $440 Million; Attack Type: Suspected rugpull)
  4. Wormhole (Loss: $326 Million; Attack Type: Contract vulnerability — validation issue)
  5. Nomad bridge (Loss: $190 Million; Attack Type: Contract vulnerability — validation issue)
  6. Beanstalk (Loss: $182 Million; Attack Type: Flashloan)
  7. Wintermute (Loss: $160 Million; Attack Type: Private key compromise)
  8. Mango markets (Loss: $116 Million; Attack Type: Price manipulation)
  9. Elrond (Loss: $113 Million; Attack Type: VM issue)
  10. Harmony (Loss: $100 Million; Attack Type: Private key compromise)
Top 10 Loss Projects. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

As for the chains that were victims of the attacks, number one for losses went to the Ethereum blockchain with losses mounting to more than $2.01 billion and 59 incidents. The second place was taken by the BNB Chain, which lost about $0.8 billion, but was ahead in the number of incidents — 72. The third place was held by the Solana blockchain with losses of about $0.51 billion and 7 incidents.

Loss Amount & Count by Chain. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

In 2022, according to the study, 243 rug pulls were carried out. The total amount of damage to the industry from rug pulls was about $425 million (excluding $440 million FTX incident)

Rug Pulls by Month. Source: “Global Web3 Security Report 2022 & Crypto Regulatory Compliance Research”

As for the regulation of cryptocurrencies, in 2022, countries like the United States, EU member countries, Hong Kong SAR, Singapore, Japan, South Korea, Malaysia and the United Arab Emirates actively participated in this legislative sphere. The authors of the study note that in 2023 the main trend in regulatory policy will be “systematization”.

“In 2022, crypto ‘bombshells’ exploded frequently, accompanied by a dramatic market downturn that caused severe turmoil in the industry. 2023 will certainly see a response from global regulators. A number of regulatory trends are already emerging in 2022. In our view, one of the overarching themes of global crypto regulatory developments in 2023 is likely to be the “systematisation of the regulatory framework”. A large number of jurisdictions with rapidly growing crypto industries (e.g. the US, UK, Canada, etc.) have not yet developed a systematic regulatory framework. In these jurisdictions, there have been a large number of regulations issued by various regulatory or enforcement bodies, but the fragmentation has left many of the underlying legal concepts poorly answered and has made practice difficult. The good news is that we are seeing a clear trend towards ‘systematisation’ in 2022.”

The authors of the study also talked about what can be expected in the security sector in 2023. They wrote that the global regulatory system will develop, the entire infrastructure will be strengthened, stolen funds will be returned more often, more attacks will be blocked before they begin, and users will be more aware of basic security rules.

In conclusion, we recommend you familiarize yourself with the third chapter of this study, which describes security guidelines for Web3 users. And we continue to observe.

Comments

All Comments

Recommended for you

  • Fed Chair Nominee Waller: Independence Depends on the Fed Itself

    Fed Chair nominee Waller: I will be independent of Trump's opinions. Trump tends to call for the FOMC to cut interest rates. Independence depends on the Fed itself.

  • Digital Bank Revolut's IPO Valuation Could Reach $200 Billion

    The Financial Times reported, citing anonymous investor sources, that the UK digital bank Revolut plans to seek a valuation of $150 billion to $200 billion in its upcoming IPO, a significant increase from its previous valuation of $75 billion. The company's CEO, Nik Storonsky, also revealed that Revolut is preparing for a new round of secondary share sales in the second half of 2026, with a valuation potentially exceeding $100 billion.

  • ETH Falls Below $2300

    Market data shows that ETH has fallen below $2300, currently priced at $2299.92, with a 24-hour decline of 0.38%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Trump: Disappointed if New Fed Chair Does Not Cut Interest Rates

    On April 21, U.S. President Trump stated: If the new Federal Reserve Chair does not cut interest rates, I will be disappointed.

  • Chairman of the Joint Chiefs of Staff Milley States Readiness to Resume Operations

    On April 21, Chairman of the Joint Chiefs of Staff Mark Milley stated that the U.S. is ready to resume operations and can act against Iran at any time. (Axios)

  • Bank of Japan to Maintain Interest Rates in April

    On April 21, according to Nikkei News: The Bank of Japan will maintain interest rates unchanged in April.

  • Iranian Military: Ready to Respond Decisively to 'Enemy's Breach of Promises'

    On April 21, local time, Abdollahi, commander of the Khatam al-Anbiya Central Command of the Iranian Armed Forces, stated that Iran is prepared to respond decisively to the 'enemy's breach of promises.' Abdollahi emphasized that the current Iranian military possesses 'authority, readiness, and comprehensive strategic capabilities.' He noted that the Islamic Revolutionary Guard Corps and other defense forces have demonstrated combat capabilities in relevant operations, putting 'Israel and the United States in a difficult and fatigued position,' forcing them to 'seek a ceasefire.' Abdollahi also stressed that the Iranian armed forces maintain a high level of unity with the government and the people under the supreme leader's unified command, and will respond 'decisively, resolutely, and promptly' to any threats and actions. (CCTV News)

  • Another Iranian Oil Tanker Returns to Iran After Breaking US Blockade

    On April 21, according to CCTV News, maritime intelligence company 'TankerTrackers' reported that a tanker belonging to the National Iranian Tanker Company returned to Iran after unloading approximately 2 million barrels of crude oil in Indonesia, crossing the relevant maritime blockade line. The tanker is currently en route to Iran's main oil export hub, Khark Island, and is expected to arrive on April 22 local time. It is reported that the tanker set sail from Iran in late March, heading towards the Riau Islands of Indonesia.

  • White House: US and Iran on the Verge of Reaching an Agreement

    On April 21, White House Press Secretary Kayleigh McEnany stated in an interview with Fox News on the evening of the 20th that the United States and Iran are on the "verge of reaching an agreement." McEnany remarked, "The US has never been closer to achieving a truly good deal." However, she did not disclose any information regarding the current status of the negotiations. McEnany noted that even if an agreement is not reached, President Trump has multiple options and is not afraid to utilize these measures. Previous actions have demonstrated that Trump is not just "bluffing."

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.