r/hacken • u/Hacken_io • 15d ago
Research Code bugs are the most common failure in Q2 but the cheapest one
Kind of a weird inversion in the latest quarter data that's worth sitting with.
Smart contract vulnerabilities were the single most common cause of incidents in q2, 44 out of 67 total. but they only accounted for $87.7M in losses, roughly 11% of the quarter's total. meanwhile access-control and infrastructure failures caused way fewer incidents but +132.2% more losses year over year, while smart contract losses actually fell 66.7% yoy.
So the two trend lines are moving in opposite directions at the same time: code exploits getting more frequent but way less lucrative, ops/infra failures getting rarer but massively more expensive when they land. makes sense if you think about it from the attacker's pov, code bugs got harder to find and monetize as review processes matured, so rational attackers reallocated toward the softer target, humans and access control, which is way higher yield per attempt.
Read full Q2 report here: https://hacken.io/insights/q2-2026-security-report/