attacks will always happen, that's just the nature of the game
the bigger issue is we're still building systems on the assumption that trusted things won't break, but they do.
keys get compromised, signers get social engineered, cloud accounts get taken over literally all the time.
we need to stop designing for "this won't fail" and start designing for "this WILL fail, now what!"
survival architecture > prevention
Web3 lost about $900M to hacks in the first half of 2026. Around three quarters of it left through keys, signers, cloud accounts and domains while the contracts held. We keep pointing audit budget at the one layer that is no longer where the money goes.
I wrote the article analyzing the hacks year-to-date and you can find it below.
burnnotice.adrianhetman.xyz/…