The Quantstamp Blog
.png)](/content/blog/may-2026-security-beat/index.html)
May 2026 Security Beat
$59.52M was lost across 29 crypto incidents, down sharply from April's ~$635M. No single hack carried the month. The bigger story happened off-chain, where a self-propagating npm worm called Mini Shai-Hulud kept resurfacing in new waves through the month, ultimately spanning more than 1,000 malicious package versions across the npm ecosystem.
April 2026 Security Beat: Same Actors, New Targets
April was undoubtedly a rocky month in security. $635M was lost across 28 crypto incidents. The Axios npm package was compromised on day one, exposing an estimated 600,000 installs in three hours. Vercel was breached through a third party. Three major CVEs under active exploitation. Here's the month in security 👇
Engineering Smart Contract Families for Solidity
Decentralized applications (dApps) (e.g., DEXes) increasingly span multiple Ethereum-compatible chains, such as a number of L2s. Although these chains are intended to be compatible with the Ethereum Virtual Machine (EVM), subtle differences in opcode implementations can significantly alter smart contract behavior and security. This poses an important question: how can developers efficiently code and manage smart contracts targeting different chains?
Will EIP-7702 Affect Your Code?
The upcoming EVM hardfork, Pectra, amongst other changes, will implement EIP-7702, a proposal introducing a new transaction type that allows Externally Owned Accounts (EOAs) to delegate—and later undelegate—their behavior to smart contracts. While this upgrade enhances flexibility, it also disrupts long-standing security assumptions in many deployed contracts. With the risk that malicious actors may exploit these changes once Pectra is enabled, it is crucial to assess whether your codebase might be negatively impacted.
When AI Meets Blockchain: A Guide to Securing the Next Frontier
In recent months, AI agents have attracted significant attention by the promise of assisting users and automating complex processes across diverse applications. The rapid performance improvements of Large Language Models (LLMs) in natural language processing (NLP) tasks drive this trend. However, as the capabilities and reach of these agents expand, so do the risks. The rapid pace of development, combined with the intricacies of integrating LLMs into real-world infrastructures—especially in dynamic fields like blockchain—has created an urgent need to scrutinize them for security, compliance, and operational integrity.
Monthly Hacks Roundup: March 2024
March was a volatile month for the web3 security landscape, with significant security breaches totaling over $152 million in losses. Read on as we dive into four major security incidents and the trends from last month 👇
Modular Account: How Audits Can Help Shape Standards And Catalyze Mass Adoption
Quantstamp recently conducted a smart contract audit for Alchemy’s Modular Account, a wallet implementation designed from the ground up for ERC-4337 and ERC-6900 compatibility including two plugins
Quantstamp 2023 Web3 Security Year In Review
As the year comes to a close, we wanted to take a moment to reflect on this year’s biggest hacks, root causes, and noteworthy trends.
DeFi Protection: Compensating Users For DeFi Losses
Quantstamp has developed a framework for compensating users affected by DeFi losses, aiming to set new industry standards.
Partnering with Toku to Enhance Web3 Security & Payroll Practices
Quantstamp is thrilled to announce a strategic partnership with Toku, marking a significant milestone in our commitment to web3 security and compliance.
Why Bitcoin is Capturing Enterprise Attention
MicroStrategy made headlines this summer as the first publicly-traded company to buy Bitcoin as part of its capital allocation strategy. Since then, other companies have followed suit. Learn how current economic conditions and the unique properties of Bitcoin have driven these decisions.
Formally Verifying Hedera Hashgraph's Stablecoin Framework
Quantstamp created and formally verified a specification for Hedera Hashgraph stablecoins. This simplifies the process of creating safe stablecoins and also makes easier for partners to safely integrate them.
Quantstamp Completes Audit of 2nd ETH 2.0 Implementation
Quantstamp has now completed its audit of Teku, the Ethereum 2.0 client developed by ConsenSys. Quantstamp also audited Prysm by Prysmatic Labs.
Ethereum Gas Fees Rising, But L2 Solutions Are Coming
Read about the projects developing Layer 2 scaling solutions that can scale Ethereum before ETH 2.0.
Chasing Yield with DeFi Aggregators
The DeFi space has seen impressive innovation and traction over the last two years. As DeFi continues to evolve, DeFi aggregators are emerging as a strong trend. As user-facing products built on decentralized infrastructure, DeFi aggregators unlock the potential for higher yields and a better user experience.
Quantstamp Audits Binance Smart Chain
Quantstamp has audited Binance Smart Chain, a blockchain that runs parallel to Binance Chain optimized for DeFi.