CertiK: Web3 projects lost $2B+ to hacks and exploits in H1 2022, more than in all of 2021 combined; $308M was lost across 27 flash loan attacks in Q2 2022
Context & Ripple Effects
CertiK's H1 2022 tally extends a run the WSJ research had already flagged in April, when roughly $2.9B stolen across 38 weeks was nearly on par with all of 2021 — meaning the first half of 2022 alone outpaced that entire prior year. The standout detail is the $308M lost across 27 flash loan attacks in Q2, a DeFi-native vector consistent with CipherTrace's finding that DeFi made up 60%+ of hack volume in 2021.
The report also sets the baseline for CertiK's later annual scorecards: its 2023 tally of $1.8B across 751 hacks was framed as down 51% from the $3.7B lost in 2022, making this H1 figure the front-loaded half of that record year.
First-order effects
- Web3 projects and their liquidity providers absorb the losses directly, with flash loan attacks alone draining $308M from DeFi protocols in Q2 — attackers exploiting composability rather than stealing keys.
- Security auditors like CertiK see demand spike, since the report effectively markets their core service by quantifying what unaudited or under-audited code costs.
Second-order effects
- DeFi protocols face pressure to harden against flash loan vectors specifically — price-oracle manipulation and single-block borrowing — shifting security spend toward runtime monitoring and economic-attack modeling, not just code audits.
- Insurance and treasury products priced against protocol risk get repriced upward as loss data accumulates, raising effective costs for every project seeking coverage.
Third-order effects
- Annual loss tallies are consolidating into a standard industry metric — CertiK's later reports treat yearly totals as comparable series — which gives regulators and insurers a quantified basis for intervention if the pattern holds.
- If DeFi remains the dominant attack surface, security auditing shifts from optional pre-launch step to continuous infrastructure, concentrating power with the handful of firms that can monitor protocols at scale.
The trend: Crypto exploit losses have become an annually tracked, multi-billion-dollar baseline, with DeFi-specific vectors like flash loans keeping security economics central to how the industry is regulated and built.