OODA Releases Web3 Cyber Incident Database

Interactive research project looks at hacking risks for blockchain, cryptocurrency, and NFT projects, documenting over $61 Billion dollars in losses to date.


RESTON, Va., Feb. 16, 2022 /PRNewswire/ -- Over the past several years, there has been a rapid emergence of companies, projects, and initiatives in what is broadly categorized as Web3. While monitoring that rapid innovation, the OODA research team has noticed a disproportionately high number of cybersecurity incidents that have the potential to negatively impact the Web3 innovation ecosystem, disrupt customer adoption of these technologies, and result in consumer and enterprise monetary losses.

OODA has compiled a Web3 incident database based on our research to categorize what compromises are taking place as well as document the cyberattack root causes. Tracking root causes provides insights into how innovators can create robust cyber risk management approaches and reduce the potential for consequential attacks.

"We believe that Web3 technologies represent the future of innovation and will be highly disruptive to existing economic, technical, and cybersecurity models. However, with these great opportunities come cyber risks that must be appropriately managed to realize the full promise of these approaches", noted OODA CEO Matt Devost. "By releasing this Web3 incident database, we hope to inform those risk models and provide useful constructs for managing cyber risk in the future."

The Web3 incident database currently documents 155 incidents that have resulted in over $61 Billion Dollars in lost value (in today's dollars) with the root causes of the most costly incidents being primarily insiders, contract flaws, intrusions, and social engineering.

Analysis of the data indicates the number of incidents attributed to a root cause does not correlate to the value lost in an incident. The largest number of incidents are intrusions by unauthorized adversaries, with 36% of the incidents being in this category. But this accounts for only 14% of the total loss. Only 9% of the incidents were attributed to insiders, but this accounts for 52% of the total value lost.

The Web3 Incident Database is available at the OODA Loop site at the following URL:


Content is dynamically maintained and up to date, and is also fully searchable and sortable based on date, incident type, past and current monetary value of the incident, and cryptocurrency impacted.


OODA helps clients identify, manage, and respond to global risks and uncertainties while exploring emerging opportunities and developing robust and adaptive strategies for the future. They are a global strategic advisory firm with deep DNA in global security, technology, and intelligence issues.

OODA services include technology and cybersecurity consulting, M&A advisory and due diligence, and the firm also operates a global research team and expert network at OODAloop.com. For more information on OODA, please visit www.ooda.com.