Beyond the Audit: Why Web3 Security Needs Operational Controls
At Dedaub, we know operational security (OpSec) matters for Web3 projects, and we have been providing clients with OpSec advisory notes on specific engagements. But OpSec usually sits outside the scope of an audit, so that advice was ad hoc rather than structured. Now, in collaboration with the Security Alliance (SEAL), we can offer those clients properly structured advice. We assess them against the SEAL Certification Framework, an open standard developed collaboratively by Web3 security practitioners.
OpSec has become an increasingly important focus in Web3 as attackers move beyond smart contract vulnerabilities to phishing, credential theft, compromised signing systems, and infrastructure attacks. In our sample of 135 major incidents since 2024, operational failures accounted for a third of cases and two-thirds of the money lost.
What 135 Web3 Hacks Show About Operational Security
Web3 hacks expose weaknesses in both protocol design and operational security. Using AI, we created this dataset from 135 Rekt incidents published between January 2024 and August 2026, representing about USD 4.9 billion in reported amounts.
The AI extracted the reported data and classified each incident by root cause. These classifications are AI-generated for this analysis and are not classifications published by Rekt News.
OpSec compromises mean stolen keys, phishing, malware, and abuse of privileged access.
- By count: 44 of the 135 incidents, or 32.6%.
- By value: USD 3.3 billion, or 66.9% of the total.
A third of the incidents, two-thirds of the money. Although the sample isn’t comprehensive and six cases are unresolved, it offers a good understanding of OpSec failures’ impact. The full dataset, with a source link for every incident, is at go.dedaub.com/opsec-research.
| Period | Incidents | OpSec incidents | OpSec share of incidents | Reported amount (USD) | OpSec share of amount |
|---|---|---|---|---|---|
| 2024 | 43 | 14 | 32.6% | 1.29B | 80.1% |
| 2025 | 48 | 20 | 41.7% | 2.36B | 77.0% |
| 2026 (through 30 Aug) | 44 | 10 | 22.7% | 1.24B | 33.9% |
| Total | 135 | 44 | 32.6% | 4.89B | 66.9% |
The money column matters. What the sample shows:
Across the full sample, OpSec compromises accounted for a third of incidents and two-thirds of reported amounts.
In 2024 and 2025, they accounted for between a third and two-fifths of incidents and close to four-fifths of the money.
Per incident, the average OpSec incident cost about USD 74 million, against USD 15 million for an audit-addressable one.
One 2025 incident accounts for about 29% of all value in the sample; with it removed, OpSec still takes 53% of the money across the period and 41% in 2025.
So far in 2026, the share has fallen on both measures, to 22.7% of incidents and 33.9% of reported amounts. That may be an early sign that teams are hardening their operations, although the figure rests on 44 incidents, a partial year, and one large incident of mixed cause.
Fewer OpSec incidents, but still the expensive ones.
Smart Contract Audits Secure the Protocol, Not the Operations Around It
An audit is still necessary. For protocols holding significant value, independent security review remains a fundamental layer of defense. But every audit has a defined scope, and operational security usually sits outside it. Unless explicitly included in scope, an audit typically does not check who holds the signing keys, how those keys are stored and rotated, whether the deployment pipeline can be poisoned, whether the domain registrar account has phishing-resistant login, or who makes the call at 3 a.m. when an alert fires. Even a thoroughly audited contract will execute a valid transaction signed by an authorized key, regardless of who has gained control of that key. Securing the code and securing the operation around it are different jobs, but the former has traditionally received far more formal third-party scrutiny.
What the Security Alliance (SEAL) Is
The Security Alliance (SEAL) is a nonprofit whose mission is “Securing the future of crypto.” It runs several programs for the ecosystem: SEAL 911, a free 24/7 emergency response service; SEAL Intel, for threat intelligence; Wargames, for incident response drills; Safe Harbor, a legal framework that lets protocols pre-authorize whitehats to rescue funds during an exploit; and SEAL Frameworks and Certifications, which set open operational security standards. This post covers the last one.
How the SEAL Certification Framework Works
SEAL built the certification program in the open. On November 18, 2025, it published a request for comments and announced it on X, inviting protocols and security firms to shape the standard before finalizing it. SEAL’s own diagnosis was that “there’s no standardized way for them to demonstrate operational security maturity”, even for protocols with strong smart contract audits.
The rules it set were simple: accredited firms deliver the assessments and set their own pricing, the checklists stay free and open source, and certifications are issued as onchain attestations through the Ethereum Attestation Service.
In 2026, the program began moving from pilot validation into active certification, starting with supervised first engagements through accredited firms. The framework covers six modules, each of which can be scoped on its own:
- Multisig Ops: signer set, M-of-N design, key rotation, and recovery
- Treasury Ops: custody, policy, and onchain controls for protocol and DAO treasuries
- Incident Response: detection, escalation, and emergency execution
- DevOps & Infrastructure: development environment, source code, CI/CD, and cloud infrastructure
- DNS & Registrar: domain, DNS, and certificate integrity
- Identity & Accounts: account ownership, credentials, and access lifecycle
SEAL maintains the standard and accredits the assessing firms; the firm performs the assessment, and SEAL issues the onchain certification. A protocol is certified module by module. A module passes when every control in its scope is scored Implemented or N/A with a justification the reviewer verifies, the evidence substantiates the claims, and the overall security posture meets the framework’s requirements.
A certification gives a protocol proof it can show. The attestation is public and cryptographically verifiable onchain, while the evidence and the assessment report stay confidential between the protocol and the assessor. In SEAL’s words, it demonstrates that the protocol “has implemented a set of standardized operational practices to manage and mitigate risk”. That proof is starting to carry market value: SEAL reports that institutional investors now ask about operational security standards during due diligence, and that insurance carriers are beginning to offer preferential rates to protocols that can show comprehensive risk management. The program is modular, so a team can certify its highest-priority area first, say incident response or treasury operations, and build up from there. SEAL is also working on a formal mapping to SOC 2 and ISO 27001, so the work is meant to count toward those frameworks too. Certifications are time-limited and re-assessed periodically, and SEAL is careful to say an attestation is not a guarantee against every future vulnerability. See the Certification Guidelines for scoring and evidence requirements.
How Dedaub Assesses Against the SEAL Framework
Dedaub’s operational security assessments cover the same six domains, mapped one-to-one to the SEAL Certifications framework, and every item we assess follows the framework’s published control criteria. Each domain is scoped on its own, so a protocol can take all six or only the ones that matter. What we look at in each:
- Multisig Ops: the M-of-N design, signer hygiene, key rotation, and recovery, then every privileged role mapped to the funds it can actually move. That includes the propose, verify, execute process for transactions, signer onboarding and offboarding, and emergency drills.
- Treasury Ops: custody architecture, the registry of treasury wallets, exposure limits, and whether the limits, signers, and delays you documented are the controls that actually execute onchain.
- Incident Response: monitoring coverage of critical systems, alerting that reliably reaches an available responder, playbooks for common incident types, signer reachability for emergency onchain actions at any hour, backup signing infrastructure with pre-prepared emergency transactions, and drills with evaluated results.
- DevOps & Infrastructure: repositories, secrets, delivery pipelines, and infrastructure; reviewed the way an attacker maps them: repository controls, secret scanning, dependency management, who can modify and execute pipelines, infrastructure as code, least-privilege access, and tested backup and disaster recovery.
- DNS & Registrar: domain inventory, registrar hardening and locks, DNS and email authentication standards, TLS certificate lifecycle, and monitoring configured to catch a record or certificate change the instant it happens.
- Identity & Accounts: how organizational accounts are protected, reviewed, and revoked: phishing-resistant MFA, credential standards with individual accountability, account lifecycle from provisioning through offboarding, takeover monitoring, and time-limited third-party access.
Every weakness we find is tied back to exactly what it can do to funds onchain. Where a control falls short of the framework, the report details the gap, and the protocol can reassess once it is fixed.
To request a quote, use the OpSec assessment form: tell us the project and which domains matter, and we get back to you.
Dedaub has partnered with SEAL to offer its clients security certification under the SEAL framework. Dedaub conducts the assessment, and SEAL issues the certification as an onchain attestation. For more information, visit https://dedaub.com/operational-security/





