CertiK Annual Security Report: Web3 Losses Increase 37% Year-on-Year in 2025, Phishing Attacks and Supply Chain Incidents Emerge as Major Threats

marsbitPublished on 2025-12-25Last updated on 2025-12-25

Abstract

CertiK's 2025 Skynet Hack3D Security Report reveals that the Web3 industry suffered approximately $3.35 billion in losses across 630 security incidents, a 37% increase from 2024. While the number of incidents decreased by 137, the average loss per attack surged by 66.6% to $5.32 million, indicating a trend toward targeting high-value assets. The most significant losses resulted from supply chain attacks, which accounted for nearly half of the total losses ($1.45 billion) despite only two recorded incidents. The largest was the February Bybit breach, where attackers compromised a third-party multi-signature wallet service to bypass security protocols. Phishing remained the most frequent threat, with 248 incidents causing $723 million in losses. The report warns that AI is amplifying these attacks by generating highly convincing fake websites and targeted scam messages, making traditional defenses less effective. Amid growing risks, regulatory clarity is improving globally, with advancements in U.S. stablecoin legislation and frameworks like MiCA in the EU. Security is shifting from a reactive cost to a core infrastructure element. The report concludes that projects embedding security into their design and development will be better positioned for the future.

On December 23, CertiK, the world's largest Web3 security company, released the "2025 Skynet Hack3D Web3 Security Report," systematically outlining the major security incidents and risk trends in the Web3 space over the past year. The report indicates that while the Web3 industry is accelerating its development amid a recovering market environment and clearer regulatory expectations, security risks have not eased and continue to pose systemic security threats.

The report shows that in 2025, the Web3 space experienced 630 security incidents, resulting in total losses of approximately $3.35 billion, a 37% year-on-year increase compared to 2024. Although the number of incidents decreased by 137 compared to the previous year, the average loss per attack reached $5.322 million, a sharp increase of 66.6%, highlighting the trend of attackers targeting high-value objectives.

Supply Chain Attacks Drive Annual Losses Higher

In terms of attack types, supply chain attacks became the largest source of losses in 2025. Despite only two recorded incidents throughout the year, the cumulative losses amounted to $1.45 billion, accounting for nearly half of the total annual losses. The majority of these losses stemmed from the Bybit incident in February.

According to the report, the security incident experienced by Bybit in February 2025 resulted in approximately $1.4 billion in losses, making it one of the largest cryptocurrency thefts to date. The attackers did not directly breach the exchange's system but instead infiltrated the developer environment of a third-party multi-signature wallet service provider, embedding malicious code in the signing process to bypass multiple approval mechanisms.

CertiK noted in the report that such incidents reflect attackers increasingly focusing their resources on critical service providers and underlying tools rather than individual protocols, underscoring that supply chain security has become an unavoidable systemic risk.

High Frequency of Phishing Attacks, AI Acts as an "Amplifier"

In terms of attack frequency, phishing remained the most common security threat in 2025. The report shows that a total of 248 phishing attack incidents were recorded throughout the year, resulting in approximately $723 million in losses, slightly higher than the number of code vulnerability attacks (240 incidents).

Notably, CertiK believes this figure may still be an underestimate. A significant number of phishing and scam incidents targeting individual users were not formally disclosed, especially those involving smaller losses or off-chain social engineering attacks.

The report emphasizes that the proliferation of artificial intelligence is significantly lowering the technical barriers to phishing attacks. Attackers are increasingly using AI to generate highly realistic phishing websites, wallet pop-ups, and multilingual scam messages, combined with on-chain data and social media content for "precision targeting." Traditional defense methods relying on grammatical errors or template features for identification are gradually becoming ineffective.

Regulatory Clarity Increases, Security Shifts from "Cost Item" to "Infrastructure"

Amid rising risks, the report also notes positive changes in the global regulatory environment. Legislative progress in the U.S. around stablecoins and digital asset transparency has sent clearer policy signals to the industry. Regulatory frameworks such as the EU's MiCA, Singapore's regulatory sandbox, and Hong Kong's initiatives are also pushing Web3 toward a more standardized development phase.

CertiK pointed out in the report that as institutional and compliant funds continue to enter the space, security capabilities are transitioning from "post-incident remediation" to an infrastructure element in project design and operations. For both project teams and individual users, security is no longer optional but a critical factor affecting long-term viability.

The report concludes by projecting that in the coming year, AI-driven impersonation attacks, increasingly complex supply chain intrusions, and social engineering attacks targeting individual users will continue to evolve. In this context, projects that embed security into architectural design, development processes, and user experience are more likely to stand out in the next wave of Web3 competition.

Full report: https://indd.adobe.com/view/6935ac85-c644-4048-9e27-1d310549aa0a

Related Questions

QAccording to CertiK's 2025 report, what was the total financial loss in the Web3 sector and what was the year-over-year percentage increase?

AThe total financial loss in the Web3 sector was approximately $3.35 billion, representing a 37% year-over-year increase compared to 2024.

QWhich type of attack was identified as the largest source of loss in 2025, and what was a key characteristic of the Bybit incident?

ASupply chain attacks were the largest source of loss. A key characteristic of the Bybit incident was that attackers did not directly breach the exchange's system but instead compromised a third-party multi-signature wallet service provider's developer environment to inject malicious code.

QWhat was the most frequent type of attack in 2025, and how is AI impacting this threat?

APhishing attacks were the most frequent, with 248 recorded incidents. AI is acting as an 'amplifier' by lowering the technical barrier, enabling attackers to create highly realistic phishing sites, wallet pop-ups, and multi-language scam messages for 'precision targeting'.

QHow did the average loss per attack change in 2025, and what does this trend indicate?

AThe average loss per attack reached $5.322 million, a sharp increase of 66.6% year-over-year. This trend highlights that attackers are concentrating their efforts on higher-value targets.

QHow is the role of security changing for Web3 projects according to the report's view on the evolving regulatory landscape?

AWith clearer regulations and more institutional capital entering the space, security is shifting from being a 'cost item' and 'remedial measure' to a fundamental 'infrastructure' element that is integrated into project design and operations, crucial for long-term viability.

Related Reads

Analyzing the Impact of AI on Economic Growth and Productivity

**Title: Analyzing AI's Impact on Economic Growth and Productivity** This article examines three contrasting views on AI's influence on economic growth and productivity. **The Optimistic View** posits that AI, especially through automating R&D ("recursive self-improvement"), could dramatically accelerate growth, even triggering a technological "singularity" with explosive, potentially infinite, economic expansion. **The Moderate/Mainstream View** acknowledges AI's productivity benefits but emphasizes significant real-world constraints that could limit its impact. These include: limited cost savings per task, structural ceilings on which jobs and industries are "exposed" to AI, adoption bottlenecks (e.g., compute, energy, regulatory hurdles), and the "weak link" effect where non-automatable tasks cap overall gains. Consequently, the realized AI dividend may be far lower than optimistic projections, with estimates typically ranging from 0.1% to 1.3% annual productivity growth. **The Pessimistic View** stems from two strands. The first aligns with the moderate view but applies extremely conservative assumptions about task exposure and efficiency gains, yielding minimal projected impact. The second introduces a demand-side critique: if AI primarily replaces rather than augments labor, it could depress labor's share of income, weaken consumer demand, and create a "demand trap" that ultimately stifles growth, unless offset by redistribution policies. **The authors' assessment** is nuanced: * **Short-term (1-2 years):** AI will support growth primarily through investment spending, not significant productivity gains. * **Medium-term (3-5 years):** Three potential paths emerge based on AI demand and bottleneck severity: 1. **"Optimistic Path":** High demand, few bottlenecks. Rapid productivity gains but risk of major job displacement and social conflict without redistribution. 2. **"Moderate Path" (most likely):** High demand but significant, surmountable bottlenecks. Leads to moderate productivity gains, financial market volatility (K-shaped returns), and sectoral job losses. 3. **"Pessimistic Path":** Low demand or severe bottlenecks. Minimal productivity and growth impact, triggering financial market corrections but allowing a smoother societal transition with less labor disruption. * **Long-term:** AI holds potential for a major productivity revolution and prosperity. The conclusion stresses that no path is smooth. Technologically "optimistic" outcomes could be socially detrimental, while "pessimistic" technological diffusion might be more socially stable. Policymakers must monitor developments and prepare balanced responses to manage economic, financial, and social sustainability.

marsbit1m ago

Analyzing the Impact of AI on Economic Growth and Productivity

marsbit1m ago

The New Cold War is a Tech Stock War

The New Cold War is a Tech Stock War The article argues that the contemporary geopolitical and economic rivalry between the US and China represents a "New Cold War," but one fundamentally fought through technology and financial markets, not physical barriers or conventional trade. Historically, US dominance was secured through financial systems. The Soviet Union, reliant on the rigid "Transferable Ruble," was ultimately undermined by its dependency on the US dollar for oil trade. Later, Japan's semiconductor challenge was countered not just by tariffs (e.g., Plaza Accord, 301 investigations) but by binding it to US Treasury bonds. China presents a more complex, "embedded" challenger. While it holds vast dollar reserves and US debt like Japan, its industrial base is stronger and more diversified than the Soviet Union's. Surviving the initial 2018 trade war phase, the conflict has evolved into a "tech-financial war." The core battlefield is now the stock market. US tech stocks (AI, semiconductors) are treated as sovereign assets, buoyed by bipartisan national will. China is pushing to strengthen its own financial markets to convert industrial strength into financial power and fund its tech ambitions. Companies like ChangXin (semiconductors), Moonshot AI, and DJI compete not just for market share but as financial proxies for their respective systems. The new paradigm is moving from globally efficient monopolies (Apple, Google) towards companies that achieve monopolistic profits within their respective geopolitical spheres. This competition over "pricing power" and financial valuation in segmented markets defines the current era, making the stock market the primary arena for this tech-centric struggle.

marsbit10m ago

The New Cold War is a Tech Stock War

marsbit10m ago

RWA Weekly: Ten European Financial Institutions Establish Tokenized Asset Cooperative; Ondo Launches New Execution Network Ondo Network

RWA Weekly: European Banks Form Tokenized Asset Cooperative; Ondo Launches New Execution Network Ondo Network Covering July 24-31, 2026, the RWA sector saw a steady on-chain total value locked (TVL) of $36.8 billion, with holder count hitting a record high. However, stablecoin transfer volumes fell sharply (~30%), indicating low on-chain settlement demand. Key regulatory moves include South Korea advancing stablecoin legislation and a push to scrap crypto taxes, Kenya lowering capital requirements for stablecoin issuers, and Zimbabwe approving seven projects for its crypto sandbox. In project developments, BIS-led Project Agorá successfully tested cross-border payments with tokenized funds across six currencies. Ten major European financial institutions formed the RL1 blockchain cooperative to build tokenized asset infrastructure. Other notable updates: Aviva launched a tokenized dollar liquidity fund on XRPL, POSCO International tokenized commercial invoices on Injective, and a Brazilian farmer used tokenized cattle as collateral for a loan. Additional progress includes BNY Mellon migrating its core transfer agent operations to blockchain, Securitize gaining SEC investment advisor registration, and Tether’s compliant stablecoin USA₮ launching on Celo. Ondo Finance introduced Ondo Network, a new execution layer focused on speed and privacy, moving away from its initial chain plans. An analysis highlights that despite the growing scale of on-chain RWAs (~$32B), approximately 90% remain underutilized in DeFi, pointing to a critical challenge in unlocking liquidity and fostering real-world application beyond mere issuance.

marsbit11m ago

RWA Weekly: Ten European Financial Institutions Establish Tokenized Asset Cooperative; Ondo Launches New Execution Network Ondo Network

marsbit11m ago

South Korean Stock Market Sees Sharp Rebound After Forceful De-leveraging, SK Hynix Rises 30%

On July 31, South Korean stocks staged a historic rebound. The benchmark KOSPI index surged 18.27%, with chipmaker SK Hynix hitting a 30% gain limit. This followed a brutal, near-40% decline in the KOSPI over the previous month, driven largely by a deleveraging spiral involving leveraged ETFs. Analysts attributed the sharp sell-off to structural liquidity issues rather than deteriorating corporate fundamentals. The rally was triggered by a confluence of positive catalysts. Firstly, strong earnings from U.S. cloud giants Microsoft and Amazon alleviated fears of an "AI bubble burst," boosting global tech sentiment. Secondly, SK Group Chairman Chey Tae-won made a rare personal purchase of SK Hynix shares, seen as a strong vote of confidence. Thirdly, the South Korean government announced a 20 trillion won ($139 billion) AI investment fund. In response to the market turmoil, South Korean regulators are tightening controls on leveraged ETFs, admitting oversight shortcomings. Measures include raising minimum cash保证金 requirements for散户 investors and suspending new product launches. While the rebound signals eased liquidity pressure, analysts note deep structural issues remain. The market's future stability is seen as dependent on global tech capital expenditure trends and memory chip price cycles, with some viewing the surge as a technical correction rather than a definitive trend reversal.

marsbit31m ago

South Korean Stock Market Sees Sharp Rebound After Forceful De-leveraging, SK Hynix Rises 30%

marsbit31m ago

Trading

Spot
活动图片