Skynet Hack3D Report Highlights Web3 Security in 2025

TheNewsCryptoPublicado em 2025-12-24Última atualização em 2025-12-24

Resumo

Web3 entered 2025 with strong momentum due to improved macroeconomic conditions, supportive U.S. policies, and growing institutional confidence. However, total losses from cyberattacks reached $3.35 billion, a 37% increase from 2024. Excluding the $1.45 billion Bybit exploit—attributed to the Lazarus Group via a supply-chain attack—losses actually decreased year-over-year, indicating a shift toward fewer but more sophisticated and high-value attacks. Phishing was the most common attack vector, accounting for $722.9 million across 248 incidents, followed by code-related exploits at $554.6 million. AI played a dual role: enhancing defensive tools like automated audits while also enabling highly convincing phishing campaigns, deepfake impersonations, and rapid exploit replication. Regulatory clarity improved with the U.S. GENIUS Act and E.U.’s MiCA implementation, raising security and compliance standards. CertiK expanded its security offerings, integrating risk analysis tools, publishing major reports, and advancing research in zkEVM and consensus mechanisms. As Web3 grows, integrating security at all levels remains essential to mitigate evolving AI-driven and systemic risks.

The Web3 ecosystem entered 2025 with renewed momentum, buoyed by improving macroeconomic conditions, stronger investor confidence, and a noticeably more supportive political climate in the United States. The new U.S. administration moved quickly to position digital assets as a strategic innovation sector rather than a regulatory anomaly, sending an early signal that blockchain technology would be encouraged rather than restrained. This shift restored confidence among builders, institutions, and venture capital, helping decentralized applications expand deeper into payments, gaming, tokenized assets, identity solutions, and real-world financial use cases.

Yet, as activity accelerated across the ecosystem, so did the threat landscape. Cyber adversaries evolved alongside the industry, refining both technical exploits and social engineering techniques. While innovation surged, 2025 became a stark reminder that growth and risk continue to move in parallel within Web3.

According to industry data, total losses in 2025 reached $3.35 billion, marking a 37% increase compared to $2.45 billion in 2024. At first glance, the numbers suggest a dramatic deterioration in security conditions. However, a closer look reveals a more nuanced picture. One single incident, the Bybit exploit, accounted for approximately $1.45 billion of the year’s losses. When this outlier is excluded, overall stolen funds would have declined year over year, underscoring a critical shift in attacker behavior.

Rather than relying on a high volume of mid-sized exploits, threat actors increasingly concentrated resources into fewer but far more devastating operations. The Bybit incident demonstrated the growing presence of well-funded, highly coordinated adversaries capable of executing complex, long-horizon attacks. This trend suggests that while baseline security hygiene is improving across many protocols, systemic risks remain, particularly at the infrastructure and supply-chain level.

When categorizing attack vectors, phishing emerged as the most prevalent threat in 2025. Excluding the Bybit supply-chain breach, phishing accounted for $722.9 million stolen across 248 incidents, surpassing both code vulnerabilities and infrastructure attacks in frequency. Code-related exploits followed closely, resulting in $554.6 million across 240 incidents, although nearly half of those funds were eventually frozen or returned, highlighting improved response coordination and on-chain intervention capabilities.

Artificial intelligence played a defining role in shaping this evolving threat environment. On the defensive side, developers increasingly relied on AI-powered tools to generate test cases, identify inefficiencies, enhance formal verification, and streamline audit workflows. Conversely, attackers adopted the same technologies at scale. AI-generated phishing interfaces became nearly indistinguishable from legitimate dApps and wallet prompts, while automated multilingual campaigns expanded reach into previously insulated communities.

Threat actors also leveraged AI for reconnaissance, scraping on-chain data and private chat channels to identify high-value targets. Impersonation attacks grew more convincing, with fake founder accounts, synthetic voices, and deepfake videos eroding traditional trust signals. Perhaps most concerning was the speed of exploit replication, as AI tools enabled attackers to copy and deploy successful attack patterns within days or even hours.

Regulatory clarity improved significantly throughout 2025, helping stabilize the broader ecosystem. In the U.S., the GENIUS Act established early frameworks for stablecoin oversight and digital asset transparency, while signaling a more cooperative stance toward innovation. Globally, the European Union advanced toward full MiCA implementation, raising standards for disclosures and consumer protection. Meanwhile, jurisdictions such as Singapore and Hong Kong expanded digital asset sandboxes, and countries including Brazil and Colombia progressed toward regulated commodity tokenization frameworks.

These developments contributed to more structured governance and influenced how projects approached compliance, architecture, and operational security. As regulations matured, security increasingly became a prerequisite for market access rather than an optional feature.

One of the year’s most significant incidents occurred in February, when Bybit suffered the largest crypto theft in history. The attack, attributed to the Lazarus Group, did not exploit Bybit’s internal systems directly. Instead, attackers compromised a developer machine at Safe{Wallet}, a third-party multi-signature wallet provider. Malicious code injected into the wallet interface altered transaction details invisibly, causing authorized signers to unknowingly approve fraudulent transfers. The incident exposed the growing risks associated with trusted tooling and supply-chain dependencies.

Beyond large-scale breaches, individual users faced mounting risks. AI-driven phishing, deepfake impersonation, and targeted social engineering attacks surged throughout the year. Many losses went unreported, particularly those linked to off-chain scams such as pig-butchering schemes and investment fraud, suggesting that actual user losses are likely far higher than recorded figures.

As 2026 approaches, the trajectory of Web3 security is becoming clearer. Attackers are expected to further refine AI-powered impersonation and phishing campaigns, while supply-chain attacks may grow more sophisticated. At the same time, stronger regulation, real-time monitoring, and AI-assisted defenses offer a path toward reducing preventable losses.

2025 at CertiK

2025 marked a milestone year for CertiK, defined by expanded research, deeper ecosystem integrations, and continued leadership in Web3 security. Below are some of the key achievements that shaped the year:

  • Integrated Token Scan with ChainGPT and Binance Wallet, extending real-time token risk analysis directly into widely used Web3 tools.
  • Published the Skynet Stablecoin Spotlight Report: H1 2025, delivering an in-depth review of the stablecoin landscape, key vulnerabilities, and how the Skynet Security Score can be used to assess stablecoin risk.
  • Released the 2025 Skynet RWA Security Report, providing structured due-diligence criteria and a comprehensive risk review framework for real-world asset (RWA) protocols.
  • Launched the 2025 Skynet Korea Web3 Security & Ecosystem Report, offering insights into South Korea’s Web3 market dynamics and profiling leading platforms in the region.
  • Published the 2025 Skynet Digital Asset Treasuries (DAT) Report, introducing the Skynet DAT Security & Compliance Framework to evaluate operational integrity beyond surface-level metrics.
  • Released the Skynet U.S. Digital Asset Policy Report, summarizing the legal foundations, market-structure implications, and operational requirements of the GENIUS Act and CLARITY Act in the United States.
  • Conducted a full-scale security assessment of the USDCx mint and burn process on Canton Network, including audits of on-chain Daml smart contracts and penetration testing of off-chain infrastructure.
  • Launched CertiK SkyNode, a validator node service designed to improve network security, reliability, and performance across multiple public blockchain ecosystems.
  • Co-published research with Ant Group’s AntChain (Ant Dense Computing) focused on the formal verification of core components within the Asterinas operating system.
  • Introduced the LiDO framework, presented by CertiK Co-Founder Professor Shao Zhong, addressing critical security challenges in Byzantine Fault Tolerant (BFT) consensus mechanisms.
  • Secured two grants from the Ethereum Foundation, reinforcing CertiK’s leadership position in zkEVM formal verification research.
  • Rolled out Skynet leaderboards, a security-focused ranking platform designed to evaluate and compare crypto and Web3 project security.
  • Released ecosystem-specific showcase leaderboards to support strategic Layer 1 growth, including dedicated leaderboards for BNB Chain and SUI..

In this rapidly evolving environment, long-term success will depend on integrating security into every layer of Web3 development. As the largest Web3 security services provider, CertiK continues to play a central role in safeguarding the ecosystem, supporting thousands of projects, and strengthening trust as blockchain technology moves closer to mainstream adoption.

TagsBlockchainexchange

Perguntas relacionadas

QWhat was the total value of losses in the Web3 ecosystem in 2025, and how did it compare to the previous year?

ATotal losses in 2025 reached $3.35 billion, which was a 37% increase compared to the $2.45 billion lost in 2024.

QWhich single incident was responsible for the largest portion of losses in 2025, and how much was stolen?

AThe Bybit exploit was the largest single incident, accounting for approximately $1.45 billion of the year's total losses.

QWhat was the most prevalent type of attack vector in 2025, excluding the Bybit incident?

APhishing was the most prevalent attack vector, accounting for $722.9 million stolen across 248 incidents.

QHow did artificial intelligence (AI) impact the Web3 security landscape in 2025?

AAI was used both defensively by developers for tasks like generating test cases and enhancing audits, and offensively by attackers for creating convincing phishing interfaces, automated multilingual campaigns, reconnaissance, and rapid exploit replication.

QWhat significant U.S. regulatory development for digital assets is mentioned in the report?

AThe GENIUS Act established early frameworks for stablecoin oversight and digital asset transparency, signaling a more cooperative U.S. stance toward innovation.

Leituras Relacionadas

How Will the Price Move Before SpaceX's Next Share Unlock?

TL;DR Investors buying SPCX after SpaceX's IPO are not simply investing in a typical tech stock. It’s a high-valuation asset driven by Musk's narrative, Starlink, and space transport potential, but with a key twist: a very small initial float of ~4% has led to significant post-listing price appreciation. The current price action reflects a timing gap. Before the first lock-up expiration (estimated around August, subject to official confirmation), scarcity and high demand could continue to push prices up. Short-term bulls focus on low float, FOMO, and potential index inclusion. However, bears point to the supply dynamics that will change post-lockup. Existing shareholders still hold over 95% of shares, which will be released in stages starting from the first unlock window. This introduces future selling pressure from low-cost holders. The upcoming Q2 earnings report is a critical catalyst before the unlock. It will test whether the company's fundamentals can justify the current ~$2.1T valuation. Strong results could support the pre-unlock momentum, while weak figures could amplify concerns about future supply. The trading thesis is shifting from immediate scarcity ("can't buy enough") to evaluating future absorption capacity ("who will buy when more supply hits"). The path ahead hinges on the specifics of the unlock schedule, Q2 earnings performance, and whether anticipated passive index buying materializes.

marsbitHá 2m

How Will the Price Move Before SpaceX's Next Share Unlock?

marsbitHá 2m

Bitcoin Short-Term Bullish Structure Validated, HYPE Low-Entry Window Opens | Guest Analysis

**Market Analysis Summary (Week of June 2026)** **Overall Market Context:** The market environment is exceptionally complex, with the unexpected US-Iran agreement and the reopening of the Strait of Hormuz triggering a global asset repricing and significant volatility. This heightened noise underscores the importance of a structured analytical framework. **Bitcoin (BTC) Analysis & Strategy:** * **Current Status:** The price has climbed above $65,000, currently in a rebound phase (segment 38-39) following a complex 12-segment correction from the May high of $82,850. * **Key Levels:** * **Primary Resistance:** $69,500–$70,500. A successful breakout above $65,000 targets this zone. * **Primary Support:** $65,000 (immediate), followed by $59,000–$60,000 and $55,000. * **Weekly Outlook & Strategy:** The focus is on the confirmation of the $65,000 level. * **Bullish Scenario (Hold $65K):** A move toward the $69.5K–$70.5K resistance zone is anticipated, which is a potential area for initiating medium-term short positions. * **Bearish Scenario (Break below $65K):** A retest of the $60,000–$62,000 support range is likely. * **Medium-Term Strategy:** Currently neutral. Plan to establish short positions (up to 60% allocation) either in the $69.5K–$70.5K resistance zone upon signs of rejection, or on a confirmed breakdown below $65,000 and further below $59K–$60K. * **Short-Term Strategy:** Utilize 30% capital for scalping opportunities based on support/resistance levels, using 30/60-minute charts. **HYPE Analysis & Strategy:** * **Current Status:** The price has stabilized around $52 after a four-segment decline from the June high of $75.87 and is now in a rebound (segment 50-51). * **Key Levels:** * **Primary Resistance:** $62.50–$64.57. Watch for potential rejection here to form a lower high. * **Primary Support:** $52–$55.50, followed by $47–$49. * **Weekly Outlook & Strategy:** Adopt a "buy on dips, avoid chasing rallies" approach. * **Core View:** Monitor the price action and potential formation of a lower high ("endpoint 51") in the $62.50–$64.57 resistance zone. * **Short-Term Strategy:** Consider light long positions (max 30% allocation) if the price finds support and shows reversal signals in the $52–$54.50 or deeper $47–$49 support zones, confirmed by proprietary quantitative bottom signals. **Trade Review:** Last week's HYPE short-term long trade, executed based on proprietary "Price Difference" and "Momentum" model signals, yielded a profit of approximately 11.88%. The entry was near $54.39 and exit near $60.85. **Risk Management Reminder:** Always set an initial stop-loss upon entry. Move stop-loss to breakeven at +1% profit, then trail it upwards to lock in gains as the trade progresses. *Disclaimer: All analysis, models, and strategies are based on personal technical analysis for educational purposes only, not investment advice. The market carries inherent risk.*

Odaily星球日报Há 7m

Bitcoin Short-Term Bullish Structure Validated, HYPE Low-Entry Window Opens | Guest Analysis

Odaily星球日报Há 7m

Bitcoin Short-Term Bullish Structure Validated, HYPE Accumulation Window Opens | Guest Analysis

**Bitcoin and HYPE Market Analysis: Short-Term Outlook and Trading Strategies** This market analysis examines Bitcoin (BTC) and HYPE amid volatile conditions, providing short-term outlooks and specific trading strategies. **Key Outlooks:** * **Bitcoin (BTC):** Focus is on whether BTC's recent move above $65,000 holds. A successful breakout could lead to a test of the $69,500-$70,500 resistance zone, where medium-term short positions are considered. A failure, breaking below $65,000, may trigger a decline towards the $59,000-$60,000 support area. * **HYPE:** The token completed a four-wave correction and is now rebounding. The key resistance zone is $62.5-$64.57. The trading strategy is "buy on dips," looking for entry opportunities near the $52-$54.5 or deeper $47-$49 support zones, pending confirmation from proprietary models. **BTC Trading Strategy:** * **Medium-term:** Primarily looking to establish short positions (up to 60% allocated capital) if price rallies to the $69,500-$70,500 resistance area and shows signs of reversal. Alternative plans involve initiating shorts on a breakdown below $65,000. * **Short-term:** Allocate up to 30% capital for intraday "spread" trades based on support/resistance levels on 30/60-minute charts. **HYPE Trading Strategy:** * **Short-term:** Adopt a dip-buying approach. Consider light long positions (under 30% capital) when price tests key support levels ($52-$54.5 or $47-$49) and shows stabilization, confirmed by proprietary "Price Spread" and "Momentum Quant" models. **Trade Recap:** The analysis reviews a successful HYPE long trade from the previous week, executed at ~$54.39 and closed at ~$60.85 for an ~11.88% gain, based on signals from the aforementioned models. **Risk Management Emphasis:** The article stresses strict capital allocation (under 30-60%), immediate initial stop-loss placement, and a trailing stop-loss protocol to lock in profits as trades move favorably. ***Disclaimer:** All analysis, models, and strategies are for educational purposes based on technical analysis, not investment advice. Markets are volatile; trade with caution.*

marsbitHá 9m

Bitcoin Short-Term Bullish Structure Validated, HYPE Accumulation Window Opens | Guest Analysis

marsbitHá 9m

Trading

Spot
Futuros
活动图片