Web3生态系统在2025年以 renewed momentum 进入,受到宏观经济条件改善、投资者信心增强以及美国政治气候明显更支持的影响。美国新政府迅速采取行动,将数字资产定位为战略性创新领域而非监管异常,早期发出信号表明区块链技术将受到鼓励而非限制。这一转变恢复了建设者、机构和风险投资的信心,帮助去中心化应用更深入地扩展到支付、游戏、资产代币化、身份解决方案和现实世界金融用例中。
然而,随着生态系统活动的加速,威胁形势也在加剧。网络对手与行业同步发展,改进了技术漏洞利用和社会工程技术。尽管创新激增,2025年成为一个 stark reminder,表明增长和风险在Web3中继续并行发展。
根据行业数据,2025年的总损失达到33.5亿美元,较2024年的24.5亿美元增长了37%。乍一看,这些数字表明安全状况 dramatic deterioration。然而,仔细观察 reveals a more nuanced picture。单一事件,Bybit漏洞利用,约占当年损失的14.5亿美元。当这一异常值被排除时,总体被盗资金将 year over year 下降,突显了攻击者行为的关键转变。
威胁行为者不再依赖大量中型漏洞利用,而是 increasingly concentrated resources into fewer but far more devastating operations。Bybit事件 demonstrated the growing presence of well-funded, highly coordinated adversaries capable of executing complex, long-horizon attacks。这一趋势表明,尽管许多协议的基线安全卫生正在改善,但系统性风险仍然存在,特别是在基础设施和供应链层面。
在对攻击向量进行分类时,网络钓鱼 emerged as the most prevalent threat in 2025。排除Bybit供应链漏洞,网络钓鱼在248起事件中造成了7.229亿美元的损失,在频率上超过了代码漏洞和基础设施攻击。代码相关的漏洞利用紧随其后,在240起事件中造成了5.546亿美元的损失,尽管近一半的资金最终被冻结或归还,突显了 improved response coordination and on-chain intervention capabilities。
人工智能在塑造这一 evolving threat environment 中 played a defining role。在防御方面,开发者 increasingly relied on AI-powered tools to generate test cases, identify inefficiencies, enhance formal verification, and streamline audit workflows。相反,攻击者大规模采用了相同的技术。AI生成的网络钓鱼界面变得 nearly indistinguishable from legitimate dApps and wallet prompts,而 automated multilingual campaigns expanded reach into previously insulated communities。
威胁行为者还 leveraged AI for reconnaissance, scraping on-chain data and private chat channels to identify high-value targets。冒充攻击 grew more convincing, with fake founder accounts, synthetic voices, and deepfake videos eroding traditional trust signals。或许最令人担忧的是漏洞利用复制的速度,因为AI工具 enabled attackers to copy and deploy successful attack patterns within days or even hours。
2025年全年,监管 clarity improved significantly,帮助稳定了更广泛的生态系统。在美国,GENIUS法案建立了稳定币监管和数字资产透明度的早期框架,同时 signaling a more cooperative stance toward innovation。全球范围内,欧盟 advanced toward full MiCA implementation,提高了披露和消费者保护的标准。与此同时,新加坡和香港等司法管辖区 expanded digital asset sandboxes,巴西和哥伦比亚等国家 progressed toward regulated commodity tokenization frameworks。
这些 developments contributed to more structured governance and influenced how projects approached compliance, architecture, and operational security。随着 regulations matured,安全 increasingly became a prerequisite for market access rather than an optional feature。
今年最重大的事件之一发生在二月,当时Bybit suffered the largest crypto theft in history。这次攻击 attributed to the Lazarus Group,并未直接利用Bybit的内部系统。相反,攻击者 compromised a developer machine at Safe{Wallet}, a third-party multi-signature wallet provider。注入钱包界面的恶意代码 invisibly altered transaction details,导致授权签署人 unknowingly approve fraudulent transfers。该事件 exposed the growing risks associated with trusted tooling and supply-chain dependencies。
除了大规模漏洞, individual users faced mounting risks。AI驱动的网络钓鱼、深度伪造冒充和 targeted social engineering attacks surged throughout the year。许多损失未报告,特别是那些与 off-chain scams such as pig-butchering schemes and investment fraud 相关的损失,表明 actual user losses are likely far higher than recorded figures。
随着2026年的临近,Web3安全的轨迹 becoming clearer。预计攻击者将进一步 refine AI-powered impersonation and phishing campaigns,而供应链攻击 may grow more sophisticated。与此同时, stronger regulation, real-time monitoring, and AI-assisted defenses offer a path toward reducing preventable losses。
2025年的CertiK
2025年是CertiK的 milestone year,以 expanded research, deeper ecosystem integrations, and continued leadership in Web3 security 为标志。以下是塑造这一年的 key achievements:
- 将Token Scan与ChainGPT和Binance Wallet集成,将实时代币风险分析直接扩展到广泛使用的Web3工具中。
- 发布了Skynet稳定币聚焦报告:2025年上半年,对稳定币 landscape, key vulnerabilities, and how the Skynet Security Score can be used to assess stablecoin risk 进行了深入审查。
- 发布了2025年Skynet RWA安全报告,为现实世界资产(RWA)协议提供了 structured due-diligence criteria and a comprehensive risk review framework。
- 推出了2025年Skynet韩国Web3安全与生态系统报告,提供了对韩国Web3市场动态的 insights and profiling leading platforms in the region。
- 发布了2025年Skynet数字资产国库(DAT)报告,引入了Skynet DAT安全与合规框架,以评估 operational integrity beyond surface-level metrics。
- 发布了Skynet美国数字资产政策报告,总结了美国GENIUS法案和CLARITY法案的 legal foundations, market-structure implications, and operational requirements。
- 对Canton Network上的USDCx铸币和销毁过程进行了 full-scale security assessment,包括 on-chain Daml智能合约的审计和 off-chain infrastructure 的渗透测试。
- 推出了CertiK SkyNode,一个 validator node service designed to improve network security, reliability, and performance across multiple public blockchain ecosystems。
- 与蚂蚁集团的AntChain(蚂蚁密集计算)共同发表了研究, focused on the formal verification of core components within the Asterinas operating system。
- 引入了LiDO框架,由CertiK联合创始人邵中教授提出, addressing critical security challenges in Byzantine Fault Tolerant (BFT) consensus mechanisms。
- 获得了以太坊基金会的两项资助, reinforcing CertiK’s leadership position in zkEVM formal verification research。
- 推出了Skynet排行榜,一个 security-focused ranking platform designed to evaluate and compare crypto and Web3 project security。
- 发布了生态系统特定的展示排行榜以支持战略Layer 1增长,包括 dedicated leaderboards for BNB Chain and SUI。
在这个 rapidly evolving environment 中,长期成功将 depend on integrating security into every layer of Web3 development。作为最大的Web3安全服务提供商,CertiK continues to play a central role in safeguarding the ecosystem, supporting thousands of projects, and strengthening trust as blockchain technology moves closer to mainstream adoption。





