CertiK Releases 2025 Skynet Hack3D Report, Showing $3.35 Billion Stolen in Blockchain Security Incid
NEW YORK, Dec. 24, 2025 (GLOBE NEWSWIRE) -- CertiK, the world's largest Web3 security services provider, released its 2025 Skynet Hack3D Web3 Security Report, providing a comprehensive review of major security incidents and risk trends across the Web3 ecosystem over the past year. The report finds that, while the industry accelerated its recovery amid improving market conditions and clearer regulatory expectations, security risks remained elevated and therefore continue to pose systemic challenges.
According to the report, the Web3 sector experienced 630 security incidents in 2025, resulting in total losses of approximately $3.35 billion, representing a 37% year-over-year increase. While the number of incidents declined by 137 compared to 2024, the average loss per incident surged to $5.32 million, up 66.6% from the previous year, highlighting a clear shift by attackers toward higher-value targets.
By attack vector, supply chain attacks emerged as the most financially damaging threat in 2025. Although only two such incidents were recorded throughout the year, they accounted for a combined $1.45 billion in losses, nearly half of the total annual damage. The majority of these losses stemmed from the Bybit incident in February.
As detailed in the report, Bybit suffered an estimated $1.4 billion loss following a security incident in February 2025, and is widely regarded as one of the largest cryptocurrency thefts to date. Rather than directly breaching the exchange's core systems, attackers compromised the development environment of a third-party multi-signature wallet service provider, inserting malicious code into the signing workflow and effectively bypassing multi-approval safeguards. CertiK notes that incidents of this nature reflect a broader strategic shift among attackers toward targeting critical service providers and foundational tooling, rather than individual protocols alone.
In terms of frequency, phishing attacks remained the most common security threat in 2025. The report recorded 248 phishing-related incidents, which led to approximately $723 million in losses. The number of phishing incidents slightly exceeded those caused by code vulnerabilities (240 cases).
CertiK cautions that these figures are likely understated. A significant number of phishing and scam incidents targeting individual users go unreported, particularly those involving smaller losses or off-chain social engineering attacks.
The report further emphasizes that the widespread adoption of artificial intelligence is dramatically lowering the barrier to entry for phishing attacks. Threat actors are increasingly leveraging AI to generate highly convincing phishing websites, wallet pop-ups, and multi-lingual scam messages, often combining on-chain data with social media intelligence for more targeted campaigns. As a result, traditional detection methods that rely on grammatical errors or recognizable templates are becoming progressively less effective.
Amid rising security risks, the report also highlights positive developments in the global regulatory landscape. Legislative progress in the United States around stablecoins and digital asset transparency has provided clearer policy signals, while frameworks such as the EU's MiCA, along with regulatory sandboxes in Singapore and Hong Kong, are helping guide the Web3 industry toward more standardized and compliant growth.
CertiK observes that, as institutional and compliance-driven capital continues to enter the market, security is evolving from a reactive, post-incident expense into a foundational component of system design and operations. For both projects and individual users, security has become a decisive factor in long-term resilience and viability.
Looking ahead, the report concludes that AI-driven impersonation attacks, increasingly sophisticated supply chain compromises, and social engineering schemes targeting individual users are likely to continue evolving in the coming year. In this environment, projects that embed security directly into their architecture, development workflows, and user experience will be best positioned to stand out in the next phase of Web3 competition.
Full report: https://indd.adobe.com/view/d21da0b0-06c4-4f38-a82b-c7757971064b
- Schneider Electric’s new research forecasts AI’s impact on energy consumption
- 打造高端经济型酒店“性价比之王” 城市便捷实现“造价省大半、卖价进中档”
- 2024智建会凝聚科技创新成果,促进建筑低碳发展
- 福州爱尔:女子突然右眼看不见,医生紧急提醒:冬季高发,“三高”人群更需警惕
- “春糖节”来啦!第110届全国糖酒会引爆消费热情
- 电力热能企业售后电话自动接听机器人客服系统
- 顺势·赢增长:2024足力健南方大战区秋季新品发布会圆满落幕
- 极空间私有云引领AI时代 携手奕斯伟计算共同推动RDI生态繁荣
- GNC健安喜携手小苹果医疗共庆医师节,向生命守护者致敬!
- Whispeara Reviews (Complaints & Side Effects): Buyers Reveal Unexpected Truths Behind Its Real E
- 欧盟公告机构(BSI荷兰)和欧洲药品管理局批准LeukoStrat® CDx FLT3突变检测在欧盟和欧洲经济区用于VANFLYTA®治疗
- 超级码溯源智能秤:一秤搞定茶青收购、加工称重、库存管理!
- 新南威尔士州产业和贸易部长访问诺为泰首尔办公室,深化临床试验合作
- SLB OneSubsea获得Equinor的Fram Sør项目EPC合同
- 中国电能表平台火热招商中!!!
- 点燃孩子的寒假学习激情:光明园迪学习桌椅,新年的最佳礼物!
- 海南农业产业化标杆再获认可 南国食品蝉联“国家级重点龙头企业”称号
- 天生倔强脸的白纸新人,徐畅演艺生涯初舞台获得肯定!
- 索斯科亚洲新生产基地落址佛山高明
- Canva将收购生成式人工智能平台Leonardo.AI,为所有组织带来领先的视觉人工智能技术
- 温度升级,美置商业2024“小悦队”焕新出道 ——优质陪伴,让爱与成长同行!
- 嘻哈包袱铺再赴新疆和田,传统曲艺助力文化交流与融合
- 画家李心禅获任海峡两岸文化交流大使,助推两岸艺术交融
- 冠君产业信托ESG Gala举行共创明“Teen”电影放映会
- WadzPay Plans to Expand Portfolio into Stablecoin Business
- 荣耀加冕!第五届爱尔眼科EVO ICL眼内镜手术国际论坛圆满落幕,翁景宁教授揽获双誉
- 纺织品的未来:HiggIndex认证与绿色制造的结合
- 【喜迎七一建党节特别报道】 國宝级國医大师——周培富
- 中国农业发展银行怀化市分行安全生产培训及应急演练
- “阶段性服药”“可逆转”,2型糖尿病领域迎来重磅中药创新药!
推荐
-
周星驰新片《少林女足》在台湾省举办海选,吸引了不少素人和足球爱好者前来参加
周星驰新片《少林女足》在台湾省举办海选,吸
资讯
-
大家一起关注新疆乌什7.1级地震救援见闻
看到热气腾腾的抓饭马上就要出锅、村里大家
资讯
-
新增供热能力3200万平方米 新疆最大热电联产项目开工
昨天(26日),新疆最大的热电联产项目—&md
资讯
-
男子“机闹”后航班取消,同机旅客准备集体起诉
1月4日,一男子大闹飞机致航班取消的新闻登上
资讯
-
国足13次出战亚洲杯首次小组赛0进球
北京时间1月23日消息,2023亚洲杯小组
资讯
-
奥运冠军刘翔更新社交账号晒出近照 时隔473天更新动态!
2月20日凌晨2点,奥运冠军刘翔更新社交账号晒
资讯
-
王自如被强制执行3383万
据中国执行信息公开网消息,近期,王自如新增一
资讯
-
海南大学生返校机票贵 有什么好的解决办法吗?
近日,有网友在“人民网领导留言板&rdqu
资讯
-
中央气象台连发四则气象灾害预警
暴雪橙色预警+冰冻橙色预警+大雾黄色预警+
资讯
-
看新东方创始人俞敏洪如何回应董宇辉新号分流的?
(来源:中国证券报)
东方甄选净利润大幅下滑
资讯

