【GoPlus Annual Security Report: In 2025, there were over 1200 Web3 security incidents, with losses exceeding $3.5 billion】
BlockBeats news, December 30, according to GoPlus RektDatabase data, in 2025, the Web3 sector experienced more than 1200 severe security incidents, resulting in total losses exceeding $3.5 billion. Among these, private key theft (based on viruses, Trojans, and social engineering), phishing attacks, and Rug Tokens (fraudulent tokens) are the most common types of attacks and fraud.
Specifically, regarding major incidents, the following are the top three incidents ranked by loss amount in 2025:
#bybit Theft incident (February 21, loss of $1.5 billion)
#Cetus Theft incident (May 22, loss of $223 million)
#balancer Theft incident (November 2, loss of $128 million)
The security situation shows characteristics of an “increase in the number of large-scale incidents” and a “significant reduction in the cost of small fraud for users,” with attackers displaying a trend of **“precision hunting” and “broad net”** in their strategies.
It is worth noting that there were a total of 12 attack incidents in 2025 with losses exceeding $30 million, of which CeFi accounted for 7 incidents, primarily due to the theft of administrator private keys and hot wallet private keys, exposing significant risks.