CertiK Annual Report: The 2025 Web3 Security Attacks Show a Trend of Specialization, with the ETH Ecosystem Being the Hardest Hit
According to CertiK's latest "2025 Web3 Security Report", despite some recovery in the industry against the backdrop of improved macro policies, the overall security situation remains extremely severe, with over 700 security incidents occurring throughout the year, resulting in total losses of up to $3.35 billion.
The report data indicates that the behavior of attackers is showing a new trend that is more focused and efficient. They are no longer attacking in a dispersed manner, but instead concentrating resources on core security aspects such as private key management and access control to implement precise "surgical" attacks.
This strategy has directly led to an increase in the average loss per attack in 2025, soaring to $5.32 million, a year-on-year increase of 66.64%. A typical standout example is that in just February, among the 58 security incidents that occurred, the loss amount reached $1.537 billion, directly making that month the hardest-hit month of the year in terms of losses.
In terms of attack methods, the most severe losses were incurred from supply chain attacks (attacks leveraging trust relationships within the supply chain), with just two incidents causing a total loss of $1.45 billion, reflecting the vulnerabilities of upstream trusted protocols at the infrastructure level.
In addition, social engineering attacks represented by phishing attacks (248 incidents throughout the year) continuously harassed ordinary users with a very high frequency, becoming the mainstream threat in terms of the number of attack incidents, highlighting the omnipresence of security risks.
Focusing on the blockchain ecosystem that suffered attacks, Ethereum is undoubtedly the hardest-hit area for security incidents. With its large developer community, the highest amount of locked funds, and the most complex application ecosystem, Ethereum has also become the public chain most frequently targeted by malicious attacks.
Throughout the year, the Ethereum ecosystem experienced 310 security incidents, resulting in economic losses of up to $1.698 billion. In terms of both the number of security incidents and the scale of financial losses, it significantly leads other public chains, ranking first in the industry.
In summary, the 2025 Web3 security landscape presents a significant characteristic of specialized attack methods. This indicates that future security defenses must shift from "comprehensive deployment" to "focused breakthroughs", enhancing the baseline defense capabilities of the entire industry while also building a deep defense system for core assets and high-value targets.
#CertiK #Web3安全报告