Key Takeaways: Web3 platforms lost $3.1 billion in H1 2025, already surpassing full-year 2024 losses. Access control failures were the leading cause, followed by phishing and smart contract bugs. AI-related attack vectors rose by 1,025%, showing risks in inference layers and APIs. Web3 projects lost $3.1 billion to exploits and scams in the first half of 2025, according to the Hacken 2025 Half-Year Web3 Security Report published July 24 . 🚨 2025 is already the most expensive year in Web3 security, and we’re only halfway through. $3.1B lost. Social engineering. AI-driven exploits. Protocol design flaws. Our Half-Year Report breaks it all down and shows how to defend against what’s next: https://t.co/6x8JDjkmJT pic.twitter.com/hQjxTvpjlN — Hacken🇺🇦 (@hackenclub) July 24, 2025 The report states that the amount lost in H1 this year has already exceeded the total losses recorded across all of 2024. It attributes $1.83 billion of this amount to access control exploits, the majority of which occurred in Q1. AI-Related Exploits Explode by 10x in Web3 Phishing and social engineering attacks accounted for $600 million, a sharp increase from the previous year. Another $263 million was lost due to smart contract vulnerabilities, marking DeFi’s most damaging quarter since early 2023. Hacken identified a surge in AI-related exploits, with incident volume rising by 1,025% compared to H2 2024. These cases stemmed from issues such as insecure API design, improper model access restrictions, and weak user input filtering in AI inference layers. The single largest incident in the period was the $290 million Munchables breach, followed by $136 million lost in the Pike Finance series of attacks. The Uniswap V4 ecosystem also recorded its first major hook-related exploit, resulting in a $12 million loss. According to the report, Ethereum accounted for 61.4% of total losses, while BNB Chain and Arbitrum represented 20.2% and 11.4%, respectively. Exploits on Ethereum L2s and alt-L1s made up the remainder. Security Enhancements in Exigent Need “2025 has been a wake-up call,” said Hacken Co-Founder and CBDO Yevheniia Broshevan. “As blockchain reaches enterprise scale and regulations advance, cybersecurity becomes a core business function.” The report recommends continuous monitoring and automated defense systems to address rising threats. It also warns that standard auditing remains insufficient given the increased complexity of integrated systems and AI models in Web3 environments. DeFi protocols made up nearly 69% of all incidents tracked in H1 2025. CeFi incidents were fewer but tended to result in higher individual losses. The report also noted a growing overlap between financial and infrastructure attack vectors. The rise in AI-driven exploits exposes the challenge facing the crypto industry: the rapid adoption of complex technologies outpacing the development of security frameworks. At the same time, geopolitical actors and financially motivated groups have begun to treat blockchain infrastructure as high-value targets. The convergence of traditional cybersecurity threats with on-chain vulnerabilities may require new regulatory coordination between Web3-native firms, national agencies, and cybersecurity vendors. Frequently Asked Questions (FAQs) How might regulations like MiCA or the EU AI Act influence future Web3 security practices? These frameworks may impose formal governance, model validation requirements, and real-time monitoring standards that force protocols to integrate cybersecurity by design rather than after deployment. Are smaller protocols more vulnerable to these complex attacks? Yes. The report implies that limited technical resources and overreliance on third-party tooling leave smaller teams exposed, especially as AI integrations expand without clear defensive standards. Is there any indication of coordination between threat actors? While not explicitly detailed, the increase in sophisticated, cross-layer attacks suggests potential collaboration or tooling exchanges between financially motivated hackers and more organized adversarial groups.Key Takeaways: Web3 platforms lost $3.1 billion in H1 2025, already surpassing full-year 2024 losses. Access control failures were the leading cause, followed by phishing and smart contract bugs. AI-related attack vectors rose by 1,025%, showing risks in inference layers and APIs. Web3 projects lost $3.1 billion to exploits and scams in the first half of 2025, according to the Hacken 2025 Half-Year Web3 Security Report published July 24 . 🚨 2025 is already the most expensive year in Web3 security, and we’re only halfway through. $3.1B lost. Social engineering. AI-driven exploits. Protocol design flaws. Our Half-Year Report breaks it all down and shows how to defend against what’s next: https://t.co/6x8JDjkmJT pic.twitter.com/hQjxTvpjlN — Hacken🇺🇦 (@hackenclub) July 24, 2025 The report states that the amount lost in H1 this year has already exceeded the total losses recorded across all of 2024. It attributes $1.83 billion of this amount to access control exploits, the majority of which occurred in Q1. AI-Related Exploits Explode by 10x in Web3 Phishing and social engineering attacks accounted for $600 million, a sharp increase from the previous year. Another $263 million was lost due to smart contract vulnerabilities, marking DeFi’s most damaging quarter since early 2023. Hacken identified a surge in AI-related exploits, with incident volume rising by 1,025% compared to H2 2024. These cases stemmed from issues such as insecure API design, improper model access restrictions, and weak user input filtering in AI inference layers. The single largest incident in the period was the $290 million Munchables breach, followed by $136 million lost in the Pike Finance series of attacks. The Uniswap V4 ecosystem also recorded its first major hook-related exploit, resulting in a $12 million loss. According to the report, Ethereum accounted for 61.4% of total losses, while BNB Chain and Arbitrum represented 20.2% and 11.4%, respectively. Exploits on Ethereum L2s and alt-L1s made up the remainder. Security Enhancements in Exigent Need “2025 has been a wake-up call,” said Hacken Co-Founder and CBDO Yevheniia Broshevan. “As blockchain reaches enterprise scale and regulations advance, cybersecurity becomes a core business function.” The report recommends continuous monitoring and automated defense systems to address rising threats. It also warns that standard auditing remains insufficient given the increased complexity of integrated systems and AI models in Web3 environments. DeFi protocols made up nearly 69% of all incidents tracked in H1 2025. CeFi incidents were fewer but tended to result in higher individual losses. The report also noted a growing overlap between financial and infrastructure attack vectors. The rise in AI-driven exploits exposes the challenge facing the crypto industry: the rapid adoption of complex technologies outpacing the development of security frameworks. At the same time, geopolitical actors and financially motivated groups have begun to treat blockchain infrastructure as high-value targets. The convergence of traditional cybersecurity threats with on-chain vulnerabilities may require new regulatory coordination between Web3-native firms, national agencies, and cybersecurity vendors. Frequently Asked Questions (FAQs) How might regulations like MiCA or the EU AI Act influence future Web3 security practices? These frameworks may impose formal governance, model validation requirements, and real-time monitoring standards that force protocols to integrate cybersecurity by design rather than after deployment. Are smaller protocols more vulnerable to these complex attacks? Yes. The report implies that limited technical resources and overreliance on third-party tooling leave smaller teams exposed, especially as AI integrations expand without clear defensive standards. Is there any indication of coordination between threat actors? While not explicitly detailed, the increase in sophisticated, cross-layer attacks suggests potential collaboration or tooling exchanges between financially motivated hackers and more organized adversarial groups.

Hacken Report Flags $3.1B Web3 Meltdown, 1,025% Spike in AI Attacks

3 min read

Key Takeaways:

  • Web3 platforms lost $3.1 billion in H1 2025, already surpassing full-year 2024 losses.
  • Access control failures were the leading cause, followed by phishing and smart contract bugs.
  • AI-related attack vectors rose by 1,025%, showing risks in inference layers and APIs.

Web3 projects lost $3.1 billion to exploits and scams in the first half of 2025, according to the Hacken 2025 Half-Year Web3 Security Report published July 24.

The report states that the amount lost in H1 this year has already exceeded the total losses recorded across all of 2024. It attributes $1.83 billion of this amount to access control exploits, the majority of which occurred in Q1.

Phishing and social engineering attacks accounted for $600 million, a sharp increase from the previous year. Another $263 million was lost due to smart contract vulnerabilities, marking DeFi’s most damaging quarter since early 2023.

Hacken identified a surge in AI-related exploits, with incident volume rising by 1,025% compared to H2 2024. These cases stemmed from issues such as insecure API design, improper model access restrictions, and weak user input filtering in AI inference layers.

The single largest incident in the period was the $290 million Munchables breach, followed by $136 million lost in the Pike Finance series of attacks. The Uniswap V4 ecosystem also recorded its first major hook-related exploit, resulting in a $12 million loss.

According to the report, Ethereum accounted for 61.4% of total losses, while BNB Chain and Arbitrum represented 20.2% and 11.4%, respectively. Exploits on Ethereum L2s and alt-L1s made up the remainder.

Security Enhancements in Exigent Need

“2025 has been a wake-up call,” said Hacken Co-Founder and CBDO Yevheniia Broshevan. “As blockchain reaches enterprise scale and regulations advance, cybersecurity becomes a core business function.”

The report recommends continuous monitoring and automated defense systems to address rising threats. It also warns that standard auditing remains insufficient given the increased complexity of integrated systems and AI models in Web3 environments.

DeFi protocols made up nearly 69% of all incidents tracked in H1 2025. CeFi incidents were fewer but tended to result in higher individual losses. The report also noted a growing overlap between financial and infrastructure attack vectors.

The rise in AI-driven exploits exposes the challenge facing the crypto industry: the rapid adoption of complex technologies outpacing the development of security frameworks.

At the same time, geopolitical actors and financially motivated groups have begun to treat blockchain infrastructure as high-value targets. The convergence of traditional cybersecurity threats with on-chain vulnerabilities may require new regulatory coordination between Web3-native firms, national agencies, and cybersecurity vendors.

Frequently Asked Questions (FAQs)

How might regulations like MiCA or the EU AI Act influence future Web3 security practices?

These frameworks may impose formal governance, model validation requirements, and real-time monitoring standards that force protocols to integrate cybersecurity by design rather than after deployment.

Are smaller protocols more vulnerable to these complex attacks?

Yes. The report implies that limited technical resources and overreliance on third-party tooling leave smaller teams exposed, especially as AI integrations expand without clear defensive standards.

Is there any indication of coordination between threat actors?

While not explicitly detailed, the increase in sophisticated, cross-layer attacks suggests potential collaboration or tooling exchanges between financially motivated hackers and more organized adversarial groups.

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.007739
$0.007739$0.007739
+0.38%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why Analysts Say XYZverse Could Overtake AVAX in Adoption This Cycle

Why Analysts Say XYZverse Could Overtake AVAX in Adoption This Cycle

Discover why top crypto analysts believe XYZverse is poised to surpass AVAX in user adoption this market cycle. Explore key factors driving its growth, technological advantages, and investor sentiment.
Share
Cryptodaily2025/09/22 17:57
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48
Rainbow proposes to acquire Clanker Protocol and announces token distribution plan

Rainbow proposes to acquire Clanker Protocol and announces token distribution plan

PANews reported on September 23rd that the Rainbow Foundation proposed acquiring the Clanker protocol and announced a token distribution plan: SCLANKER holders will receive 4% of the total supply of Rainbow's new token, SRNBW (approximately 20% of the circulating supply of TGE); all Clanker treasury assets will be airdropped to SCLANKER holders; and LP fees generated by the Clanker protocol will be permanently distributed to SCLANKER holders. Rainbow has pledged to integrate Clanker into its product ecosystem and provide SRNBW rewards for related transactions. Clanker responded that he had informed Rainbow last week that he would not accept the acquisition and that there was a disagreement in the communication between the two sides.
Share
PANews2025/09/23 08:45