TLDR: Real World Assets exploits reached $14.6M in H1 2025, CertiK data shows, with attackers shifting from DeFi to tokenized assets. Top protocols like Ondo, Paxos, and Tether scored AAA or AA ratings in CertiK’s 2025 RWA security review. Risks now extend beyond code to oracles, custody, counterparties, and fraudulent proof-of-reserve attestations. Ethereum leads in [...] The post Hackers Are Now Targeting Real World Assets: CertiK Flags $14.6M in 2025 Losses appeared first on Blockonomi.TLDR: Real World Assets exploits reached $14.6M in H1 2025, CertiK data shows, with attackers shifting from DeFi to tokenized assets. Top protocols like Ondo, Paxos, and Tether scored AAA or AA ratings in CertiK’s 2025 RWA security review. Risks now extend beyond code to oracles, custody, counterparties, and fraudulent proof-of-reserve attestations. Ethereum leads in [...] The post Hackers Are Now Targeting Real World Assets: CertiK Flags $14.6M in 2025 Losses appeared first on Blockonomi.

Hackers Are Now Targeting Real World Assets: CertiK Flags $14.6M in 2025 Losses

3 min read

TLDR:

  • Real World Assets exploits reached $14.6M in H1 2025, CertiK data shows, with attackers shifting from DeFi to tokenized assets.
  • Top protocols like Ondo, Paxos, and Tether scored AAA or AA ratings in CertiK’s 2025 RWA security review.
  • Risks now extend beyond code to oracles, custody, counterparties, and fraudulent proof-of-reserve attestations.
  • Ethereum leads in RWA tokenization, but concentration on a few chains leaves the sector exposed to systemic risk.

Hackers are no longer chasing only DeFi protocols. They are moving into tokenized real world asset projects. CertiK’s latest report tracks this change. 

Losses linked to RWA exploits hit $14.6 million in the first half of 2025. The research shows that threats have moved from off-chain defaults toward operational and on-chain weaknesses. For investors, the numbers show where attackers now see the biggest opportunities.

Real World Assets Security Risks Push Losses Higher

CertiK explained that RWA tokenization introduces hybrid threats. Unlike DeFi tokens, an RWA token represents a claim on something off-chain. This means the attack surface is wider. The risks include oracle manipulation, custodial failures, and fraudulent proof-of-reserve claims.

Losses have reflected this change. According to the report, RWA-related exploits cost $6 million in 2024. In 2023, losses were about $17.9 million. By mid-2025, $14.6 million had already been drained from projects in this space. CertiK pointed out that these attacks are evolving, with more focus now on direct on-chain weaknesses.

The report also stated that value concentration increases risk. Most RWA tokens sit on Ethereum and a handful of leading protocols. If a major chain or protocol faces a breach, the entire market could feel the impact.

Institutional Projects Rank Higher in Security

CertiK’s Skynet RWA Security Spotlight showed stronger security ratings for projects tied to traditional finance. 

Protocols linked with BlackRock and Franklin Templeton ranked higher due to strict compliance and custody systems. This suggests that institutional oversight improves security standards when bridging real world assets into crypto.

Ondo Finance ranked third with a security score above 93. It issues tokens backed by short-term U.S. Treasuries and bank deposits. Paxos followed closely with its regulated PAX Gold token, each backed by an ounce of vaulted gold. Tether Gold came in fifth, reflecting rising demand for inflation-hedging assets backed by physical reserves.

CertiK’s findings show that these projects adopted outside security audits to reinforce trust. The report listed Ondo, Paxos, and Tether among platforms that partnered with CertiK for added due diligence.

The growing focus on RWA projects makes them prime targets for hackers. The numbers prove attackers are adapting quickly, and only the most security-conscious protocols appear to be holding ground.

The post Hackers Are Now Targeting Real World Assets: CertiK Flags $14.6M in 2025 Losses appeared first on Blockonomi.

Market Opportunity
RealLink Logo
RealLink Price(REAL)
$0.05897
$0.05897$0.05897
-1.97%
USD
RealLink (REAL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Galaxy Digital’s 2025 Loss: SOL Bear Market

Galaxy Digital’s 2025 Loss: SOL Bear Market

The post Galaxy Digital’s 2025 Loss: SOL Bear Market appeared on BitcoinEthereumNews.com. Galaxy Digital, a digital assets and artificial intelligence infrastructure
Share
BitcoinEthereumNews2026/02/04 09:49
FCA, crackdown on crypto

FCA, crackdown on crypto

The post FCA, crackdown on crypto appeared on BitcoinEthereumNews.com. The regulation of cryptocurrencies in the United Kingdom enters a decisive phase. The Financial Conduct Authority (FCA) has initiated a consultation to set minimum standards on transparency, consumer protection, and digital custody, in order to strengthen market confidence and ensure safer operations for exchanges, wallets, and crypto service providers. The consultation was published on May 2, 2025, and opened a public discussion on operational responsibilities and safeguarding requirements for digital assets (CoinDesk). The goal is to make the rules clearer without hindering the sector’s evolution. According to the data collected by our regulatory monitoring team, in the first weeks following the publication, the feedback received from professionals and operators focused mainly on custody, incident reporting, and insurance requirements. Industry analysts note that many responses require technical clarifications on multi-sig, asset segregation, and recovery protocols, as well as proposals to scale obligations based on the size of the operator. FCA Consultation: What’s on the Table The consultation document clarifies how to apply rules inspired by traditional finance to the crypto perimeter, balancing innovation, market integrity, and user protection. In this context, the goal is to introduce minimum standards for all firms under the supervision of the FCA, an essential step for a more transparent and secure sector, with measurable benefits for users. The proposed pillars Obligations towards consumers: assessment on the extension of the Consumer Duty – a requirement that mandates companies to provide “good outcomes” – to crypto services, with outcomes for users that are traceable and verifiable. Operational resilience: introduction of continuity requirements, incident response plans, and periodic testing to ensure the operational stability of platforms even in adverse scenarios. Financial Crime Prevention: strengthening AML/CFT measures through more stringent transaction monitoring and structured counterpart checks. Custody and safeguarding: definition of operational methods for the segregation of client assets, secure…
Share
BitcoinEthereumNews2025/09/18 05:40
HKMA Launches Fintech Blueprint with AI, DLT, Quantum and Cybersecurity Focus

HKMA Launches Fintech Blueprint with AI, DLT, Quantum and Cybersecurity Focus

The Hong Kong Monetary Authority (HKMA) published a Fintech Promotion Blueprint to support responsible innovation and fintech development in the banking sector.
Share
Fintechnews2026/02/04 10:20