Is web3 security going great?
Nah.
Molly White’s Web3 is Going Just Great is great, but this post is about another newsletter’s content. Every week I receive the BlockThreat newsletter, whose first sentence summarizes the losses of the week. Take the last one:
Week 49: “Almost $11M were stolen this week across four incidents.”
Let’s look at some specific weeks to see the range:
Week 46: “A relatively quiet week with just three exploits resulting in $657K in losses.“
Week 45: “More than $132M were stolen this week across seven incidents.“
Week 21: “Over $260 million was stolen across five separate incidents this week, with the bulk of the losses stemming from a single ecosystem-wide compromise on the Sui blockchain.”
Week 14: “Just three exploits this week, totaling around $70M in losses—most of it from a single victim of private key theft, UPCX.”
And the bloodiest week was of course:
Week 8: “This was the worst week for the ecosystem in years. (…) A malicious upgrade of a cold storage contract, signed by a Safe multisig wallet, led to the theft of almost $1.5B worth of ETH and similar assets from Bybit.”
The total is estimated around $3B in 2025 so far, counting only the publicly reported/visible cases. The median weekly theft is $10-15M, and the average around $60M—skewed by Bybit. You’ll find a detailed analysis in this October post from DeepStrike.
The perpetrators are often well known: North Korea’s Lazarus constellation, Russian ransomware gangs, Iranian state actors.
Now here’s the uncomfortable part. I know victim-blaming isn’t great, but when you look at the targets, a pattern emerges:
Organizations with low security maturity, and often no security staff, and pervasive security amateurism.
A culture of “we passed the audits so we’re good,” treating security as a one-time checkbox rather than continuous practice.
Security models violating fundamental security principles such as segregation of duties, least privilege, need-to-know.
Critical software whose code, data, and executions are trivially visible to attackers.
A belief that cryptography alone can solve all security problems.
Poor key management practices and contingency plans, if they exist at all.
Lack of accountability, both in the internal governance processes and after incidents.
In the same way that web3 resuscitated all forms of financial frauds, it needs to rediscover how security works. And as dire as the situation looks, it’s worth observing what the victims are not, which types organizations aren’t targetted, and which type of wallets have never been compromised.
Featured image: No Country for Old Men.