Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Crypto Hackers are Shifting Focus to RWA Projects, CertiK Report Shows

Crypto Hackers are Shifting Focus to RWA Projects, CertiK Report Shows

BeInCryptoBeInCrypto2025/08/21 08:30
By:Landon Manning

Certik’s 2025 report exposes a sharp rise in RWA hacks, with a shift to on-chain vulnerabilities and suggests security measures to counter the increasing threat.

A new report from CertiK assessed the RWA (real-world assets) market in 2025 and found a growing wave of hacks. Criminals have started shifting their approach during the first half of the year, hammering on the technology’s weaknesses.

Also, the report highlights how the majority of tokenized assets sit on Ethereum and a few dominant protocols. This concentration means a single major exploit could ripple through the entire $13.9 billion+ RWA sector.

RWA Hacks on the Rise

Blockchain security researchers at CertiK published their Skynet RWA Security Report today. It shows how threats against RWA projects have evolved since 2023, and the attack surface now extends across both on and off-chain assets.

Crypto Hackers are Shifting Focus to RWA Projects, CertiK Report Shows image 0RWA Hacks By Year. Source: Certik

From January to July, the RWA sector lost $14.6 million to hacks and frauds, which is almost as much as the entirety of 2023. So far, there are no signs of stopping, especially since RWAs received a lot of market attention this year.

Unique Hybrid Vulnerabilities

Nonetheless, CertiK doesn’t ascribe economic forces as the reason for this shift. In previous years, RWA crime focused on off-chain threats, with credit and loan defaults representing a substantial chunk of all incidents.

Today, however, the RWA market is undoubtedly becoming more susceptible to hacks:

“The data highlights a clear transformation in the RWA threat landscape. The first half of 2025 shows a complete shift: losses jumped to nearly $14.6 million, and were caused entirely by on-chain and operational failures. The threat has evolved from exploiting external financial arrangements to attacking the core technology…itself,” CertiK claimed.

And yet, RWA’s unique integration with TradFi makes it vulnerable to hacks on both ends. Oracles are the key link between the on-chain and off-chain worlds, which means a single breach here can cause smart contracts to behave irrationally. It may totally untether the RWA from the underlying assets, allowing for profitable exploits.

In other words, a firm may offer RWAs solely based on “rock solid” assets like gold or US Treasury bonds, but a well-placed hack could cause the entire security structure to collapse.

Plenty of firms base RWAs on other sturdy assets like real estate, but the illiquid nature of this market also enables oracle manipulation. Most RWAs on the US market currently consist of assets like these, not private credit, but that doesn’t necessarily offer real protection.

Crypto Hackers are Shifting Focus to RWA Projects, CertiK Report Shows image 1RWA Underlying Assets. Source: Certik

Security Measures and TradFi’s Role

CertiK describes a few layers of security, some of which may be a little counterintuitive. To be clear, it prioritizes the classic hallmarks of crypto protection, but it also includes other steps.

For example, CertiK firmly stressed the importance of legally sound contracts as “a poorly drafted agreement might…render the entire structure unenforceable.” This would be catastrophic in the event of a major breach.

For this reason, the firm claimed that TradFi institutional participation is a vital component of RWA security. Firms like BlackRock already have well-established principles for most of CertiK’s recommendations, from legal language, solid asset storage, administrative guardrails, and more.

Unfortunately, this makes JPMorgan’s recent report that TradFi institutions are losing interest in RWAs all the more concerning. If crypto-native firms will soon represent the bulk of the RWA market, they’ll need diligent preparations to avoid this growing hack wave.

For now, this report details many measures that can be taken, and it assesses all the largest players in today’s RWA market on their security principles. As long as these companies keep proactively improving their security posture, they can outpace these attacks.

1

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Cold Wallet, XRP, Ethena & Chainlink: Unlocking Undervalued Assets in a Post-Presale Era

- 2025 post-presale crypto era prioritizes security, regulation, and DeFi infrastructure, with Cold Wallet, XRP, Ethena, and Chainlink leading innovation. - SEC's XRP ruling (commodity classification, $125M penalty) and ProShares ETF drove $1.2B inflows, projecting $12.60 price by year-end. - Ethena expanded cross-chain TVL to $10B via LayerZero, while Chainlink's TVS doubled to $84-95B, securing DeFi through oracle networks. - Cold Wallet's $0.3517 fixed price, 2M users post-Plus Wallet acquisition, and C

ainvest2025/08/28 14:54
Cold Wallet, XRP, Ethena & Chainlink: Unlocking Undervalued Assets in a Post-Presale Era

Top 4 Bullish Cryptocurrencies in 2025: ETH, XRP, HYPE, and BlockDAG

- 2025 crypto market prioritizes projects with strong tech, utility, and institutional backing, led by ETH, XRP, HYPE, and BlockDAG. - Ethereum's Pectra upgrade boosted scalability, attracting $145B in RWA tokenization and 5% ETF absorption via improved Layer-2 solutions. - XRP gained $1.2B ETF inflows post-regulatory clarity, while Hyperliquid's $43–$44 price range reflects demand for fast, low-cost DeFi trading. - BlockDAG's 15,000 TPS hybrid PoW-DAG architecture and $383M presale position it as a scalab

ainvest2025/08/28 14:39
Top 4 Bullish Cryptocurrencies in 2025: ETH, XRP, HYPE, and BlockDAG

Shiba Inu's $0.000020 Breakout: Speculative Hype or Strategic Inflection Point?

- Shiba Inu (SHIB) hovers near $0.000020 amid debates over whether its price surge reflects speculative hype or genuine ecosystem-driven value. - Shibarium's 1.5B+ transactions and 30% gas fee cuts correlate with SHIB's resilience, suggesting utility-driven demand despite 39% volume declines. - Deflationary burns reduced supply by 41% in 2025, but macroeconomic factors and whale activity remain key volatility drivers for the token. - Ecosystem expansion into AI, gaming, and metaverse projects aims to trans

ainvest2025/08/28 14:39
Shiba Inu's $0.000020 Breakout: Speculative Hype or Strategic Inflection Point?

The New Gold Rush: Capital Efficiency and Presale Dynamics in Q4 2025 DeFi

- Q4 2025 DeFi balances institutional stability with speculative presales, driven by capital efficiency metrics reshaping asset allocation. - Core-satellite strategies allocate 60-70% to ETH/AAVE (36.4%-72% gains) and 20-30% to high-yield presales like Remittix ($HYPER) offering 205% APY. - Bitcoin DeFi TVL hits $5-6B BTC via layer-2 solutions, while omnichain platforms and AI tools redefine liquidity and institutional adoption. - High-risk presales (e.g., MAGACOIN FINANCE's $12.8M raise) highlight innovat

ainvest2025/08/28 14:39
The New Gold Rush: Capital Efficiency and Presale Dynamics in Q4 2025 DeFi