At the DC Blockchain Summit, Web3 security leader CertiK issued a stark warning about the evolving threat landscape. Citing its “2025 Skynet Hack3D Report”, CBO Jason Jiang identified smart contract vulnerabilities as a persistent attack surface, with cross-chain bridges remaining prime targets due to their concentrated liquidity.
Cross-Chain Bridges: A High-Risk Concentration Zone
CertiK stressed that cross-chain bridge liquidity pools often hold enormous value, making them attractive targets for sophisticated hackers. Attackers exploit logic flaws or unverified signatures to drain funds. “Bridges are critical connectors between ecosystems, but they are often the weakest link,” Jiang noted.
Supply Chain Attacks: Staggering Single-Incident Losses
The report revealed that just two supply chain attacks in 2025 caused over $1.45 billion in damages. These attacks infiltrate development tools, third-party libraries, or code dependencies to implant backdoors or alter code, leading to massive asset theft. Unlike direct protocol exploits, supply chain attacks are more covert and devastating.
Phishing: Most Frequent but Often Overlooked
While supply chain and bridge attacks cause the largest losses, phishing remains the most frequent attack vector in 2025. Attackers use social media, fake airdrops, and malicious links to trick users into approving transactions or revealing keys. CertiK called for better user education and wider adoption of hardware wallets and multi-factor authentication.
Regulatory Frameworks and Cross-Industry Collaboration
In discussions with U.S. lawmakers, CertiK addressed market structure evolution, traditional bank adaptation to crypto, and consumer protection. Jiang emphasized the need for regulatory frameworks that support responsible vulnerability disclosure and close collaboration between technology providers and law enforcement. He suggested integrating mandatory security audits and active bug bounty programs into compliance standards.
CertiK’s warnings serve as a critical reminder: as the crypto ecosystem grows more complex, attack methods evolve. Both projects and users must prioritize security and work together to build a more resilient Web3 world.

