‹ BackNewsRPC Security

RPC Security

Web3 Security
2026-09-30 00:49:03

Web3 security is shifting from code exploits to trust and permission failures, Foresight says

A long-form analysis published by Foresight argues that the center of gravity in Web3 security has moved away from smart contract bugs and toward permissions, signing flows, RPC dependencies, supply chains, and operational trust. The piece points to four major incidents — Bybit, KelpDAO, Drift, and Bitget — to show that some of the largest recent losses did not come from undiscovered contract 0days. Instead, attackers targeted the systems and people around the code: compromised signing interfaces, poisoned backend approval flows, manipulated RPC responses, and social engineering aimed at privileged operators. The article says the pattern has become clearer over the past three years. In 2024, phishing overtook private key leaks as the biggest threat. In 2025, the Bybit theft pushed front-end supply chain risk and signing interfaces into focus. In 2026, the KelpDAO, Drift, and Bitget cases turned RPC trust, multisig design, and permission configuration into the main battleground. It also argues that AI is changing the economics of attacks by making phishing, fake identities, malware delivery, and old-contract scanning cheaper to run at scale, while forcing defenders to secure every entry point. Foresight’s conclusion is blunt: Web3 has not become safe or unsafe in a simple sense. The most valuable attack surface has moved outside the contract itself and into the broader trust chain that surrounds it.

200
Web3 security is shifting from code exploits to trust and permission failures, Foresight says