GoPlus 年度安全报告:1200 起严重安全事件造成超 35 亿美元总损失,攻击者策略呈现“精准猎杀”、“广撒网”并行的趋势

ChainCatcher 消息,据 GoPlus RektDatabase 数据显示,2025 年 Web3 领域用户和项目方发生超 1200 起较严重的安全事件,造成总损失超过 35 亿美元。
私钥窃取(基于病毒木马和社工)、钓鱼攻击、Rug Token(欺诈 Token)是最高发的三种攻击与欺诈类型。其中,Bybit 被盗事件(2 月 21 日,15 亿美元)、Cetus 被盗事件(5 月 22 日,2.23 亿美元)、Balancer 被盗事件(11 月 2 日,1.28 亿美元)为 2025 年受损金额 Top3 事件。
安全态势上呈现出“超大额事件数量增加”、“用户小额欺诈成本显著降低”的明显特征,这标志着攻击者策略呈现“精准猎杀”、“广撒网”并行的趋势。值得注意的是,2025 年单体损失金额超 3000 万美元的攻击事件共 12 起,其中 CeFi 占了 7 起,管理员私钥被盗、热钱包私钥被盗是最主要的原因,暴露了显著的风险。
Disclaimer: OKX Orbit content is provided for informational purposes only. Learn more
Replies
Related Flash News
Iranian media denied claims that Iran and the U.S. had reached a memorandum of understanding
Hyperliquid's accounts "Evaded" and "Garret Jin" are counterparts, with a cumulative floating loss of $2.2 million
Bitcoin's volatility is near its lowest point since 2023, and the crypto market is entering a 'calm breather'
The outlook for US rate hikes supports the US dollar, while expectations for eurozone rate hikes have decreased
Alipay launched the world's first Token Pay service and AI wallet product, unveiling its full-stack AI payment product matrix
The stablecoin market value has surpassed $322 billion, with foreign exchange reserves exceeding 95 countries
TRX broke through $0.375, setting a new high for the year
ZEC pulled back 8.5% intraday, and a major whale in Hyperliquid was forced down for $1.48 million after 'buying long on dips.'
Google's fake crypto ads persist despite repeated crackdowns, and phishing sites imitating Uniswap have stolen another $400,000
On Hyperliquid, HYPE spot TWAP orders shifted to selling pressure, with net selling pressure reaching $1.7 million in the next 24 hours



