Web3 isn’t taking cybersecurity seriously enough

I have noticed a clear progression and build up to the dire situation we are currently facing with crypto cybersecurity

OPINION
article-image

Midjourney modified by Blockworks

share

Back in early 2022, hacks in crypto were certainly not rare, but their magnitude appeared dimmed by overall industry growth, adoption and the innovation of new, cutting-edge projects. 

But the effects of exploits are clearer today than ever before: Q3 was dubbed 2023’s most damaging yet, with over $700 million in losses through various hacks and scams.

Unfortunately, this hasn’t come as a complete surprise, as companies in the crypto space are largely responsible for their own cybersecurity failings.

Private capital investment in Web3 has slowed, with VCs exercising caution in light of the ongoing market headwinds. Companies have transitioned back to building and developing as a priority, with a spotlight on robust and secure infrastructure in a bid to entice financial backing.  

The state of cybersecurity in the crypto and blockchain space over the past five to ten years is far from reassuring. While the concept of blockchain itself is founded on principles of decentralization and cryptographic security, the broader ecosystem surrounding it remains riddled with vulnerabilities. 

Despite the push for increased protections in 2022, cybersecurity is still Web3’s biggest pain point.

The market adapts

In 2022, companies had too few security engineers to audit their infrastructure. Even as they hired entire teams of engineers to prevent future hacks, the market then crumbled and priorities shifted.

Many of the security engineers who were hired to respond to the initial problems were no longer qualified or experienced enough to respond to issues arising from new technologies and new systems. These companies now find themselves with more sensitive information, bigger vulnerabilities in their base code and fewer capable individuals to handle them. We can see this 

through the emergence of new attack vectors, such as DeFi exploits and supply chain attacks.

Many audit companies have seen significant layoffs as the expertise of many of their teams is no longer adequate. Blanket security services simply do not cover the breadth necessary to properly identify all vulnerabilities. In addition, the market is small and available contracts are shrinking. 

And while cyberattacks have been on a continuous rise since 2022, the “retail” audit market has shrunk significantly from what it was in previous years. As companies are forced to tighten their budgets, they seem to be willing to sacrifice structural integrity for growth. 

In response, we’ve seen the rise of community-driven solutions such as Code4rena and Sherlock, companies that outsource auditing project chunks to outside coders and security engineers. While this is certainly an interesting and resourceful response at a time of need, it is not, however, a long-term solution, as it comes with no small amount of uncertainty and lacks guaranteed quality. 

The real differentiator now is who is capable of creating their own, new cybersecurity tools. This is a trend born from Web2, where everyone attempts to establish a cybersecurity ecosystem by scaling their services and product lines. As Web3 matures and evolves, more solutions are required in the same way.

Building habits to safeguard trust

The current state of cybersecurity in the blockchain and cryptocurrency space is a double-edged sword, marked by both progress and persistent challenges. 

On one hand, blockchain technology offers inherent security benefits through its decentralized and immutable ledger, making it difficult for malicious actors to tamper with transaction data. Additionally, cryptographic techniques at the core of cryptocurrencies provide robust protection against counterfeiting. 

However, these advancements in themselves have not guaranteed a secure ecosystem. Vulnerabilities in the surrounding infrastructure — such as wallets, exchanges, smart contracts and the human factor — will continue to expose users to substantial risks.

Companies and CEOs are being too short-sighted, ignoring the necessary follow-through to safeguard the entirety of their systems and confidently ensure their own — or worse — their customers’ assets. 

There seems to be a fundamental lack of awareness that security in the blockchain space requires a 360-degree approach and consistent follow-up to ensure the growth of a company or product. It’s a mistake for companies to seek out security reviews to address only the one specific vulnerability that led to a hack.

Following notable hacks of the last few years, over half of the companies had not had a security audit. Of those who did seek out an audit, hardly any thought to pursue a follow-up after they made alterations to the code. 

The goal now is to develop good cybersecurity habits to give the industry a chance to bounce back, build on the technology it has introduced and give itself a chance to deliver up to its potential. Groups like the Open Web Application Security Project are important for the industry to maintain those good habits with initiatives like outlining cybersecurity standards — something that simply didn’t exist before. 

As is the case with any industry, a proven expertise in the subject matter has no substitute. New technologies, such as zk proofs and liquid staking, are primed to integrate with systems throughout the industry — meaning auditing will once again require capable experts who can anticipate these security needs.

Foresight and effective planning in this rapidly evolving industry are also still paramount: No one security review guarantees peace of mind. The industry and the tools that comprise it are constantly evolving, and understanding how to foresee this and plan for regular auditing can go a very long way in mitigating risk. That is what cybersecurity should be all about — mitigating risk as much and as often as possible.



Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

recent research

Unlocked Advisory-min.png

Research

This report distills Blockworks Advisory’s research on incentive programs and their analysis, offering a foundation for designing future initiatives and advancing industry-wide standards. By highlighting key lessons and methodologies, we aim to empower protocols to make informed, data-driven decisions.

article-image

The company did about 2.5 times the amount of crypto-backed collateral financing in November compared to the rest of 2024, exec says

article-image

Programmable yield, seamless swaps and decentralized control are the hallmarks of a new stablecoin model

article-image

Crypto is “really exciting,” former SEC Commissioner Paul Atkins said in a podcast interview last year

article-image

Bitcoin is now the “seventh most valuable asset in the world by market cap, just behind the likes of Google and Amazon,” GSR’s Brian Rudick said

article-image

Many analysts expected bitcoin to top $100K before year-end, though it’s been on a post-election tear

article-image

Will investors take a 10% lower return to get access to a regulated investment wrapper?