CertiK's annual Hack3d report is in, and the numbers are brutal: $3.35 billion stolen across more than 630 Web3 security incidents in 2025. That's not a typo. That's the reality devs and security teams have been screaming about, and it's getting worse before it gets better.

The Bybit Breach Looms Large

The single largest incident remains the $1.4 billion Bybit exchange hack, which alone accounted for nearly half of all losses tracked in 2025. When an attack of that magnitude hits a major centralized exchange, it shakes confidence across the entire ecosystem—and forces every builder to reconsider their threat model.

AI Scams Are the New Front

Perhaps more alarming than raw dollar figures is the 4.5x increase in AI-powered scams targeting Web3 users. These aren't your grandfather's phishing emails—AI-generated deepfakes, convincing social engineering attacks, and automated fraud pipelines are making it harder than ever for even experienced users to distinguish legitimate projects from elaborate scams.

The Defense Side: AI Helps SOCs Cut Response Time

Here's where it gets interesting for the builder crowd. According to CertiK's data, 72% of Security Operations Centers using AI tools reported a reduction in incident response time of 25% or more. That's meaningful. Automated threat detection, anomaly identification, and faster triage are giving security teams a fighting chance against increasingly sophisticated attackers.

What This Means for Devs Building in Web3

If you're shipping smart contracts, dApps, or infrastructure in this space, the message is clear: security can't be an afterthought. Formal verification, comprehensive audit trails, and integrated AI-powered monitoring aren't luxuries anymore—they're table stakes. The attackers are using every tool available; defenders need to match that sophistication.

Key Takeaways

  • $3.35 billion lost across 630+ Web3 incidents in 2025 according to CertiK's Hack3d report
  • Bybit breach at $1.4 billion remains the single largest incident, representing nearly half of all losses
  • AI-powered scams surged 4.5x year-over-year, raising the bar for social engineering attacks
  • AI-assisted SOCs show 25%+ improvement in response times—offense is ahead, but defense is catching up

The Bottom Line

The Web3 security landscape in 2025 is a high-stakes environment where billion-dollar breaches and AI-driven fraud are the new normal. Builders who treat security as a core engineering discipline—not a compliance checkbox—will be the ones who survive and earn user trust.