The $1.5 Billion Wake-Up Call: How Supply Chain Attacks Became Web3's Deadliest Threat in 2025
When security researchers released the final tally for 2025, the number that stopped everyone cold wasn't the record-breaking $3.35 billion in total Web3 losses — it was how that money was stolen. For the first time, software supply chain attacks claimed the top spot as the single most destructive attack vector, accounting for $1.45 billion in losses across just two incidents. Smart contracts, flash loans, oracle manipulation — the classic Web3 exploits — didn't come close. The battlefield has shifted, and most of the industry is still fighting the last war.