• bitcoinBitcoin (BTC) $ 91,117.00
  • ethereumEthereum (ETH) $ 3,024.08
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.19
  • bnbBNB (BNB) $ 886.27
  • solanaSolana (SOL) $ 137.28
  • usd-coinUSDC (USDC) $ 0.999773
  • tronTRON (TRX) $ 0.282209
  • staked-etherLido Staked Ether (STETH) $ 3,024.21
  • dogecoinDogecoin (DOGE) $ 0.149169
  • cardanoCardano (ADA) $ 0.423150
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • whitebitWhiteBIT Coin (WBT) $ 58.65
  • wrapped-stethWrapped stETH (WSTETH) $ 3,692.06
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,964.00
  • bitcoin-cashBitcoin Cash (BCH) $ 551.09
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,279.40
  • usdsUSDS (USDS) $ 0.999952
  • chainlinkChainlink (LINK) $ 13.26
  • leo-tokenLEO Token (LEO) $ 9.83
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999859
  • hyperliquidHyperliquid (HYPE) $ 32.97
  • stellarStellar (XLM) $ 0.251002
  • moneroMonero (XMR) $ 435.82
  • wethWETH (WETH) $ 3,025.92
  • wrapped-eethWrapped eETH (WEETH) $ 3,274.32
  • zcashZcash (ZEC) $ 438.11
  • ethena-usdeEthena USDe (USDE) $ 0.999220
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,166.00
  • litecoinLitecoin (LTC) $ 83.82
  • hedera-hashgraphHedera (HBAR) $ 0.143490
  • avalanche-2Avalanche (AVAX) $ 13.86
  • suiSui (SUI) $ 1.54
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • daiDai (DAI) $ 0.999397
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.159152
  • crypto-com-chainCronos (CRO) $ 0.108085
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.61
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • uniswapUniswap (UNI) $ 6.15
  • paypal-usdPayPal USD (PYUSD) $ 0.998994
  • usdt0USDT0 (USDT0) $ 0.999825
  • polkadotPolkadot (DOT) $ 2.26
  • mantleMantle (MNT) $ 1.09
  • canton-networkCanton (CC) $ 0.085310
  • bittensorBittensor (TAO) $ 297.68
  • aaveAave (AAVE) $ 180.33
  • usd1-wlfiUSD1 (USD1) $ 0.999115
  • bitget-tokenBitget Token (BGB) $ 3.61
  • memecoreMemeCore (M) $ 1.42
  • nearNEAR Protocol (NEAR) $ 1.85
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • okbOKB (OKB) $ 106.23
  • tether-goldTether Gold (XAUT) $ 4,217.79
  • falcon-financeFalcon USD (USDF) $ 0.998702
  • aster-2Aster (ASTER) $ 1.08
  • internet-computerInternet Computer (ICP) $ 3.98
  • ethereum-classicEthereum Classic (ETC) $ 13.90
  • pi-networkPi Network (PI) $ 0.243354
  • ethenaEthena (ENA) $ 0.265042
  • pepePepe (PEPE) $ 0.000005
  • jito-staked-solJito Staked SOL (JITOSOL) $ 171.23
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,026.43
  • pump-funPump.fun (PUMP) $ 0.003065
  • rainRain (RAIN) $ 0.007612
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.70
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.513983
  • kaspaKaspa (KAS) $ 0.059847
  • quant-networkQuant (QNT) $ 104.42
  • worldcoin-wldWorldcoin (WLD) $ 0.636871
  • aptosAptos (APT) $ 2.01
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.134574
  • pax-goldPAX Gold (PAXG) $ 4,249.55
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • usdtbUSDtb (USDTB) $ 1.00
  • bfusdBFUSD (BFUSD) $ 0.999016
  • kucoin-sharesKuCoin (KCS) $ 10.02
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999765
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,474.51
  • skySky (SKY) $ 0.056084
  • ripple-usdRipple USD (RLUSD) $ 0.999901
  • gatechain-tokenGate (GT) $ 10.51
  • wbnbWrapped BNB (WBNB) $ 886.48
  • global-dollarGlobal Dollar (USDG) $ 0.999661
  • algorandAlgorand (ALGO) $ 0.139341
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • official-trumpOfficial Trump (TRUMP) $ 6.05
  • arbitrumArbitrum (ARB) $ 0.214398
  • hash-2Provenance Blockchain (HASH) $ 0.023205
  • flare-networksFlare (FLR) $ 0.014963
  • binance-staked-solBinance Staked SOL (BNSOL) $ 149.04
  • cosmosCosmos Hub (ATOM) $ 2.42
  • filecoinFilecoin (FIL) $ 1.60
  • vechainVeChain (VET) $ 0.013337
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,205.00
  • ignition-fbtcFunction FBTC (FBTC) $ 91,195.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 91,051.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,236.74
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 90,961.00
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • xdce-crowd-saleXDC Network (XDC) $ 0.053160
  • nexoNEXO (NEXO) $ 0.948825
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.32
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.91
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996687
  • render-tokenRender (RENDER) $ 1.76
  • sei-networkSei (SEI) $ 0.139960
  • story-2Story (IP) $ 2.54
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.40
  • bonkBonk (BONK) $ 0.000010
  • jupiter-exchange-solanaJupiter (JUP) $ 0.250064
  • morphoMorpho (MORPHO) $ 1.48
  • ousgOUSG (OUSG) $ 113.47
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,268.34
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,219.65
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,984.00
  • clbtcclBTC (CLBTC) $ 90,635.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011021
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.263335
  • dashDash (DASH) $ 54.71
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • spx6900SPX6900 (SPX) $ 0.706648
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 158.59
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999728
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999855
  • usdaiUSDai (USDAI) $ 1.00
  • optimismOptimism (OP) $ 0.324408
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.929388
  • aerodrome-financeAerodrome Finance (AERO) $ 0.679697
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,137.76
  • beldexBeldex (BDX) $ 0.081782
  • curve-dao-tokenCurve DAO (CRV) $ 0.421577
  • injective-protocolInjective (INJ) $ 5.85
  • lido-daoLido DAO (LDO) $ 0.655622
  • starknetStarknet (STRK) $ 0.126377
  • myx-financeMYX Finance (MYX) $ 3.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,026.64
  • blockstackStacks (STX) $ 0.312720
  • tbtctBTC (TBTC) $ 91,105.00
  • msolMarinade Staked SOL (MSOL) $ 184.28
  • usual-usdUsual USD (USD0) $ 0.998136
  • celestiaCelestia (TIA) $ 0.643351
  • newton-projectAB (AB) $ 0.006025
  • the-graphThe Graph (GRT) $ 0.050161
  • telcoinTelcoin (TEL) $ 0.005607
  • tezosTezos (XTZ) $ 0.489714
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,025.92
  • ether-fiEther.fi (ETHFI) $ 0.817112
  • usddUSDD (USDD) $ 0.999959
  • true-usdTrueUSD (TUSD) $ 0.995884
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • ultimaUltima (ULTIMA) $ 4,773.32
  • flokiFLOKI (FLOKI) $ 0.000048
  • gtethGTETH (GTETH) $ 3,023.86
  • kaiaKaia (KAIA) $ 0.079389
  • iotaIOTA (IOTA) $ 0.110597
  • stader-ethxStader ETHx (ETHX) $ 3,252.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • pendlePendle (PENDLE) $ 2.68
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,216.46
  • ethereum-name-serviceEthereum Name Service (ENS) $ 11.58
  • pyth-networkPyth Network (PYTH) $ 0.075159
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.03
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • justJUST (JST) $ 0.042674
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • ghoGHO (GHO) $ 0.999606
  • basic-attention-tokenBasic Attention (BAT) $ 0.278350
  • bitcoin-svBitcoin SV (BSV) $ 20.88
  • plasmaPlasma (XPL) $ 0.210082
  • conflux-tokenConflux (CFX) $ 0.079153
  • bittorrentBitTorrent (BTT) $ 0.00000041
  • sonic-3Sonic (S) $ 0.107416
  • usdbUSDB (USDB) $ 0.989824
  • swethSwell Ethereum (SWETH) $ 3,332.66
  • the-sandboxThe Sandbox (SAND) $ 0.153780
  • doublezeroDoubleZero (2Z) $ 0.115244
  • heliumHelium (HNT) $ 2.16
  • sbtc-2sBTC (SBTC) $ 90,731.00
  • sun-tokenSun Token (SUN) $ 0.020584
  • decredDecred (DCR) $ 22.77
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,349.57
  • apenftAINFT (NFT) $ 0.00000039
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.148833
  • dogwifcoindogwifhat (WIF) $ 0.375431
  • flowFlow (FLOW) $ 0.230741
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,067.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,027.99
  • olympusOlympus (OHM) $ 22.58
  • jasmycoinJasmyCoin (JASMY) $ 0.007276
  • galaGALA (GALA) $ 0.007666
  • merlin-chainMerlin Chain (MERL) $ 0.340247
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000002
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 17.08
  • wrapped-hypeWrapped HYPE (WHYPE) $ 33.27
  • gnosisGnosis (GNO) $ 131.29

Human-Targeted Attacks Are Now Web3’s Most Dangerous Threat, Report Finds

0 9

Human-Targeted Attacks Are Now Web3’s Most Dangerous Threat, Report Finds

A recent report by Kerberus, a Web3 security firm, suggests that human behavior is now the primary risk in Web3.

BeInCrypto spoke with the firm’s CEO, Alex Katz, and CTO, Danor Cohen, to understand why users continue to fall victim to attacks and what they can do to better protect themselves.

Human Error Drives Major Web3 Losses, Kerberus Report Finds

In its latest report titled “The Human Factor – Real-Time Protection Is the Unsung Layer of Web3 Cybersecurity (2025),” Kerberus revealed that human-focused attacks were the most structurally dangerous vector in Web3.

The report cites data showing that a significant share of industry losses stems from user mistakes. Roughly 44% of crypto thefts in 2024 resulted from the mismanagement of private keys. Another research indicates that human error is involved in approximately 60% of security breaches.

With 820 million active wallets in 2025, the threat landscape is expanding quickly, and everyone remains at risk. Katz told BeInCrypto that bad actors are targeting both newcomers and experienced users, but for very different reasons.

“New users are attractive because they don’t yet understand what ‘normal’ Web3 behavior looks like,” he said

Interestingly, the executive noted that long-time users are becoming increasingly higher-value targets compared to newcomers. According to him,

“Veteran users interact with far more dApps, sign more transactions, and move larger amounts. That means a single moment of complacency can do far more damage. So the group most at risk today is anyone who assumes they’re not at risk.”

Cohen added that one of the biggest misconceptions in Web3 is the belief that security failures stem from users not understanding the technology. His analysis points in the opposite direction. People are getting hacked because the system places an unrealistic burden on them.

“Users think, ‘I’m too smart to get drained, I know how wallets work – I’m safe.’ But the threat landscape changes faster than users do. Attackers aren’t trying to outsmart your wallet; they’re trying to outsmart you. And they’re extremely good at it. What people misunderstand is that Web3 puts an enormous cognitive burden on the individual. Users shouldn’t have to decipher technical signals to stay safe – security must work for them automatically,” he mentioned.

Why Even Smart Web3 Users Keep Getting Drained in 2025

These human-driven risk persists despite record spending on security in 2025. Kerberus’ report stated that crypto-related services and investors lost over $3.1 billion to hacks and scams in the first half of the year. This is already more than the total for all of 2024.

That number includes the historic Bybit breach. Excluding this, human-targeted attacks such as phishing and social engineering still accounted for $600 million. This represented 37% of the remaining $1.64 billion in losses.

The report noted that these attacks scale with growing adoption and bypass technical defenses entirely. This makes it difficult for traditional security models to prevent them.

While companies invest heavily in audits, monitoring, and code reviews, attackers increasingly exploit users directly at the transaction level. But what makes humans so vulnerable to these attacks?

“Humans are vulnerable because every scam is designed to exploit natural psychological shortcuts — urgency, authority, familiarity, fear of missing out, or comfort with routine. These are not flaws; they’re the same instincts that allow us to function in everyday life. Technology alone can’t change human psychology, but it can catch the moment when psychology is being weaponized,” Cohen detailed.

He emphasized that the strongest form of protection isn’t relying on users to avoid mistakes through education alone, but rather stopping harmful actions in real-time before damage occurs.

“That’s why real-time detection matters so much. If you can warn a user at the exact moment their trust is being manipulated, you can stop most losses before they occur,” Cohen added.

The executive noted that it’s unrealistic to expect an everyday user to distinguish between a malicious dApp, an airdrop, or a mint page. Modern fraudulent platforms often closely mirror legitimate ones. This makes them nearly indistinguishable.

He added that users can click phishing links repeatedly. They don’t do so out of carelessness, but because the attacks are intentionally crafted to deceive.

Even real-time warnings can sometimes appear to be false positives, highlighting the advanced nature of these scams.

“Users shouldn’t be expected to perform forensic checks. The burden has to shift to tools that analyze intent and behavior in real time,” Cohen suggested.

The report also states that these attacks exploit moments when users are least able to assess threats. It may happen when someone checks their wallet while distracted at work, reacts to an urgent message claiming their account will be frozen, or approves a transaction at the end of a long day when they’re exhausted.

According to the findings, the industry’s response has largely been to add more warnings and verification steps. But this approach often backfires due to “security fatigue.” As users become accustomed to constant alerts—many of which are false alarms that simply slow them down—their ability to make careful decisions diminishes under the continuous cognitive pressure.

3 Actions Users Can Take to Stay Safer in Web3

To reduce real-world losses, Katz disclosed three practices users can adopt. He advised users to:

  • Pause before signing: Most compromises occur in under ten seconds. Taking even a brief moment to read the prompt or confirm whether the request aligns with the intended action can prevent a large share of successful attacks.
  • Separate high-value assets from everyday activity: Using multiple wallets remains one of the most effective safeguards. He suggested that users should keep their long-term holdings in a cold or low-touch wallet and use a separate wallet for exploration, mints, and dApps. This compartmentalization limits potential damage.
  • Rely on real-time transaction protection: Because many threats involve social engineering rather than technical exploits, users benefit from tools that interpret on-chain actions before they’re finalized. This single layer of defense blocks many of the more advanced scams.

The intention, he stressed, is not to turn users into security experts, but to build guardrails that prevent mistakes from turning into financial losses.

The post Human-Targeted Attacks Are Now Web3’s Most Dangerous Threat, Report Finds appeared first on BeInCrypto.

Source

Leave A Reply

Your email address will not be published.