“The tokenization of real-world assets is the future of finance. But if we don’t build secure infrastructure, that future will be built on sand.”
— Allison Pearson, Director of Cybersecurity at Europol
In the first half of 2025, the tokenized real-world assets (RWA) sector faced an unprecedented surge in cyberattacks: hackers stole more than $14.6 million from various protocols, already surpassing the total losses of all 2024. This alarming trend shows that despite the impressive growth of interest from banks, funds, and regulators, the RWA infrastructure remains one of the most vulnerable areas in the Web3 ecosystem.
According to a report by Cyvers, during the first six months of 2025 there were 17 incidents involving RWA protocols, including smart contract exploits, oracle attacks, and thefts through malicious extensions. At the same time, the loss volume increased by 124% compared to H1 2024, indicating that hackers are increasingly choosing RWA as their primary target.
This rise coincides with a boom in the sector: according to DeFiLlama, the total value locked (TVL) in RWA protocols exceeded $12.8 billion by July 2025, up 68% from the previous year. The more capital flows into the sector, the more attractive it becomes for attackers.
Here are the most significant incidents in the first half of 2025 that resulted in $14.6 million in losses:
In March 2025, Ondo Finance, a leader in U.S. Treasury bond tokenization, fell victim to an exploit. The hacker leveraged a vulnerability in the rights revocation mechanism of one of its smart contracts, allowing them to bypass checks and withdraw 6.8 million USDC. The company stated that the funds were insured and affected investors were compensated.
In May 2025, a protocol specializing in the tokenization of European bonds lost $4.2 million after an attack on its data supply chain. The attacker compromised an external oracle, which fed false pricing data for a tokenized asset, enabling them to take out massive undercollateralized loans. The incident marked one of the first cases of an oracle attack targeting an RWA protocol.
In June 2025, users of a DeFi platform integrated with RWA pools fell victim to a fake VS Code extension called "rwa-helper.sol". It mimicked a legitimate developer tool but extracted private keys from .env files. As a result, $3.6 million USDT was stolen from wallets of users participating in RWA liquidity pools.
Previously, the main targets of cyberattacks were DEXs, bridges, and meme coins. Today, the focus has shifted to RWA. The reasons are clear:
RWA protocols hold millions of dollars in tokenized bonds, deposits, and real estate. This makes them more attractive than pools with illiquid tokens.
Many RWA projects are still in early stages. Their code hasn’t undergone years of scrutiny like Ethereum or Bitcoin. New protocols often attract investment before undergoing a full audit.
RWA protocols depend on multiple components: smart contracts, oracles, centralized issuers, and banking integrations. Each element is a potential point of failure.
Many RWA teams are composed of financiers and lawyers rather than experienced Web3 developers, leading to negligence of best security practices.
As a Chainalysis analyst put it: “RWA is the milk of Web3. Sweet, valuable, and attractive to anyone seeking easy prey.”
Hackers use several key methods to breach RWA infrastructure:
The most common method. Vulnerabilities in contract logic (such as in synthesis, rights revocation, or liquidity management mechanisms) allow attackers to bypass checks and drain funds.
Since RWA tokens are tied to real-world assets, their price depends on external data. If a hacker compromises an oracle, they can inject false prices and trick the protocol.
Many RWA protocols use cross-chain bridges to transfer assets. These bridges often prove to be weak links, as seen with Harmony and Wormhole.
As the rwa-helper.sol case showed, hackers increasingly target not just the protocol itself, but its users and developers through phishing and malware.
Some projects have already implemented protective measures, but they remain insufficient for complete security.
Companies such as Ondo and Maple Finance conduct audits with CertiK, OpenZeppelin, Zellic. However, an audit doesn’t guarantee the absence of vulnerabilities — it only verifies the code at the time of review.
Some protocols partner with Nexus Mutual, InsurAce, Bridge Mutual to insure funds. But coverage is often limited and payouts can be delayed.
Using multi-oracle solutions (Chainlink, Pyth) reduces the risk of a single data source compromise.
Critical protocol changes require committee approval or community voting, which slows down potential attacks.
As Hakan Unal from Cyvers noted: “RWA security is not just about code. It’s about legal agreements, physical safeguards, and trust in the issuer.”
The rising number of hacks is already affecting the entire sector:
At the same time, most of the affected investors are not large funds, but retail users who invested their savings expecting stable returns.
To stop the surge of hacks, the industry must move from reactive to proactive security.
RWA developers need a deep understanding of Web3 cybersecurity. Courses from Secureum, Immunefi, Trail of Bits should become mandatory.
Systems like Cyvers, Chainalysis, TRM Labs should track suspicious transactions and behavioral patterns.
Common standards are needed for RWA protocols, similar to those for smart contracts (e.g., ERC-20). Organizations like OpenZeppelin and ConsenSys are already working on this.
Protocols must offer generous rewards to white-hat hackers for finding vulnerabilities. Prize pools should amount to at least 10–15% of TVL.
Reducing dependence on centralized issuers and banking integrations. Developing decentralized oracles and legal frameworks for DAOs.
The tokenization of real-world assets is one of the most promising trends in Web3. According to Boston Consulting Group, by 2030 the RWA market could reach $16 trillion. However, this potential could be destroyed if security remains an afterthought.
Key takeaways:
As Charles Guillem from Ledger said: “In Web3, money is code. And code without security is a leaky wallet.”
The future of finance may be tokenized, but only if it is built on a solid foundation. As long as RWA remains vulnerable, every new billion invested in the sector is both an opportunity and a risk.
