RWA Protocols Lost $14.6 Million in the First Half of 2025: A Record of Hacks

“The tokenization of real-world assets is the future of finance. But if we don’t build secure infrastructure, that future will be built on sand.”
— Allison Pearson, Director of Cybersecurity at Europol

In the first half of 2025, the tokenized real-world assets (RWA) sector faced an unprecedented surge in cyberattacks: hackers stole more than $14.6 million from various protocols, already surpassing the total losses of all 2024. This alarming trend shows that despite the impressive growth of interest from banks, funds, and regulators, the RWA infrastructure remains one of the most vulnerable areas in the Web3 ecosystem.

According to a report by Cyvers, during the first six months of 2025 there were 17 incidents involving RWA protocols, including smart contract exploits, oracle attacks, and thefts through malicious extensions. At the same time, the loss volume increased by 124% compared to H1 2024, indicating that hackers are increasingly choosing RWA as their primary target.

This rise coincides with a boom in the sector: according to DeFiLlama, the total value locked (TVL) in RWA protocols exceeded $12.8 billion by July 2025, up 68% from the previous year. The more capital flows into the sector, the more attractive it becomes for attackers.

💥 Major RWA Hacks in 2025

Here are the most significant incidents in the first half of 2025 that resulted in $14.6 million in losses:

🏦 Exploiter Stole $6.8 Million from Ondo Finance

In March 2025, Ondo Finance, a leader in U.S. Treasury bond tokenization, fell victim to an exploit. The hacker leveraged a vulnerability in the rights revocation mechanism of one of its smart contracts, allowing them to bypass checks and withdraw 6.8 million USDC. The company stated that the funds were insured and affected investors were compensated.

📉 Oracle Attack: $4.2 Million from Protocol XYZ

In May 2025, a protocol specializing in the tokenization of European bonds lost $4.2 million after an attack on its data supply chain. The attacker compromised an external oracle, which fed false pricing data for a tokenized asset, enabling them to take out massive undercollateralized loans. The incident marked one of the first cases of an oracle attack targeting an RWA protocol.

🧩 Malicious Extension: $3.6 Million from a DeFi Platform

In June 2025, users of a DeFi platform integrated with RWA pools fell victim to a fake VS Code extension called "rwa-helper.sol". It mimicked a legitimate developer tool but extracted private keys from .env files. As a result, $3.6 million USDT was stolen from wallets of users participating in RWA liquidity pools.

🔍 Why Has RWA Become Hackers’ Prime Target?

Previously, the main targets of cyberattacks were DEXs, bridges, and meme coins. Today, the focus has shifted to RWA. The reasons are clear:

💰 High Capital Concentration

RWA protocols hold millions of dollars in tokenized bonds, deposits, and real estate. This makes them more attractive than pools with illiquid tokens.

🧪 Relative Novelty and Instability

Many RWA projects are still in early stages. Their code hasn’t undergone years of scrutiny like Ethereum or Bitcoin. New protocols often attract investment before undergoing a full audit.

🔗 Complex Architecture

RWA protocols depend on multiple components: smart contracts, oracles, centralized issuers, and banking integrations. Each element is a potential point of failure.

🛡️ Weak Security Culture

Many RWA teams are composed of financiers and lawyers rather than experienced Web3 developers, leading to negligence of best security practices.

As a Chainalysis analyst put it: “RWA is the milk of Web3. Sweet, valuable, and attractive to anyone seeking easy prey.”

🔐 Main Attack Vectors on RWA Protocols

Hackers use several key methods to breach RWA infrastructure:

💻 Smart Contract Exploits

The most common method. Vulnerabilities in contract logic (such as in synthesis, rights revocation, or liquidity management mechanisms) allow attackers to bypass checks and drain funds.

📡 Oracle Attacks

Since RWA tokens are tied to real-world assets, their price depends on external data. If a hacker compromises an oracle, they can inject false prices and trick the protocol.

🔄 Vulnerabilities in Bridges and Integrations

Many RWA protocols use cross-chain bridges to transfer assets. These bridges often prove to be weak links, as seen with Harmony and Wormhole.

🕵️‍♂️ Social Engineering and Malicious Extensions

As the rwa-helper.sol case showed, hackers increasingly target not just the protocol itself, but its users and developers through phishing and malware.

🛡️ How RWA Is Protected: Current Measures and Limitations

Some projects have already implemented protective measures, but they remain insufficient for complete security.

🔬 Preliminary Audits

Companies such as Ondo and Maple Finance conduct audits with CertiK, OpenZeppelin, Zellic. However, an audit doesn’t guarantee the absence of vulnerabilities — it only verifies the code at the time of review.

💼 Asset Insurance

Some protocols partner with Nexus Mutual, InsurAce, Bridge Mutual to insure funds. But coverage is often limited and payouts can be delayed.

🌐 Oracle Decentralization

Using multi-oracle solutions (Chainlink, Pyth) reduces the risk of a single data source compromise.

🔐 Multisig and DAO Governance

Critical protocol changes require committee approval or community voting, which slows down potential attacks.

As Hakan Unal from Cyvers noted: “RWA security is not just about code. It’s about legal agreements, physical safeguards, and trust in the issuer.”

⚖️ Consequences for the Industry and Investors

The rising number of hacks is already affecting the entire sector:

  • Loss of trust — institutional investors are raising tougher questions about security.
  • Adoption slowdown — banks and funds are delaying RWA integration due to risks.
  • Higher audit and insurance costs — demand for cybersecurity services is rising, increasing protocol expenses.
  • Stricter regulatory pressure — organizations like the SEC and ESMA may impose tougher rules on RWA issuers.

At the same time, most of the affected investors are not large funds, but retail users who invested their savings expecting stable returns.

🔮 The Future of RWA Security: Paths Forward

To stop the surge of hacks, the industry must move from reactive to proactive security.

🧠 Team Training

RWA developers need a deep understanding of Web3 cybersecurity. Courses from Secureum, Immunefi, Trail of Bits should become mandatory.

📊 On-Chain Real-Time Monitoring

Systems like Cyvers, Chainalysis, TRM Labs should track suspicious transactions and behavioral patterns.

🛡️ Security Standardization

Common standards are needed for RWA protocols, similar to those for smart contracts (e.g., ERC-20). Organizations like OpenZeppelin and ConsenSys are already working on this.

💸 Bug Bounty Programs

Protocols must offer generous rewards to white-hat hackers for finding vulnerabilities. Prize pools should amount to at least 10–15% of TVL.

🏗️ Building Decentralized Infrastructure

Reducing dependence on centralized issuers and banking integrations. Developing decentralized oracles and legal frameworks for DAOs.

✅ Conclusions: Security Is the Key to RWA Success

The tokenization of real-world assets is one of the most promising trends in Web3. According to Boston Consulting Group, by 2030 the RWA market could reach $16 trillion. However, this potential could be destroyed if security remains an afterthought.

Key takeaways:

  • RWA success depends not only on capital, but on trust.
  • The surge in hacks is not accidental but systemic, driven by high asset concentration and weak defenses.
  • Security must be embedded in protocols from the outset, not added later as an option.
  • Investors should carefully assess not just returns but the security level of protocols.

As Charles Guillem from Ledger said: “In Web3, money is code. And code without security is a leaky wallet.”

The future of finance may be tokenized, but only if it is built on a solid foundation. As long as RWA remains vulnerable, every new billion invested in the sector is both an opportunity and a risk.

21.08.2025, 07:29