Subscribe
Logo
Logo
  • Topics Icon Topics
    • AI Icon AI
    • Banking Icon Banking
    • Blockchain/DeFi Icon Blockchain/DeFi
    • Embedded Finance Icon Embedded Finance
    • Fraud/Identity Icon Fraud/Identity
    • Investing Icon Investing
    • Lending Icon Lending
    • Payments Icon Payments
    • Regulation Icon Regulation
    • Startups Icon Startups
  • Podcasts Icon Podcasts
  • Products Icon Products
    • Webinars Icon Webinars
    • White Papers Icon White Papers
  • TechWire Icon TechWire
  • Search
  • Subscribe
Reading
Recent hacks teach valuable Web3 lessons
ShareTweet
Dangerous Hooded Hacker Breaks into Government Data Servers and Infects Their System with a Virus. His Hideout Place has Dark Atmosphere, Multiple Displays, Cables Everywhere.
Home
Crypto
Recent hacks teach valuable Web3 lessons

Recent hacks teach valuable Web3 lessons

Tony Zerucha·
Crypto
·Sep. 14, 2022·3 min read

Recent crypto hacks provide lessons on the importance of constant security testing, the limitations of Web3 in today’s environment, and the need to hold judgment until all facts are in.

CertiK’s director of security operations, Hugh Brooks, said the blockchain security firm tracked 31 significant incidents in August. The most notable, the $190 million Nomad hack, led to what may be the first mob attack in crypto history. Thanks to a code vulnerability, thieves could easily, and with little knowledge, exploit the flaw.

Brooks said that the Solana hack is an example of Web2’s impact on Web3. A third-party service installed by a vendor was not properly security tested. It sent secret phrases and clear text back to the servicer, which hackers had accessed. They went into wallets and transferred money out.

Why Web3 is limited in a Web2 world and the importance of security testing

“Everyone needs to realize that true decentralization in 2022 is a dream and will continue to be one until Web3 no longer relies on Web2 infrastructure. Your dApp likely utilizes files that are stored on various servers. It’s a bit of Web3 and a whole lot of Web2,” Brooks said.

Another lesson companies must learn is that security testing is a continuous process.

“These people had done security testing of the app and audits and all these other things as well, but they didn’t do it with every release,” Brooks said. “And sure enough, the latest release caused them to have some accidents.”

Brooks frequently sees hacks exploiting improperly audited projects. Companies must complete exhaustive checks when considering external vendors or risk damage from someone else’s mistake, as Solana did.

“There was no flaw in Solana itself,” Brooks stressed. “Initially, everybody thought there was some mistake in Solana. It was difficult at first to tease out what was going on there. And it wasn’t until the community got together… (that) they were able to start narrowing it down.

“But it is the kind of thing that regular mobile application security testing would have caught.”

Web3 can learn from those they want to displace

Web3 companies need to view their internal security processes like companies in traditional cybersecurity industries do.

“There’s been this big move and shift… where people are looking at security from the lifecycle of when they start coding that mobile app to when we put it out there,” Brooks said. “And then every release, it goes through essentially, that same kind of testing. 

“You don’t see that yet in many of the Web3 worlds. Web3 people with great ideas also do a mobile app or a web app. They’re not bringing on the kind of security, and few people are experts to do the security testing they need.”

But the stakes are higher in Web3 because of the total value locked in. A slight mistake can quickly become expensive, avoided by regular security testing.

That’s what TradFi accepts as part of doing business. Bank apps are tested at every step. Because of regulations, there are security protocols to be met.

“We’re just not seeing that in the crypto space,” Brooks said.

Why bridges bring risk

Bridges allow communication between separate blockchains that might otherwise be interoperable. With cryptocurrencies, they hold one token as collateral and issue you another on the blockchain you want to participate in.

As bridges connect to more protocols and more types of collateral are accumulated, matters become more complex. One error can produce many vulnerabilities.

Brooks said that the solution is testing and then more testing by multiple sources.

“You can guarantee the hackers are looking at it. Then you need to be red teaming and have blue teams on your team that can manage when things go bad. Security is always cat and mouse, and you must be doing that life all the time.”

  • Tony Zerucha
    Tony Zerucha

    Tony is a long-time contributor in the fintech and alt-fi spaces. A two-time LendIt Journalist of the Year nominee and winner in 2018, Tony has written more than 2,000 original articles on the blockchain, peer-to-peer lending, crowdfunding, and emerging technologies over the past seven years. He has hosted panels at LendIt, the CfPA Summit, and DECENT's Unchained, a blockchain exposition in Hong Kong. Email Tony here.

    View all posts

Tags
bridgesHugh BrooksWeb2Web3
Related
cogni passport

The Fintech Coffee Break – Simon Grunfeld, Cogni

cogni passport

Cogni debuts KYC compliance tool for Web3

masa celo prosperity passport

Masa and Celo launch Soulbound Token Digital Identity

Boy ponders

Web3 reimagined from the ground up

Popular Posts

Today:

  • _Renton’s Take on AI x Banking; Fed Independence Weighs on Macro OutlookFraudsters Beware: Fintech is on the Case Sep. 16, 2025
  • Diya JollyXero’s CTO on building a ‘superagent’ for accounting Sep. 17, 2025
  • FN 8:28The Unique Challenges and Opportunities for AI Companies Working with Banks Aug. 28, 2025
  • Justin OverdorffLightspeed’s Overdorff on AI Investing Momentum Sep. 18, 2025
  • Jon StonaTips from Airwallex x McLaren on Making the Best of a Fintech Sponsorship  Jun. 18, 2025
  • Fintech ForecastWhy Every Lender Should Be Using Cash Flow Underwriting Today Jul. 29, 2025
  • Zinnia CEO – Michele TrogniThe Nexus Profile: Zinnia’s CEO on Building the Rails for Financial Longevity Sep. 9, 2025
  • Fintech Nexus – Newsletter Creative (2)The Rise of the Algorithmic State Sep. 17, 2025

This month:

  • Sunil Sachdev, FiservFiserv’s Sachdev on stablecoins’ evolution Aug. 26, 2025
  • FNFounders and the Future Dispatch: Responsible AI in an Age of Acceleration Aug. 27, 2025
  • FN 8:28The Unique Challenges and Opportunities for AI Companies Working with Banks Aug. 28, 2025
  • Zinnia CEO – Michele TrogniThe Nexus Profile: Zinnia’s CEO on Building the Rails for Financial Longevity Sep. 9, 2025
  • Revised-AI-InvoiceAI Faces Skepticism. Startups Say: OK, Pay When it Works Jun. 25, 2025
  • 5 Founders Driving Humanoid AIThe Humanoid Era: 5 Leaders Defining Physical AI Sep. 10, 2025
  • Jeff Radke AccelerantAs Accelerant IPOs on NYSE, CEO Jeff Radke Hopes to Usher In Insurtech 3.0 Jul. 24, 2025
  • SOLO CeoSOLO’s CEO on the data and banking dilemma Sep. 11, 2025
  • Diya JollyXero’s CTO on building a ‘superagent’ for accounting Sep. 17, 2025
  • Aidan CorbettWayflyer’s $5B Bet on Small Business Lending May. 1, 2025

  • About
  • Contact
  • Disclaimer
  • Privacy Policy
  • Terms
Subscribe
Copyright © 2025 Fintech Nexus
  • Topics
    • AI
    • Banking
    • Blockchain/DeFi
    • Embedded Finance
    • Fraud/Identity
    • Investing
    • Lending
    • Payments
    • Regulation
    • Startups
  • Podcasts
  • Products
    • Webinars
    • White Papers
  • TechWire
  • Contact Us
Start typing to see results or hit ESC to close
lis digital banking USA Lending Club UK
See all results