Institutional Goldrush Sparks RWA Security Crisis

Generated by AI AgentCoin World
Thursday, Aug 21, 2025 9:24 am ET2min read
Aime RobotAime Summary

- RWA protocol exploits surged to $14.6M in H1 2025, surpassing 2024’s $6M and 2023’s $17.9M losses, driven by 260% growth in tokenized asset demand.

- Hybrid security risks like oracle manipulation and custodial failures caused major breaches, including Zoth’s $8.5M key compromise and Loopscale’s $5.8M hack.

- Institutional adoption of tokenized U.S. Treasuries and private credit (58% market share) intensified vulnerabilities, exposing gaps in legal frameworks and liquidity structures.

- The report urges hybrid market designs, transparency, and regulatory alignment to address liquidity bottlenecks and secure the $23B+ RWA ecosystem against escalating threats.

RWA protocol exploits reached $14.6 million in the first half of 2025, surpassing the $6 million lost to similar exploits in 2024, according to a report by CertiK shared with Cointelegraph. This figure marks a significant increase from the $17.9 million in losses recorded in 2023, indicating a growing threat in the RWA sector. The rise in exploits is attributed to the increasing institutional demand for tokenized real-world assets, which has surged over 260% in the first half of 2025, reaching a total valuation of over $23 billion by June 5. The primary drivers of this growth include tokenized private credit and U.S. Treasury debt, with private credit accounting for approximately 58% of the RWA market share.

The growing malicious activity in the RWA sector is attributed to the hybrid security challenges introduced by tokenizing offchain assets. These challenges extend beyond smart contracts to include

manipulation, custodial and counterparty failures, unenforceable legal frameworks, and fraudulent proof of reserves attestations. The report highlights that RWA protocols face vulnerabilities at each layer of their security stack, particularly due to the involvement of human actors and legal interpretations in offchain processes. For instance, the RWA restaking protocol Zoth suffered the largest exploit of $8.5 million in 2025, caused by a classic operational security failure involving a compromised private key. Similarly, Loopscale faced a $5.8 million hack due to blockchain oracle price manipulation, although $2.8 million of the stolen funds were recovered by April 29.

The report emphasizes that the complexity of RWA tokenization introduces new risk vectors that require a multi-faceted approach to address. The hybrid nature of RWA protocols means that risks emerge from the interaction between onchain and offchain components, creating a broader attack surface. Institutional participation in the RWA market has been driven by clearer regulatory frameworks, with tokenized U.S. Treasuries and private credit leading the way. However, the same regulatory clarity has also attracted malicious actors, who exploit vulnerabilities in the protocols to siphon funds.

The impact of RWA exploits is not limited to financial losses but also includes a potential erosion of trust in the tokenization process. The report underscores the importance of addressing these security challenges to maintain the integrity of the RWA market. The recommendations include the adoption of hybrid market structures, improved transparency, and the implementation of incentives for liquidity providers. These measures are intended to enhance the resilience of RWA protocols against future attacks and to ensure that the market continues to grow sustainably.

The growth of the RWA market has been accompanied by a surge in tokenized assets, with over $25 billion in tokenized RWAs brought on-chain as of mid-2025. Despite this progress, liquidity remains a critical bottleneck, with most RWA tokens exhibiting low trading volumes, long holding periods, and limited investor participation. The structural barriers to liquidity include regulatory gating, custodial concentration, whitelisting, valuation opacity, and the lack of decentralized trading venues. Addressing these issues requires coordinated progress across legal, technical, and institutional domains. By implementing hybrid market structures, improving transparency, and leveraging regulatory innovations, the RWA ecosystem can transition from an issuance-centric model to a transaction-centric one, thereby realizing the full potential of tokenization in financial markets.

Source: [1] RWA protocol exploits reach $14.6M in H1 2025, surpassing 2024 (https://cointelegraph.com/news/rwa-protocol-exploits-14-6m-in-h1-2025-surpassing-2024)

Comments



Add a public comment...
No comments

No comments yet