Dunicot A cybersecurity consultancy and advisory firm.

Web3 · Application security · 3 min read

Web3 security exposed: hunting vulnerabilities in dApps

Immutable code raises the stakes of every bug: there is no patch Tuesday for a deployed contract.

Introduction to Security and Privacy Threats in Web3

Web3 stands out as a groundbreaking advancement, integrating decentralization with user preference. However, this new wave of internet innovation brings a host of security and privacy concerns that must be addressed. Web3 poses many security and privacy risks, and you must be aware of these risks to navigate its challenges effectively.

Below are the threats that account for most of what Web3 loses each year, and what stops each of them.

Exploring Web3 Security and Privacy Threats

Hacking and Phishing

These attacks exploit vulnerabilities in dApp code or infrastructure to gain unauthorized access to private keys, wallets, and sensitive data.

For example, malicious smart contracts or misleading interface elements can be used to trick users into unauthorized transactions.

Web3 and blockchain security threats

Smart Contract Vulnerabilities

Smart contracts are fundamental to Web3 but can contain flaws leading to unintended actions and potential loss of funds.

For instance, A smart contract fails to validate input correctly, allowing attackers to withdraw funds repeatedly.

Web3 and blockchain security threats

Logic Vulnerabilities in dApps

Vulnerabilities such as faulty backdoors or logic flaws in decentralized applications can lead to security breaches. An example is a decentralized finance (DeFi) application that calculates transaction fees incorrectly, enabling exploitation for unintended profit.

Supply Chain Attacks

Targeting specific components within the application, such as compromised open-source libraries, that can be used to inject malicious code.

For instance, An attacker submits a malicious update to a widely used library, compromising all dApps that depend on it.

Web3 and blockchain security threats

Zero-Day Exploits

These exploits take advantage of vulnerabilities that are not yet known to the community or developers. For example, a zero-day exploit in popular blockchain client software could allow attackers to bypass network security and perform unauthorized actions.

Web3 and blockchain security threats

Metadata Leakage

The metadata attached to transactions can reveal sensitive information about users, despite the immutability of blockchains. An example is analyzing transaction times and amounts to deduce the identity of parties involved in a transaction.

Blockchain Analytics: While useful for data-driven personalization, it can inadvertently expose sensitive information. Example: Using transaction data to track the financial activity of users without their consent.

What actually reduces the risk

  • Use a hardware wallet: keys held on a hardware device never touch an internet-connected machine, so a compromised laptop does not cost you the wallet. A Ledger or Trezor signing offline is the baseline for any balance you would mind losing.
  • Keep the recovery phrase offline: anyone holding the phrase holds the wallet. Write it down, put it somewhere physically secure, and never photograph it, type it into a browser or store it in a password manager that syncs.
  • Implement Two-Factor Authentication: This adds a layer of security by requiring a second form of verification. Example: Enabling 2FA on a crypto exchange so that logins require not only a password but also a code from an authenticator app.

Conclusion

Web3 has been adopted faster than its security practices have matured. The threats described here, phishing, key theft, contract flaws and front-end compromise, are all understood, and all of them keep working because the same mistakes keep being repeated. Developers who audit before deploying and users who verify before signing avoid most of what the sector loses each year. The rest is a matter of habit.

In short

Point 1
A deployed contract cannot be patched, so review has to happen before deployment, not after.
Point 2
Most dApp losses start off-chain: in the front end, the RPC layer or the signing flow.
Point 3
Users sign what the interface shows them; compromise the interface and you compromise consent.
Point 4
Audit the integration, not only the contract.

Want this applied to your stack?

Everything written here comes out of delivered engagements. Describe the platform and the deadline.