Kerberus Report Warns Real-Time Protection Lags as Human-Targeted Scams Surge

Markets 2025-11-19 10:13

A new industry report released this week shows that human-targeted attacks – rather than technical vulnerabilities – are responsible for the majority of Web3 losses, despite record levels of security spending across the sector.

The report, The Human Factor: Why Real-Time Protection Is the Missing Layer in Web3 Security, published by security firm Kerberus, estimates that more than $3.1 billion was stolen through hacks and scams between January and June 2025. Of that, over $600 million came from phishing, wallet compromise and social engineering incidents that targeted users directly rather than exploiting blockchain code.

The figures include the $1.46 billion Bybit exchange breach, the largest crypto heist to date. Kerberus notes that even when excluding the Bybit incident as an outlier, human-targeted attacks remain a significant source of losses across the ecosystem.

The report highlights what Kerberus describes as a fundamental resource-allocation failure across the Web3 security sector. According to the company’s analysis, most security spending still flows into tools that operate either before an attack occurs – such as audits and vulnerability testing – or after funds have already been stolen, including forensics and incident response. Kerberus argues that this leaves a critical gap during the short window in which users approve transactions, a moment attackers increasingly exploit because it remains largely undefended. Despite rising losses tied to phishing, wallet drainers, and social engineering, real-time protection still accounts for only a small share of available solutions.

Key findings from the report

According to the research:

  • 44% of crypto thefts stem from private key mismanagement.

  • 60% of wider cybersecurity breaches involve human error.

  • 90% of exploited smart contracts had passed security audits before being attacked.

  • Phishing click-through rates remain between 7–15%, even after security training.

The report suggests that these patterns continue because most Web3 security spending is directed toward code auditing and post-incident analysis, while attackers increasingly focus on manipulating users during wallet interactions.

Kerberus’ leadership team notes that the majority of existing tools function entirely outside the transaction window. These systems play an important role in keeping code safe and analysing breaches, but they don’t interpret user intent or scan live transactions at the wallet level. Kerberus points out that delivering this type of protection requires sophisticated real-time detection infrastructure capable of running deep scans in under a second without disrupting the user experience — a technically demanding challenge that explains why only a small minority of providers currently offer true real-time defences.

Real-time protection remains limited

Kerberus reviewed 61 active Web3 security providers and found that:

  • 87% operate preventatively focusing on audits or post-incident forensics

  • Only 13% provide real-time, transaction-level defences that can block malicious actions before approval.

The report states that this distribution helps explain why losses remain high even as the number of “real-time” solutions increases: many providers market real-time features, but few deliver transaction blocking at the wallet level.

Kerberus Report Warns Real-Time Protection Lags as Human-Targeted Scams Surge

Examples cited in the report

One case highlighted involves an American investor who lost $330 million in Bitcoin after being manipulated in a phone-based social engineering attack, despite keeping funds secure for years. Another section points to compromised websites, hacked social media accounts, and manipulated Discord servers as growing channels for wallet-draining schemes.

Implications for the sector

The authors argue that the current model – where users are expected to independently evaluate risks, verify links, and recognise phishing attempts- creates predictable failure points. Frequent security prompts, they note, can lead to “alert fatigue,” making users more likely to approve malicious transactions.

The report concludes that wider adoption of real-time, automated transaction screening is crucial to reduce losses and support mainstream use of Web3 platforms.

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.