A joint report by RWA.io and Veritas Protocol, with contributions from Tron DAO, identifies a sharp increase in security threats to the tokenized real-world asset (RWA) market. Financial losses from on-chain operational failures reached $14.6 million in the first half of 2025, a 143% increase over the total for 2024.
The "RWA Security Report 2025: An Analysis of Tokenized Asset Threats" analyzes data from January 2023 to June 2025. It shows a clear change in attack methods. Unlike previous years dominated by off-chain credit defaults, incidents in 2025 resulted entirely from on-chain attacks like private key compromises and oracle manipulation. This exposes the limitations of periodic security audits in the RWA market, now valued at over $30 billion.
"The tokenization of real-world assets is a large and growing financial sector, but this growth introduces new risks," said Marko Vidrih, COO of RWA.io. "The speed of modern attacks requires that the industry moves from periodic audits to continuous, automated security to protect investors and maintain market stability".

A key case study is the March 2025 Zoth Protocol incident, which resulted in an $8.5 million loss due to a private key compromise. This event shows how operational security gaps can lead to drained funds even from secure smart contracts, a threat traditional audits may not prevent.
As a solution, the document presents a security framework developed by Veritas Protocol that uses an autonomous multi-agent AI system for continuous, real-time threat monitoring. This system runs over 14,000 times faster than manual audits and generates dynamic "Trust Scores" to help investors evaluate the risk of smart contracts and wallets in real time.
The analysis also covers effective industry actions, such as the T3 Financial Crime Unit. This partnership between TRON, Tether, and TRM Labs has frozen more than $250 million in illicit assets in less than a year, providing a working model for proactive financial crime prevention.

Key Findings from the Report
- Increased Losses: Losses in H1 2025 ($14.6 million) surpassed all of 2024 ($6.1 million) by 143%.
- Changing Attack Methods: All 2025 incidents were caused by on-chain operational failures, a shift from previous credit-related risks.
- Stablecoin Role in Illicit Finance: Stablecoins were used in 63% of illicit transaction volumes.
- Network Risk Concentration: 56.6% of financial losses occurred on the Ethereum network.
With projections showing the RWA market could exceed $30 trillion in 2030s, the report concludes that automated security infrastructure is necessary to manage risk at scale.
The full report is available for download at https://www.rwa.io/research.
About RWA.io
RWA.io is the global hub for real-world asset tokenization. The platform provides a unified ecosystem where issuers and investors can find, evaluate, launch, trade, and manage the complete lifecycle of RWAs with clear paths to liquidity.
About Veritas Protocol
Veritas is an AI-powered security protocol for autonomous vulnerability detection. Built on custom-trained AI and multi-agent framework infrastructure, it finds and fixes vulnerabilities in real-time, bringing affordable high-end security to projects and users.