The CertiK "2025 Skynet RWA Security Report" has been released. The report indicates that RWA tokenization is reshaping the blockchain financial landscape at an astonishing pace. By mid-2025, the RWA market size has exceeded $26 billion, a fivefold increase from approximately $5 billion in 2022, making it one of the most dynamic segments of the digital asset ecosystem. RWA is becoming a critical bridge connecting traditional finance (TradFi) and decentralized finance (DeFi), but at the same time, its security threats are exhibiting new characteristics.
Skynet RWA Rankings
The report unveiled the Skynet RWA Rankings, with the top ten projects in the first half of 2025 being: BlackRock BUIDL, Franklin Templeton OnChain Fund, Ondo Finance, Paxos Gold, Tether Gold, Binance RWUSD, Ethena USDtb, Centrifuge, Usual, and SKY (MakerDAO RWA Vaults). These projects cover various segments such as government bonds, gold, stablecoins, and accounts receivable, representing the diversified development directions of the RWA ecosystem.
These protocols demonstrate the highest standards in the RWA industry through compliant legal structures, transparent proof of reserves, and institutional-grade security measures. Their practices in compliance, transparency, and risk management are setting new benchmarks for the entire industry.
The Double-Edged Sword of RWA Growth and Security Risks
RWA tokenization has unleashed significant value potential, bringing efficiency and transparency to the financial system. However, the security risks of such assets far exceed traditional smart contract vulnerabilities, encompassing oracle manipulation, custodian and counterparty risks, unenforceable legal frameworks, and false proof of reserves, among other issues.
On the other hand, the threat landscape of RWA has undergone significant changes over the past two years. In the first half of 2025, losses from RWA-related security incidents reached $14.6 million, compared to only $6 million in 2024. More notably, the source of risks has fundamentally shifted: in 2023 and 2024, the primary threats came from off-chain credit defaults, such as borrowers failing to fulfill obligations, while in 2025, losses were almost entirely due to on-chain and operational vulnerabilities.
This shift indicates that the RWA security landscape is undergoing profound evolution, with the focus of risks gradually moving from off-chain financial defaults to on-chain technical vulnerabilities and operational management failures.
"Five-Layer Security Stack" and Skynet Scoring Framework
To help the market more systematically identify and manage risks, CertiK proposed a "Five-Layer Security Stack" model in the report, covering asset, legal, operational, data, and on-chain layers. This forms a full-stack security assessment method, ranging from oracle security and proof of reserves to compliance and governance mechanisms.
Based on the Five-Layer Security Stack, CertiK launched the Skynet RWA Security Scoring Framework, comprehensively assessing risks across six dimensions, including assets, legal, operations, and smart contracts. The Skynet security framework is built on the core risk dimensions of RWA, with each dimension corresponding to its potential impact on the overall security and stability of RWA protocols. This structure ensures that key off-chain components representing the latest significant risk vectors are appropriately weighted in the final assessment.
Outlook: From $26 Billion to a Trillion-Dollar Market
The report also summarized three core trends in the RWA field:
-
U.S. Treasury products dominate the market: The scale of tokenized U.S. Treasury bonds has increased by 400% year-on-year, becoming the "entry asset" for RWA.
-
Integration of yield and stablecoins: Emerging stablecoins directly distribute Treasury interest to users, reshaping the stablecoin landscape.
-
Deep involvement of traditional financial giants: The participation of institutions like BlackRock and Franklin Templeton has raised compliance and transparency standards, accelerating industry mainstream adoption.
As of mid-2025, the total market capitalization of RWA has exceeded $26 billion and is expected to maintain rapid growth. Boston Consulting Group predicts that up to $16 trillion in assets globally could be tokenized by 2030.
CertiK emphasized at the end of the report: RWA security has become a critical proposition for the healthy development of the entire Web3 ecosystem. A transparent and systematic security assessment framework will help investors, institutions, and regulators make more robust decisions in the future trillion-dollar market.