18 May 2025

Trust Issues: Zscaler Warns Web3 Isn’t Ready for GenAI Phishing Attacks

Trust as the new vulnerability - The Coinomist

Your wallet is safe. Your attention isn’t. Zscaler’s new report warns that phishing attacks in Web3 has gone from email blasts to AI-powered deception—targeting users, tools, and trust.

On this page

The foundational ethos of the crypto space is ‘trust the code.' However, in 2025, the primary vulnerability lies not within the code itself, but in the users:

  • their habits, 
  • shortcuts, 
  • devices, 
  • attention. 

According to Zscaler’s ThreatLabz, attackers are leveraging advanced techniques, outpacing the security efforts of many rapidly scaling Web3 startups.

A new report from the cloud security leader, Zscaler, reveals a sharp shift in the phishing landscape. Based on over two billion blocked phishing attempts in 2024, the findings are as clear as they are chilling: mass phishing is out, precision phishing is in. And the Web3 world—fast-moving, remote-first, and interface-obsessed—is sitting in the center of the blast radius.

The phishing game has changed. Attackers are using GenAI to create near-flawless lures and outsmart even AI-based defenses,

says Deepen Desai, Chief Security Officer at Zscaler.
Cover of Zscaler’s 2025 ThreatLabz phishing report featuring AI-driven cyberattack imagery — The Coinomist
Cover of the Zscaler ThreatLabz 2025 Phishing Report, which analyzes over two billion phishing attempts to uncover how GenAI is transforming the cyber threat landscape. Source: zscaler.com

In a world where crypto risks are growing fast, staying safe is more crucial than ever. Discover expert strategies to avoid scams, phishing attacks, and costly mistakes in our latest education piece!

The Code Was Fine—The Trust Wasn’t

The report’s central message for crypto teams is stark: while smart contracts may be secure, users remain the primary target. Indeed, the most successful attacks in 2024 bypassed code vulnerabilities entirely, relying instead on convincing interfaces, familiar branding, and exploiting a sense of urgency.

In the past, phishing meant mass emails. 

Today, it means:

  • Spoofed wallets, 
  • Malicious AI agents, 
  • Fake DevOps tools, 
  • Real-time impersonation of your IT team.

Web3 doesn’t get a pass. It gets targeted.

Vishing Makes Its Way Into Web3 IT Desks

One of the sharpest spikes in 2024 was in vishing—voice phishing attacks where bad actors call startup employees pretending to be from their internal IT department. Using breached credentials and malware logs, they build credibility fast.

Zscaler’s report notes how DevOps engineers, remote designers, and even DAO moderators are falling for these calls. The attacker doesn’t need to sound like your CTO. They just need to know what tool your team uses—and when someone’s off-guard enough to approve an “urgent access request.”

A phishing attack targeting MailerLite users has cost victims over $700,000, with major crypto brands caught in the fallout. Get the full story in our news coverage!

Phishing-as-a-Service Hits Your Wallet First

The scariest part? Many phishing pages today look better than the real thing.

The report highlights a surge in fake crypto exchanges and wallet clones, targeting unsuspecting users through:

  • SEO manipulation (search engine poisoning),
  • Fake Telegram bots,
  • Scam social ads offering “airdrops” or “upgraded features.”

These cloned sites capture private keys or login sessions, then drain funds. For newer users and solo traders, there’s no clear red flag—just the wrong link.

It’s a fundamental breakdown of interface trust. And as more crypto apps migrate to browser-based wallets, the surface grows faster than the defenses.

Donut chart showing most targeted industries for phishing in 2024, led by manufacturing, services, and education — The Coinomist
Breakdown of phishing targets by industry in 2024. Despite a 32.8% drop in attacks, tech and communication companies remain high-risk, while manufacturing and services lead as top targets. Source: zscaler.com

Fake AI Agents, Real Wallet Drains

As Web3 builders increasingly adopt generative AI tools (ChatGPT, Gemini, and open-source LLMs), they’re also becoming targets of a new kind of phishing: fake AI platforms.

The lure is simple:

  • “Access GPT-5 early,”
  • “Train your own bot,”
  • “Run on-chain AI with one click.”

One wrong download and your dev environment is compromised. The attackers don’t need to find your mnemonic, they just need a backdoor into the laptop that holds it.

According to ThreatLabz, these campaigns now spread via YouTube ads, X threads, and Discord invites. 

The attack is weaponized marketing, not a hack.

Match Systems has exposed the team behind the phishing app Angel Drainer, which stole $25 million from 35,000 users before shutting down. Dive into the full story in our news coverage!

One of the most interesting revelations in Zscaler’s 2025 report is that global phishing is down 20% year-over-year. That sounds like good news—until you look closer.

Phishing isn’t shrinking. It’s concentrating.

Attacks in 2024 focused on fewer targets with greater precision:

  • India overtook the UK in attack volume.
  • Germany and Canada saw major spikes.
  • In all five leading countries, tech companies were among the most hit.

Why? Because these are cloud-native markets with massive startup ecosystems. Crypto, fintech, AI, SaaS—it’s one big surface area. And no, your .xyz domain doesn’t make you invisible.

Phishing map showing top 10 targeted countries in 2024, led by the U.S. and India — The Coinomist
Global phishing heatmap from Zscaler’s 2025 report, highlighting the top 10 most targeted countries for phishing attacks—including the U.S., India, Germany, and Brazil. Source: zscaler.com

Zscaler’s View: Zero Trust, or Zero Chance

Zscaler isn’t just observing these shifts—it’s arguing for a response. The company frames phishing in 2025 as an AI arms race, where the only real defense is AI-powered Zero Trust architecture.

This means:

  • Inspecting encrypted traffic without decryption risks,
  • Validating device posture before granting app access,
  • Blocking suspicious AI interactions and spoofed domains in real time.

Organizations must leverage equally advanced AI-powered defenses to outpace these emerging threats,

says Desai.

For crypto teams, this means going beyond hardware wallets and browser extensions

It means securing the people layer. Because attackers already moved there.

Deepen Desai, CSO at Zscaler and head of global security research — The Coinomist
Deepen Desai, Chief Security Officer at Zscaler, leads the company’s global security research operations and cybersecurity innovation strategy. Source: zscaler.com

Torq has raised $70 million to expand its AI-driven cybersecurity solutions, as demand for automated defense grows among major clients like Procter & Gamble and PepsiCo. Get the full story in our news coverage!

The Smartest Hacks Don’t Touch Code

In crypto, we don’t trust. We verify.

But 2025 is testing that maxim. Not at the protocol level—but at the product, user, and founder level. Because the thing phishing exploits best isn’t your smart contract.

It’s your confidence.

And as Zscaler warns: the next breach probably won’t come through your backend. It’ll come through the front door. And will wear your brand colors and ask politely for access.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Senate Nears Consensus on GENIUS Act, Vote Expected Next Week

Senate Nears Consensus on GENIUS Act, Vote Expected Next Week

Updates to the GENIUS Act, aimed at regulating stablecoins, include new provisions on national security and ethics. The Senate is preparing to bring the bill to a vote next week.

Dmytro Psevdonimenko
Méliuz Launches Bitcoin Treasury Strategy Amid Business Overhaul

Méliuz Launches Bitcoin Treasury Strategy Amid Business Overhaul

Shifting gears toward a crypto-first identity, Méliuz is relaunching with plans to become a Bitcoin treasury powerhouse in Latin America.

Anton Kryshtal
Atkins Outlines SEC’s New Crypto Framework

Atkins Outlines SEC’s New Crypto Framework

On May 12, 2025, SEC Chair Paul Atkins introduced a new regulatory strategy for digital assets, with a focus on tokenization, custody, and crypto trading practices.

Vlad Vovk
DDC Enterprise Unveils 3-Year Plan to Hold 5,000 BTC

DDC Enterprise Unveils 3-Year Plan to Hold 5,000 BTC

DDC Enterprise (NYSEAM: DDC) has committed to building a 5,000 BTC reserve, beginning with a 100 BTC purchase and a 36-month accumulation plan.

Vlad Vovk
Monica Long: How Ripple’s Quiet Force Is Redrawing Crypto’s Map

Monica Long: How Ripple’s Quiet Force Is Redrawing Crypto’s Map

Ripple’s Monica Long isn’t chasing headlines—she’s quietly building crypto’s future. From payments to tokenization, here’s how she’s reshaping finance from the inside.

Elina Moskovchuk
Top Crypto Tweets Today: Zerebro Dev Reveals He Faked His Suicide

Top Crypto Tweets Today: Zerebro Dev Reveals He Faked His Suicide

The biggest mystery in today’s Twitter/X recap is Zerebro dev Jeffy Yu, who claimed to take his life on a Pump.fun stream – but later said he faked the video to stop harassment.

Anahit Avetisyan
Top Crypto Tweets Today: Samourai Case, Curve X Hack & More

Top Crypto Tweets Today: Samourai Case, Curve X Hack & More

DOJ prosecutors reportedly suppressed key evidence in the Samourai Wallet case. Crypto lawyer Zack Shapiro shared the defense team’s hearing request on X.

Anahit Avetisyan
What Is Bitcoin Knots, a Fork by Luke Dashjr?

What Is Bitcoin Knots, a Fork by Luke Dashjr?

Bitcoin Knots (formerly Bitcoin LJR) is an alternative to Bitcoin Core, both allowing network participants to interact with the Bitcoin blockchain.

Anahit Avetisyan
How to Buy New Crypto Before Listing: A Step-by-Step Guide

How to Buy New Crypto Before Listing: A Step-by-Step Guide

Buying a cryptocurrency before it’s listed publicly has become one of the most talked-about strategies in the space, offering the potential for major upside—if done carefully.

The Coinomist
The Rise and Fall of Web3 Darlings: A Guide to Crypto Longevity

The Rise and Fall of Web3 Darlings: A Guide to Crypto Longevity

Most Web3 projects don’t collapse—they just stop being talked about. What makes one protocol a star and another a ghost? And why, in crypto, silence might signal transformation rather than failure?

Vlad Vovk
Beyond Profits: Understanding the Spiritual Side of Trading

Beyond Profits: Understanding the Spiritual Side of Trading

Are spiritual habits the missing link in trading psychology? For many, mindfulness and reflection offer a buffer against stress, reduce snap decisions, and aid in staying grounded through market volatility.

Vlad Vovk
How Cryptocurrency and Its Owners Are Tracked

How Cryptocurrency and Its Owners Are Tracked

Think blockchain is private? Wallets have no names and transfers seem untraceable — but that’s misleading. Discover how experts uncover wallet owners and link identities to transactions.

Vlad Vovk
The State of Crypto Regulation in 2025: Where the World Stands

The State of Crypto Regulation in 2025: Where the World Stands

A wave of regulation is sweeping the crypto world in 2025. From Washington to Brussels to Singapore, governments are setting new ground rules. What’s at stake for crypto’s next chapter?

Daryna Nesterenko
Bitcoin Retests $101K as Market Consolidation Holds

Bitcoin Retests $101K as Market Consolidation Holds

BTC remains range-bound between $101,000 and $105,000 as the market waits for new catalysts. Despite the pause in momentum, the leading cryptocurrency continues to show underlying strength.

Anton Kryshtal
Bitcoin Retreats Toward $101,000 Amid Mounting Sell-Side Pressure

Bitcoin Retreats Toward $101,000 Amid Mounting Sell-Side Pressure

Bitcoin loses ground despite notable net inflows into spot ETFs, signaling a bearish short-term trend.

Anton Kryshtal
MORE
Earning by Habit: How Crypto Weaves into Everyday Actions

Earning by Habit: How Crypto Weaves into Everyday Actions

You can now earn crypto tokens for your most routine daily habits — shopping, working out, or grabbing breakfast at a café. But how does it actually work?

Yara Zornell
Valletta: How Blockchain Became a Growth Engine for the Island of the Hospitallers

Valletta: How Blockchain Became a Growth Engine for the Island of the Hospitallers

Malta attracts crypto companies from around the world — flexible regulation, low taxes, and a prestigious European jurisdiction have turned the small city of Valletta into a land of opportunity.

Iaroslava Kramarenko
MORE