September 2025
Intermediate to advanced
640 pages
19h 47m
English
Threat Scenario TS1 Malicious actors targeting critical processes and assets in a dApp’s mobile UI and associated components.
| Threat ID | Threat event | Threat description | Threat agents | Attack vectors | Assets targeted | Threat impacts | Countermeasures and risk mitigation strategies |
|---|---|---|---|---|---|---|---|
| T1 | Exploitation of authentication and session management flaws | Weak authentication mechanisms or stolen session tokens allow unauthorized access or actions. | Malicious users, external attackers | Phishing attacks, stolen credentials, session hijacking | User accounts, authentication tokens | Unauthorized access to accounts or execution of fraudulent transactions | Implement strong authentication (e.g. MFA), secure session management, and token integrity checks. |
| T2 | Data tampering at the mobile UI boundary | Malicious actors alter data inputs or manipulate transaction payloads between the user and mobile UI. | Malicious users, external attackers | Input manipulation, malicious payload injection | Transaction payloads, input data | Corruption of data, compromised transactions, and loss of trust | Validate inputs, encrypt data in transit, and use secure communication protocols. |
| T3 | Information disclosure through insecure communication | Sensitive data is exposed due to unencrypted communication or weak encryption protocols. | External attackers, advanced persistent threats | Eavesdropping on communication, exploiting weak encryption | Data in transit between user and mobile UI | Data breaches and exposure of sensitive user information ... |
Read now
Unlock full access