September 2025
Intermediate to advanced
640 pages
19h 47m
English
Threat Scenario TS1 Malicious actors targeting critical processes and assets in a dApp’s mobile UI and associated components.
| Weakness targeted (CWE) | Weakness description | Severity risk | Asset impacted | Attack vectors |
|---|---|---|---|---|
| CWE-287 | Improper authentication | 9.8 (critical) | Mobile or browser client/UI | Phishing attacks, stolen credentials, session hijacking |
| CWE-359 | Exposure of private information | 8.8 (high) | Mobile or browser client/UI | Intercepting unprotected communication or insecure data storage |
| CWE-1104 | Use of unmaintained third-party components | 7.8 (high) | Mobile or browser client/UI | Exploiting vulnerabilities in outdated libraries or frameworks |
| CWE-20 | Improper input validation | 7.5 (high) | Mobile or browser client/UI | Manipulating input data to bypass validation checks |
| CWE-922 | Insecure storage of sensitive information | 4.7 (medium) | Mobile or browser client/UI | Accessing sensitive data in local storage without encryption |
| CWE-104 | Excessive logging | 2.0 (low) | Mobile or browser client/UI | Accessing sensitive information from improperly sanitized debug logs |
| Threat Scenario TS2: Malicious actors targeting critical processes and assets in a dApp’s interaction with digital wallets and associated components exploit vulnerabilities in authentication, transaction integrity, API security, and external services like oracles. | ||||
| CWE-287 | Improper authentication | 9.8 (critical) | Digital wallet/smart contracts | Phishing, credential theft, session hijacking |
| CWE-284 | Improper access ... | |||
Read now
Unlock full access