Exploring User Perceptions of Security Auditing in the Web3 Ecosystem

Molly Zhuangtong Huang (University of Macau)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Privacy & Usability 1 · Privacy & Usability 1

Overview

In an era defined by rapid technological advancement and increasing decentralization, the Web3 ecosystem has emerged as a transformative force, promising users greater control over their data and interactions through blockchain technology. However, this burgeoning landscape is not without its perils. Despite its rapid growth and appeal to millions globally, Web3 is frequently plagued by significant security incidents, leading to substantial financial losses for users. To counter these pervasive threats, a variety of security solutions have surfaced, with security auditing standing out as a crucial and increasingly prominent mechanism. This talk, presented by Molly Zhuangtong Huang from the University of Macau, delves into an often-overlooked dimension of Web3 security: the user's perception of these auditing processes.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to Web3 and its security challenges
  2. 1:30 Defining security auditing and its function in Web3
  3. 2:48 Overview of the study's research questions and methods
  4. 3:51 Key finding: Users perceive audit information as insufficient
  5. 4:48 Key finding: Users question auditing effectiveness and impartiality
  6. 7:00 Key finding: Audits have limited impact but aid education
  7. 8:07 Discussing challenges: decentralization, regulation, technical complexity
  8. 10:00 Design implications and recommendations for users and auditors

Exploring User Perceptions of Security Auditing in the Web3 Ecosystem

Speakers: Molly Zhuangtong Huang (University of Macau)

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=jCzL6D4tEas

Overview

In an era defined by rapid technological advancement and increasing decentralization, the Web3 ecosystem has emerged as a transformative force, promising users greater control over their data and interactions through blockchain technology. However, this burgeoning landscape is not without its perils. Despite its rapid growth and appeal to millions globally, Web3 is frequently plagued by significant security incidents, leading to substantial financial losses for users. To counter these pervasive threats, a variety of security solutions have surfaced, with security auditing standing out as a crucial and increasingly prominent mechanism. This talk, presented by Molly Zhuangtong Huang from the University of Macau, delves into an often-overlooked dimension of Web3 security: the user's perception of these auditing processes.

The research presented addresses a critical gap in existing literature, which has predominantly focused on the technical intricacies of Web3 security while largely neglecting the human element—how users understand, trust, and interact with security auditing information. Huang’s work explores three core research questions: how users perceive security information from Web3 auditing, their views on auditing's role in enhancing security, and its impact on their interactions with Web3 applications. By employing a mixed-methods approach encompassing case studies of auditing firm disclosures, interviews with 20 Web3 users, and sentiment analysis of online community discussions, the study uncovers nuanced and often contradictory user sentiments, providing invaluable insights for both the auditing industry and the broader Web3 community.

The findings underscore a fundamental disconnect between the intended purpose of security auditing—to instill confidence and mitigate risk—and its actual reception by the user base. The research highlights issues ranging from insufficient information disclosure and skepticism regarding auditor impartiality to the limited tangible impact on user security decisions. This exploration is particularly timely as Web3 continues to mature, emphasizing the urgent need for auditing firms and the ecosystem at large to reconsider current practices to foster genuine user trust and effectively enhance security.

Background

▶ Watch: Introduction to Web3 and its security challenges (0:00)

The Web3 ecosystem, built upon blockchain technology, represents a paradigm shift towards decentralization, empowering users with enhanced autonomy over their digital assets and online interactions, free from reliance on central authorities. This vision has resonated with millions, driving rapid adoption and innovation across various sectors. However, this nascent ecosystem also faces an escalating challenge: pervasive and costly security vulnerabilities. As illustrated by frequent security incidents and significant financial losses, the decentralized nature of Web3 introduces novel attack vectors and complexities that traditional security models struggle to address.

In response to these pressing security concerns, a specialized industry of security auditing firms has rapidly materialized. These firms are tasked with conducting external, independent assessments of Web3 applications, particularly smart contracts, to identify and remediate potential vulnerabilities. The culmination of this process is typically a public audit disclosure or auditing report, which is made available on both the audited application's website and the auditing firm's own homepage. Beyond simply identifying flaws, many of these firms also actively contribute to the broader Web3 security landscape by reporting on significant security incidents and disseminating technical knowledge through their websites and social media channels, aiming to educate the community and elevate overall security posture.

Despite the proliferation of these auditing services, a critical question remains: Is this security auditing sufficient to truly secure Web3, particularly from the user's perspective? Prior academic and industry research has predominantly concentrated on the technical aspects of blockchain security, such as cryptographic vulnerabilities, protocol design flaws, or smart contract logic errors. Comparatively little attention has been paid to the user security dimension—how end-users perceive, interpret, and act upon the information provided by these auditing efforts. This oversight creates a significant gap, as the ultimate goal of security measures is to protect users and foster their trust. Molly Huang's research directly addresses this lacuna, aiming to understand the multifaceted user perceptions of security auditing, thereby providing a more holistic view of its effectiveness and challenges within the Web3 ecosystem.

Key Findings

▶ Watch: Overview of the study's research questions and methods (2:48)

Molly Huang's research employed a rigorous mixed-methods approach to uncover user perceptions of security auditing in Web3. The methodology included:

  1. Case Study: An analysis of information disclosure practices on the websites of top Web3 auditing firms, selected based on their engagement with the top 15 Web3 applications.
  2. User Interviews: In-depth discussions with 20 Web3 users to gather qualitative insights into their experiences and opinions.
  3. Online Community Analysis: Sentiment analysis of discussions related to Web3 auditing on platforms like Reddit, providing a broader quantitative and qualitative view of community attitudes.

Through these methods, several key findings emerged, structured around the three primary research questions:

1. User Perception of Security Information from Web3 Auditing:

Users overwhelmingly reported that the information disclosure from Web3 auditing firms is insufficient. This insufficiency manifests in two primary ways:

  • Lack of Comprehensiveness: Users found it difficult to ascertain crucial details such as "who is responsible for the security auditing" and "how was their performance in the past." This lack of transparency regarding auditor identity and track record hinders users' ability to assess the credibility and reliability of the audit.
  • Lack of Depth: Many users reported that "important details are missing" from audit reports. While reports may exist, they often lack the granular information necessary for users to fully understand the scope of the audit, the vulnerabilities identified, or the mitigation strategies implemented.

2. User Perception of the Role of Web3 Auditing in Enhancing Security:

The study found that user attitudes towards the role of Web3 auditing in enhancing security are highly varied, with a slight lean towards negative sentiments observed in online community discussions.

  • Questioning Effectiveness: A significant reason for skepticism is the observation that "audited applications still experience attacks." This leads users to question "whether the security auditing can truly protect the application," undermining confidence in the auditing process itself.
  • Questioning Independence and Impartiality: Users raised concerns about the auditing firms' independence, particularly noting that "money in responsible auditing protests" (referring to the financial relationship between audited projects and auditing firms) often fails to meet their expectations of impartiality. This perceived conflict of interest leads to a lack of trust, with the research concluding that "auditing phones currently lack of reputations as most of us can net a trust was one."
  • Appreciation of Value (with reservations): Despite the widespread skepticism, a segment of users still "appreciate its value." They believe that security auditing can "help reduce the minimize the smart contract vulnerability and enhancing the security of the application." Many also perceive it as "a proof for the applications security efforts," especially considering the financial cost involved in obtaining an audit.
  • Lack of Strong Backing for Positive Views: Crucially, the positive perceptions often "lack of strong backing." Users had difficulty knowing the "specific specific cause of the security auditing," as most firms "do not provide information about price" or simply state "the price depends on workload and without specific receiving any figures." This lack of transparency around cost further erodes trust and makes it difficult for users to gauge the true value or effort behind an audit.

3. User Perception of the Impact of Web3 Auditing on Their Interactions:

The research indicated that security auditing has a limited impact on users' security decisions. Users typically "just simply check if the application is audited and do not really take ES very seriously." This suggests a superficial engagement with auditing information, where the presence of an audit acts more as a basic checkbox rather than a trigger for deep scrutiny or informed decision-making.

  • Role in Security Education: Nevertheless, security auditing plays an "important role in security education within the Web3 ecosystem." Many users reported that they "have learned some technical professional knowledge from the security report." While not directly influencing their immediate security decisions in a profound way, the reports serve as valuable educational resources, helping users gradually build their understanding of Web3 security concepts.

In summary, the key findings paint a picture of a Web3 security auditing landscape struggling with transparency, trust, and effectiveness from the user's vantage point. While recognized for its educational potential, its direct impact on user security decisions is minimal due to insufficient information, perceived conflicts of interest, and a general lack of clarity surrounding the auditing process.

Technical Deep Dive

▶ Watch: Key finding: Users question auditing effectiveness and impartiality (4:48)

While Molly Huang's talk primarily focuses on the sociological and psychological aspects of user perception rather than a deep dive into specific code vulnerabilities or protocol architectures, the underlying technical complexities of Web3 form the crucial backdrop against which these perceptions are shaped. The research identifies several unique characteristics of Web3 that pose significant challenges for effective security auditing and user understanding, directly influencing the findings discussed previously.

The first fundamental characteristic is decentralization. Web3's foundation on blockchain technology grants users unprecedented autonomy but simultaneously distributes security responsibility, often placing a greater burden on individual users. In a trust-less community—a core tenet of blockchain—users naturally possess "more hider explanation on the impartiality of the web auditing practice." This inherent skepticism is exacerbated by the lack of centralized oversight, making it harder for users to verify the independence and integrity of auditing firms. The technical design of decentralized networks, while offering resilience against single points of failure, also means that security vulnerabilities can have widespread and irreversible consequences, increasing the stakes for auditing effectiveness.

Secondly, the lack of regulations in the nascent Web3 ecosystem significantly impacts security auditing. Unlike traditional financial or software industries, Web3 operates largely in an unregulated or under-regulated environment. Security auditing is emerging as a "potential regulatory tool" to help users navigate this space. However, this places immense pressure on the auditing industry to "maintain high standards" voluntarily. Without established regulatory frameworks or independent bodies to enforce best practices, the industry risks "irresponsible auditing practice[s]" that can "damage these reputations" and "undermine user trust." Technically, this means that there are no standardized requirements for audit scope, methodology, or disclosure, leading to the inconsistent and insufficient reporting identified in the study. Auditors are not compelled to disclose specific details about their process, their past performance, or their pricing, contributing to the "lack of comprehensiveness" and "depth" in audit reports.

Finally, the technical complexity of blockchain and Web3 applications presents a formidable barrier for the average user. While revolutionary, concepts like smart contracts, cryptographic principles, and decentralized finance (DeFi) protocols are inherently intricate. Security auditing aims to "bridge this gap by translating the technical terms into accessible report for users." However, the research highlights a persistent problem: how to "balance the profession with reability especially considering the users's diverse knowledge level in the web3 ecosystem." For instance, as pointed out in the Q&A, an audit report might have a critical disclaimer like "this contract supports upgradability so nothing in this audit report means anything" buried in a single line at the end. While technically accurate, such nuanced details are often lost on non-technical users, rendering the audit "useless" from their perspective. Even technically proficient users might struggle with the sheer volume and complexity of codebases, making a thorough personal audit impractical or impossible. The challenge lies in distilling highly technical findings into digestible, actionable information without oversimplifying or omitting crucial caveats. This delicate balance is often not achieved, leading to user confusion and a superficial understanding of audited status.

In essence, while the talk doesn't dissect smart contract code, it critically examines the interface between complex Web3 technology and human understanding. The technical characteristics of decentralization, regulatory vacuum, and inherent complexity create an environment where security auditing, despite its intent, struggles to effectively communicate risk and build trust with a diverse user base.

Demo / Proof of Concept

▶ Watch: Key finding: Audits have limited impact but aid education (7:00)

The talk "Exploring User Perceptions of Security Auditing in the Web3 Ecosystem" presented a comprehensive research study and its findings. It did not include a live demonstration or a proof of concept of any technical exploit, auditing tool, or security mechanism. The methodology focused on qualitative and quantitative analysis of user perceptions and existing audit disclosures rather than the development or showcasing of new technical artifacts.

Defensive Implications

▶ Watch: Design implications and recommendations for users and auditors (10:00)

The findings from Molly Huang's research carry significant defensive implications for various stakeholders within the Web3 ecosystem, aiming to bridge the gap between technical security measures and user trust and understanding. These implications extend to individual users, auditing firms, and the broader Web3 community.

For Individual Web3 Users:

  • Leverage Communities for Technical Understanding: Given the technical complexity of Web3 and the often insufficient depth of audit reports, users are encouraged to "leverage communities for technical understanding." Online forums, specialized groups, and educational platforms can serve as valuable resources to discuss audit findings, clarify technical jargon, and gain a more comprehensive understanding of application security beyond a superficial "audited" label. This fosters a more informed user base capable of making better security decisions.
  • Move Beyond Superficial Checks: Users should be educated to go beyond merely checking "if the application is audited." While an audit is a positive indicator, its presence alone does not guarantee absolute security. Users should be encouraged to seek out and understand the specifics of the audit, including the scope, findings, and the reputation of the auditing firm.

For Web3 Auditing Firms:

The research highlights a critical need for auditing firms to re-evaluate their practices to enhance transparency, build trust, and cater to a diverse user base:

  • Balance Information Presentation: Firms must "balance the information present presentations" to cater to the "users's diverse knowledge level." This implies a multi-layered approach to reporting:
  • Simple Summaries: Provide concise, easily digestible summaries for average users who need a quick overview of security posture and key risks.
  • Detailed Technical Reports: Offer comprehensive, in-depth technical reports for users with a strong computer science or blockchain background who wish to scrutinize specific vulnerabilities, code changes, and mitigation strategies. This could involve making specific findings more accessible for technical users, as suggested in the Q&A.
  • Implement Trust-Building Measures: To address concerns about independence and impartiality, firms should "take some trans build measures." This includes:
  • Transparent Disclosure of Methodology: Clearly outlining the audit scope, methodologies, and limitations.
  • Auditor Biographies and Experience: Providing information about the auditing team's expertise and track record.
  • Performance Transparency: Publicly sharing success rates or post-audit incident data (where appropriate and privacy-compliant) to build a verifiable reputation.
  • Clear Pricing Structures: Being transparent about audit costs, moving beyond vague statements like "depends on workload," to help users understand the investment and scope of the audit.
  • Standardization of Reports: As suggested in the Q&A, there's a strong need for "some type of standardization around the father reports." This would ensure consistency in reporting formats, the types of information disclosed, and the clarity of disclaimers (e.g., about upgradability), making it easier for users to compare audits and understand their implications across different projects.
  • Proactive Education: Auditing firms, recognized for their role in security education, should embrace this responsibility more proactively. They can provide educational content that explains common smart contract vulnerabilities, best security practices, and how to interpret audit reports effectively.

For the Broader Web3 Ecosystem:

  • Foster a Culture of Transparency: The ecosystem needs to collectively push for greater transparency from all participants, especially those providing critical security services. This includes encouraging projects to select reputable auditors and to clearly present audit findings on their platforms.
  • Develop Industry Standards and Best Practices: Without formal regulation, industry-led initiatives to establish standards for security auditing—covering scope, disclosure, and ethical conduct—become paramount. This could involve collaborations between auditing firms, blockchain foundations, and user advocacy groups.
  • Prioritize User-Centric Security Design: The development of Web3 applications should inherently consider user understanding and security decision-making. This means not just building secure systems, but also building systems where the security posture is clearly and reliably communicated to the end-user.

By addressing these defensive implications, the Web3 ecosystem can move towards a more robust security posture that is not only technically sound but also genuinely trusted and understood by its millions of users.

Key Takeaways

  • Insufficient Information Disclosure: Web3 security auditing suffers from a critical lack of transparency, with users reporting insufficient comprehensiveness regarding auditor identity and past performance, and a lack of depth in the details provided within audit reports.
  • Varied and Skeptical User Attitudes: User perceptions of Web3 auditing's effectiveness are mixed, with a slight leaning towards negative sentiment primarily due to audited applications still experiencing attacks and concerns about the independence and impartiality of auditing firms, often linked to financial incentives.
  • Limited Impact on Security Decisions: While audits are acknowledged as a "proof of security efforts," their impact on users' actual security decisions is minimal; most users only superficially check for an audit's existence rather than deeply engaging with its findings.
  • Crucial Role in Security Education: Despite skepticism about its direct protective value, security auditing plays an important role in the Web3 ecosystem by serving as a valuable educational resource, helping users learn technical knowledge from audit reports.
  • Web3 Characteristics Pose Challenges: The unique characteristics of Web3—namely decentralization, a lack of robust regulation, and inherent technical complexity—create significant challenges for effective security auditing and for communicating security posture to a diverse user base.
  • Urgent Need for Transparency and Standardization: Auditing firms must enhance transparency regarding their processes, performance, and pricing, and actively work towards balancing professional detail with readability. Industry-wide standardization of audit reports is essential to build trust and enable users to make more informed security decisions.

About the Speaker(s)

Molly Zhuangtong Huang is a researcher from the University of Macau. Her work focuses on exploring user perceptions within the Web3 ecosystem, particularly concerning security auditing. The research presented at the NDSS Symposium, "Exploring User Perceptions of Security Auditing in the Web3 Ecosystem," exemplifies her contribution to understanding the human factors influencing security and trust in decentralized environments.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

User study on perceptions of Web3 auditing. Methodologically thin — 20 interviews and Reddit sentiment analysis — and the findings amount to 'users don't read audit reports carefully and don't fully trust them,' which anyone who has spent a week in this space already knows. The recommendations are generic enough to apply to any nascent industry with trust problems.

Heather Calloway (CISO) — WEAK

Solid academic work on a real gap — user perception of Web3 security auditing — but it stops well short of the institutional and governance implications that would make it actionable for security leaders. Twenty user interviews and Reddit sentiment analysis is a thin foundation for the weight the conclusions want to carry.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025