Security and Privacy Challenges in Web 3.0: A Survey of Threats, Authentication Mechanisms, and Open Problems
Abstract
Web 3.0 is a paradigm shift in the design of the Internet, from centralized platform custodians to decentralized blockchain-based infrastructures and user empowered data models. This results in a new and dynamic threat landscape including social engineering, smart-contract exploitation, cryptojacking, identity abuse and data-reliability failures, which existing security frameworks only address in part. This paper provides a comprehensive survey on the security and privacy issues of Web 3.0. We systematically review the dominant attack classes. We review the current state of decentralized authentication mechanisms including publicprivate key schemes, Decentralized Identifiers (DIDs) and Verifiable Credentials. We synthesize findings from ten recent studies to identify recurring gaps. In particular, the unresolved tension between user anonymity and network accountability has repeatedly been identified as an open problem in the literature. We characterize this gap, classify proposed mitigations, and identify areas for future research. The objective of this survey is to offer a structured reference for researchers and practitioners who are developing security-aware decentralized applications.