Close Menu
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Market Cap
  • Blockchain
  • Web 3
    • NFT
    • Metaverse
  • Regulation
  • Analysis
  • Learn
  • Blog
What's Hot

Bitmine expands Ethereum Treasury to 5.7 million ETH after latest purchase

2026-06-30

AIPOCH Launches MedSkillAudit, an AI Audit Framework to Evaluate the Skills of AI Medical Agents Before Deployment

2026-06-30

Tron – Why TRX’s $1.96T stablecoin boom still faces ONE challenge

2026-06-30
Facebook X (Twitter) Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
Facebook X (Twitter) Instagram
Bitcoin Platform – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Market Cap
  • Blockchain

    What is real-world asset tokenization? RWAs on the blockchain explained

    2026-06-29

    BNB Chain Reaches $5 Billion in Tokenized Shares – What Does This Mean for Investors?

    2026-06-29

    British asset manager Baillie Gifford launches tokenized bond fund on Ethereum and Solana

    2026-06-29

    Token Terminal Announces Data Partnership with Sui Network

    2026-06-29

    Canton Network Tops the Blockchain Cost Rankings with $60 Million in 30 Days

    2026-06-28
  • Web 3
    • NFT
    • Metaverse
  • Regulation

    What states can still do with crypto after GENIUS and CLARITY

    2026-06-29

    Ripple’s MiCA win is not yet a full license

    2026-06-28

    Congress is blocking the introduction of CBDC in the next four years

    2026-06-28

    European crypto users are paid to move before MiCA closes its doors

    2026-06-27

    The UK has softened stablecoin rules but may still restrict its own market

    2026-06-27
  • Analysis

    MSTR jumps after Strategy says it may sell more Bitcoin to fund dividends and buybacks

    2026-06-29

    Bitcoin’s $60,000 Breakdown Causes a Volatility Shock as Traders Focus on Downside Hedging

    2026-06-29

    Waarom een ​​ineenstorting van de hausse aan AI-uitgaven van $1 biljoen Bitcoin-handelaren als eerste zou kunnen treffen

    2026-06-29

    Polymarket’s $3.3 Billion World Cup Explosion Exposes the Pitfall of Prediction Markets

    2026-06-29

    Bitcoin has just dipped below the bear market line that traders cannot ignore

    2026-06-28
  • Learn

    Bull Trap in Crypto: How False Breakouts Trap Traders

    2026-06-29

    Bear Trap in Crypto: False Breakdowns Explained

    2026-06-29

    What Is the Evening Star Candlestick Pattern in Crypto?

    2026-06-29

    Most Profitable Crypto to Mine in 2026: Best Altcoins for Mining

    2026-06-23

    Bitcoin Alternatives: Our Top Altcoin Picks for You in 2026

    2026-06-23
  • Blog
Bitcoin Platform – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
Home»Web 3»How to solve the blockchain infrastructure security problem while creating a dApp
Web 3

How to solve the blockchain infrastructure security problem while creating a dApp

2023-05-14No Comments7 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The race for WEB3 is on. Venture capitalists, cryptocurrency startups, engineers and visionaries are developing WEB3 (or Web 3.0) powered by blockchain. A new frontier emerged, more democratic, decentralized, independent and ideal for data recovery.

But is everything so perfect when it comes to decentralization and security of infrastructures? No, and countless cases of man-in-the-middle attacks are proof of that.

But to solve the security problem, let’s remember what WEB3 is. The core concept of WEB3 is to solve the security problems caused by centralization and give people authority over their data and identification. So at what technology level are these unfortunate incidents of security breaches happening in your blockchain infrastructure? Let’s figure it out.

To focus on the internal aspects of WEB3, technologies such as EVM, Solidity and JavaScript still play a major role. However, we use Node providers and WEB3 API providers when discussing backend functions.

Node providers are companies that allow you to use their services instead of managing your nodes. This is very useful because instead of setting up your node and experiencing all the stress and costs that come with it, you can send your dApp transaction requests over the internet to the node provider. If you are interested in smart contract development, you can use one or two node providers (for redundancy).

There are many WEB3 API providers; However, in many cases these companies work with nodes behind the scenes. With these tools applied, you can get all the pre-compiled and pre-calculated data in the chain.

In addition, it is easy to establish reliable communication and interaction between different applications through these WEB3 APIs. In addition, quality APIs ensure that the coding remains consistent and stable. That’s why we rely most on reliable WEB3 APIs when building applications.

💡 Difference between Node providers and WEB3 API providers: The WEB3 provider allows your application to communicate with a blockchain node by making JSON-RPC requests to a server. Node service providers run distributed node clients behind the scenes, letting them write to and read from a blockchain using an API key.

See also  PayPal redeels messages with crypto and cash payment connections

What is the security threat to dApps developers?

Nodes are still relatively primitive technologies, but they are still valuable. For example, a WEB3 node cannot tell you what users have deposited into their accounts. Beyond simply providing raw blockchain information, nodes cannot process multiple smart contracts. In addition, nodes have limited capabilities and can only process one chain. Fortunately, APIs are available to help you get around this limitation.

APIs define and standardize application interactions so you can use raw blockchain data. This is why WEB3 APIs are useful for dApp development. WEB3 APIs are a key component in dApp development; they not only provide a simple interface, but also allow a piece of software to communicate with other applications. Because reliable APIs enable consistent coding in a stable environment, dApp developers don’t have to reinvent the wheel.

In addition, by using these WEB3 provider APIs, you can easily link nodes. Therefore, you don’t have to worry about connecting to nodes when using these APIs. When you interact with these providers, you may also receive a variety of valuable pre-calculated and pre-compiled on-chain data.

But such services do not completely exclude developers’ requests in the security plans, and in most cases you have to pay upfront for using them.

The fact is that there are more and more cases where dApps are hacked using the man-in-the-middle attack mentioned above.

This is when an attacker, using vulnerabilities in DNS servers (for example), switched servers to serve traffic from jsonrpc endpoints.

One victim is known have lost 16.5 WBTC (~$350,840). And about 23 cryptocurrency projects have already encountered a similar DNS attack.

With a very simple solution, you can protect yourself against such man-in-the-middle attacks. And we will come back to this.

And if you have a development team, you can go your own way and try to build your solution, but you need a super-skilled team of like-minded people to make it work.

See also  When will web3 have its Apple moment?

The difficulty of this process is that you can significantly overestimate your strength. A task that seems simple then raises many questions, which are solved by years of experience in one’s work. Therefore, if you have a lot of time and resources, you should accept this path.

Violation of 3 major blockchain principles in the WEB3

So now let’s take a deep breath and look at the current security challenges in the WEB3 world from an infrastructure perspective.

The main principles of blockchain are

  • decentralization
  • transparency
  • trustlessness

But does it work in practice? Have a look at the most popular dApp architecture.

Most popular dApp architecture
Most popular dApp architecture

We can see users on the front end sending requests to JSON-RPC providers (could be Infura, Alchemy, Quicknode, etc.).

So the requests are forwarded to a shared environment where we have no control over the data transformation at the API gateway, caching engine, blockchain nodes or anything else.

And this is where the first problem arises because a shared environment means that many users, especially bots and hackers, work in the same environment. This is a real black box for the developer that draws too much attention from attackers.

Well, this approach contradicts all 3 principles of WEB3 because:

  1. It centralizes access to the Blockchain, with everything passing through a shared environment;
  2. It’s not transparent – we can’t verify the answers from such an API;
  3. Therefore, it cannot be called true distrust, as the security problems of such an infrastructure are simply based on trust. See for yourself in the following diagram.
problems with the dApp architecture
problems with the dApp architecture

The second problem is that the described infrastructure version enables man-in-the-middle attacksthat criminals periodically use.

The following services can be attacked:

    • Domain or DNS registrars
    • JSON-RPC providers
    • All aggregated third-party services

A self-hosted cluster of blockchain nodes is the only solution

But is there a solution? Yes — configured on-premises environment.

First, it uses a self-hosted cluster of blockchain nodes. All nodes are initialized from the official genesis and synchronized using p2p. This ensures data consistency.

See also  Nigeria's SPPG is implementing the country's first blockchain certificate system

Nodes should be periodically updated with fewer snapshots to run at peak efficiency. The ideal solution is to automatically create new nodes from the resized snapshot while zooming. If you initialize the node from scratch, this approach can get you a new node in 30 minutes instead of several days.

Another critical point is the automatic update of the blockchain software after its release – this can also be done. The most important thing is to take a snapshot with the new version (as sometimes it may require some data operations, which may take some time), and then the new nodes should automatically start with the new snapshot and updated software.

Below is an infrastructure diagram that solves most of the problems described.

dApp infrastructure solution
dApp infrastructure solution

It is also important to monitor the sync status and exclude the nodes that are behind the upstream stream. This can be done, for example, with the help of health checks.

In addition to the fact that access can be restricted by IP address, it’s worth noting that the good old JWT token can protect against domain registrars or DNS attacks. JWT token is easy to integrate into web3js and other libraries and must be deployed on the API gateway side in our blockchain cluster.

In this way we make the blockchain endpoint secure and decentralized.

Sum up

Web3 is still in its infancy. But the race for decentralization has already begun. And you will see that the most secure applications are probably the most innovative and open-source approaches.

And that’s why you shouldn’t ignore the basics of WEB3, because then your newly created dApp won’t provide security to other participants. The only option currently available is one autonomous cluster of geo-distributed blockchain nodes.

Author:

Daniel Yavorovich

Co-founder and CTO at RPCSfast And Dysnix



Source link

Blockchain creating dApp infrastructure problem Security solve
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

AIPOCH Launches MedSkillAudit, an AI Audit Framework to Evaluate the Skills of AI Medical Agents Before Deployment

2026-06-30

Beach Day API launches real-time beach and ocean data API for developers

2026-06-29

Vadzo Imaging Positions Falcon-1335CRO AR1335 OIS Autofocus USB Camera with On-board 9-Axis IMU for Head-Mounted and Wearable Vision Applications

2026-06-29

What is real-world asset tokenization? RWAs on the blockchain explained

2026-06-29
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ledger Recover: Is Your Seed Phrase Really Safe?

2023-05-17

Arbitrum Expands AI Infrastructure with ERC-8004 and Onchain Identity

2026-02-08

Edward Snowden calls Bitcoin ‘the most important thing’ in this area

2024-02-19
Editors Picks

Dione Protocol Partners with Welffinance to stimulate the adoption of mass blockchain

2025-03-19

Bitcoin price could rebound back to $107,000 if this key level is broken

2024-12-24

Rabby Wallet integrates IOTA EVM

2024-06-16

Solana Price (SOL) Drops: Will a Break Below $140 Cause More Downsides?

2024-08-29

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Cryptocurrencies, Defi, NFT, Metaverse and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitmine expands Ethereum Treasury to 5.7 million ETH after latest purchase

AIPOCH Launches MedSkillAudit, an AI Audit Framework to Evaluate the Skills of AI Medical Agents Before Deployment

Tron – Why TRX’s $1.96T stablecoin boom still faces ONE challenge

Get Informed

Subscribe to Updates

Get the latest news and Update from Bitcoin Platform about Crypto, Metaverse, NFT and more.

  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
© 2026 Bitcoinplatform.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.