Attack Surface

Last Updated Sep 24, 2026

In One Sentence

An attack surface is the set of interfaces and exposure points through which a system could be accessed, influenced, or have information extracted.

Definition

An attack surface describes where a system can be interacted with in ways relevant to security. It includes more than publicly visible application screens. For a crypto service, relevant points may include smart contract functions, administration tools, wallet integrations, APIs, dependencies, signing devices, and recovery processes. A surface is not itself a vulnerability; it is an area where weaknesses might be present or introduced.

How It Works

Adding an integration, permission, service endpoint, or privileged role can create new paths that need assessment. A small front end may depend on many external systems, while a larger system may have well-contained interfaces. Simple counts of features or lines of code therefore cannot determine overall risk. Threat modeling relates exposed paths to the assets, attackers, controls, and possible consequences that matter.

Key Considerations

Reducing unnecessary permissions, disabling unused services, separating responsibilities, and maintaining clear dependency inventories can make defense easier. Reduction should be combined with monitoring and review of the functionality that remains. A feature removed from a website may still be callable directly on-chain, so actual exposure must be checked at the relevant layer. For wallet users, extensions, connected applications, backups, and recovery contacts all deserve attention. The objective is to understand and manage reachable risks, not to claim that a complex financial system can operate with literally no attack surface.