Crypto losses near $3.4B as hackers went ‘big game hunting’

cointelegraphPublished on 2025-12-18Last updated on 2025-12-18

Crypto hackers focused on large crypto entities and personal crypto wallets this year, resulting in $3.4 billion in crypto losses in 2025 — the highest figure since 2022.

Just three hacks in 2025, led by the $1.4 billion hack of crypto exchange Bybit, accounted for 69% of all losses from January through to early December, a Chainalysis report released on Thursday found, with the largest attacks a thousand times larger than the typical incident.

Andrew Fierman, the head of national security intelligence at Chainalysis, told Cointelegraph that while massive attacks drove this year’s uptick in losses, it’s unclear if 2026 will unfold in the same way.

The $1.4 billion hack on Bybit contributed nearly half to 2025’s total losses. Source: Chainalysis

“It’s difficult to predict if it will get worse in 2026, as hacks are very outlier-driven — one or two big hacks can set records for a given year. But what I can say is that this trend of big game hunting seems to be continuing, and there’s no reason to believe hacks will decline next year,” he said.

Wallet and private key compromises are a popular target

Meanwhile, Fierman said that on the opposite end of the spectrum, personal wallets have also become a popular target for hackers.

They represented 7.3% of the total stolen value in 2022 and 44% in 2024. This year it’s around 20%, but ignoring the Bybit hack, the total would have been closer to 37%.

However, the overall amount stolen from individual hacks declined from $1.5 billion in 2024 to $713 million this year, despite the number of incidents nearly tripling compared to 2022.

More personal wallets were hacked this year, but the total stolen was far less. Source: Chainalysis

“These amounts are smaller because individual personal wallets tend to hold less funds than large exchange wallets, which pool many users’ funds together,” Fierman added.

DeFi protocols adopted more effective security measures

DeFi total locked value is around $119 billion, according to the analytics platform DefiLlama, more than double from 2023 lows when it dropped to below $40 billion.

However, Chainalysis said the recovery in DeFi markets hasn’t led to a spike in hacks, which presents “a clear divergence from historical trends.”

Previously, areas of the industry flush with funds tended to suffer more hacks. However, in this case, Chainalysis points to DeFi protocols implementing more effective security measures and attackers shifting their focus to wallets and centralized services as possible causes.

“The sustained lower level of DeFi hacks, even as billions of dollars have returned to these protocols, represents a meaningful change,” the Chainalysis team said.

North Korea is becoming more sophisticated

North Korean hacker crews were responsible for $2.02 billion in stolen cryptocurrency in 2025, an additional $681 million over the total in 2024, through tactics such as embedding IT workers inside projects.

North Korean hackers stole more in 2025 than in previous years. Source: Chainalysis

Analysis found that North Korean hackers executed fewer but far more damaging attacks in 2025, which Chainalysis attributes to an increase in sophistication and patience as they focus more on achieving larger scores.

Related: Solana under ‘industrial scale’ DDoS attack: Co-founder says it’s ‘bullish’

“The regime is consistently training and developing new tactics by which their operators execute their strategies, whether infiltrating Web3 companies as IT workers or finding exploitable access points through third-party vendors,” Fierman said.

“While with every hack the industry learns more about DPRK tactics, and strengthens security measures to mitigate future risk, the DPRK is also evolving, in an ongoing attempt to find new attack vectors to continue yielding returns for the regime through their ill-gotten gains.”

Magazine: Do Kwon sentenced to 15 years, Bitcoin’s ‘choppy dance’: Hodler’s Digest, Dec. 7 – 13

Related Questions

QWhat was the total value of cryptocurrency losses due to hacks in 2025, and how does this compare to previous years?

AThe total value of cryptocurrency losses due to hacks in 2025 was $3.4 billion, which is the highest figure since 2022.

QWhich single hack was the largest contributor to the total losses in 2025, and how much was stolen?

AThe $1.4 billion hack of the crypto exchange Bybit was the largest contributor, accounting for nearly half of the total losses for the year.

QAccording to the report, what significant trend has been observed in attacks on personal wallets?

AWhile the number of incidents targeting personal wallets nearly tripled compared to 2022, the total amount stolen from them declined from $1.5 billion in 2024 to $713 million in 2025.

QHow did the recovery in DeFi Total Value Locked (TVL) relate to the number of hacks on DeFi protocols in 2025?

ADespite the DeFi TVL recovering to around $119 billion, more than double its 2023 lows, there was no spike in hacks, which represents a clear divergence from historical trends due to improved security measures.

QHow much cryptocurrency did North Korean hacker crews steal in 2025, and what tactics did they using?

ANorth Korean hacker crews stole $2.02 billion in cryptocurrency in 2025, using more sophisticated tactics such as embedding IT workers inside projects and executing fewer but far more damaging attacks.

Related Reads

This Week's Key Events Preview | U.S. to Release April CPI Data; U.S. Senate Banking Committee to Review "Digital Asset Market Structure Act of 2025"

Weekly News Preview: Key events for May 12-16 include major economic and crypto industry developments. On Tuesday, May 12, the U.S. will release its April CPI data. Additionally, the gaming blockchain Ronin will begin a 10-hour migration to an Ethereum Layer 2, built on OP Stack with EigenDA for data availability. This aims to leverage Ethereum's security and settle RON's annual inflation below 1%. Base's first independent network upgrade, "Base Azul," is scheduled for mainnet activation on Wednesday, May 13, focusing on security, performance, and developer experience enhancements. Thursday, May 14, sees the U.S. Senate Banking Committee voting on the "Digital Asset Market Structure Act of 2025." In other news, Solana DeFi protocol Carrot will shut down, setting a final withdrawal deadline due to impacts from the Drift exploit. The Moscow Exchange will launch futures trading for Solana, Ripple, and Tron indices (RUB-settled) for qualified investors. Multiple service closures are scheduled for Friday, May 15. Dmail Network will begin winding down due to unsustainable infrastructure costs and failed commercialization. Users must export data before this date. Separately, the Cosmos-based lending blockchain UX Chain will fully shut down. Finally, on Saturday, May 16, gaming infrastructure provider Lattice will wind down operations, with its Redstone Layer 2 network ceasing. Users are urged to withdraw assets, especially from contracts like Uniswap pools, before the shutdown.

链捕手1h ago

This Week's Key Events Preview | U.S. to Release April CPI Data; U.S. Senate Banking Committee to Review "Digital Asset Market Structure Act of 2025"

链捕手1h ago

Morning Post | Trump Media Group Releases Q1 Financial Report; Top Three DeFi Applications Return Nearly $100 Million in Revenue to Token Holders in 30 Days; Michael Saylor Shares Bitcoin Tracker Info Again

**Title: Daily Briefing | Trump Media Group Releases Q1 Report; Top 3 DeFi Apps Return Nearly $100M to Token Holders; Michael Saylor Signals Potential Bitcoin Buy** **Summary:** Key developments in the past 24 hours include: * **Economic Outlook:** Goldman Sachs has pushed back its forecast for the next two Federal Reserve interest rate cuts to December 2026 and March 2027, citing persistent inflationary pressures from energy costs. This delayed timeline is expected to tighten liquidity flow into risk assets, including cryptocurrencies. * **DeFi & Revenue:** Data from DefiLlama shows that three leading DeFi applications—Hyperliquid, Pump.fun, and EdgeX—collectively distributed $96.3 million in revenue to their token holders over the last 30 days. This trend highlights a shift in the crypto community's focus towards real protocol earnings and sustainable economic models. * **Corporate Bitcoin Moves:** Michael Saylor, founder of MicroStrategy (note: referred to as 'Strategy' in the text, likely a typographical error), has signaled potential upcoming Bitcoin purchases by posting a "Bitcoin Tracker" update, following a pattern that typically precedes the company's official disclosure of new acquisitions. * **Market Integrity:** Prediction market platform Polymarket announced updates to address platform issues, including identifying and banning clusters of accounts involved in "ghost-fill" activities and implementing measures to prevent bulk account creation. * **Regulation:** The Bank of England Governor warned that stablecoin regulation could lead to tensions between US and international regulators. In South Korea, the National Tax Service has launched a pilot program to entrust seized virtual assets to private custody firms for management. * **Meme Token Trends:** GMGN data lists the top trending meme tokens on Ethereum (e.g., HEX, SHIB), Solana (e.g., FWOG, TROLL), and Base (e.g., SKITTEN, PEPE) over the past day. **Financial Note:** Trump Media & Technology Group reported a Q1 loss of approximately $4 billion, primarily attributed to unrealized losses on its Bitcoin and other digital asset holdings.

链捕手1h ago

Morning Post | Trump Media Group Releases Q1 Financial Report; Top Three DeFi Applications Return Nearly $100 Million in Revenue to Token Holders in 30 Days; Michael Saylor Shares Bitcoin Tracker Info Again

链捕手1h ago

Telegram Takes Direct Control of TON, Social Traffic Rewrites the Public Chain Narrative

Telegram founder Pavel Durov announced that Telegram will replace the TON Foundation as the core driver and largest validator of The Open Network (TON). Key initiatives include a sixfold reduction in transaction fees, performance upgrades, and improved developer tools within the next few weeks. This marks a strategic shift from Telegram merely providing user access to deeply integrating TON into its platform's core infrastructure. The goal is to transform Telegram's massive social traffic into sustainable on-chain activity. While viral mini-apps like Notcoin have demonstrated Telegram's ability to drive user adoption, TON aims to support frequent, low-value transactions inherent to social platforms—such as tipping, in-app payments, and game rewards. Ultra-low fees and sub-second finality (0.6 seconds) are crucial to making blockchain interactions seamless and nearly invisible within the Telegram user experience. However, Telegram's increased central role raises questions about network decentralization. Durov argues that Telegram's participation will attract more large validators, thereby enhancing decentralization. TON also offers high annual staking rewards (18.8%), aiming to retain capital within its ecosystem. The fundamental challenge for TON is no longer leveraging Telegram's user base, but becoming an indispensable, seamless infrastructure layer for Telegram's everyday applications—moving from an adjacent chain to an embedded utility.

marsbit1h ago

Telegram Takes Direct Control of TON, Social Traffic Rewrites the Public Chain Narrative

marsbit1h ago

Trading

Spot
Futures

Hot Articles

How to Buy NEAR

Welcome to HTX.com! We've made purchasing NEAR Protocol (NEAR) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy NEAR Protocol (NEAR) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your NEAR Protocol (NEAR)After purchasing your NEAR Protocol (NEAR), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade NEAR Protocol (NEAR)Easily trade NEAR Protocol (NEAR) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

5.7k Total ViewsPublished 2024.03.29Updated 2025.05.06

How to Buy NEAR

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of NEAR (NEAR) are presented below.

活动图片