Crypto Santa’s Naughty List — List of Top Heists in 2025

ccn.comОпубликовано 2025-12-25Обновлено 2025-12-25

Введение

Crypto Santa’s Naughty List: 2025 was a record-breaking year for crypto theft, with total losses estimated between $4–5 billion. North Korean hacking groups, particularly Lazarus, were responsible for over 60% of stolen funds. The largest single heist was the February Bybit breach, where $1.5 billion was stolen via a compromised multi-signature wallet. Other major incidents included a $200–400 million Coinbase insider breach, a $90–100 million attack on Iran’s Nobitex, a $48–50 million hot wallet exploit at BtcTurk, and a $91 million phishing scam against an individual Bitcoin holder. The year highlighted growing threats from state-backed actors, sophisticated social engineering, and vulnerabilities in both centralized and DeFi platforms.

Key Takeaways

  • 2025 was one of the most profitable years on record for crypto scammers, with losses topping $4 billion.
  • The February Bybit breach became the largest centralized exchange hack in history, draining more than $1.5 billion.
  • North Korea–linked hacking groups were responsible for over 60% of the year’s stolen crypto.

As 2025 comes to a close, the crypto industry is taking stock of a year defined by sharp contrasts.

On one side were record-breaking ETF inflows, growing institutional adoption, and long-awaited regulatory clarity.

On the other hand, there was a relentless surge in hacks, scams, and state-backed cybercrime that quietly drained billions from the ecosystem.

This year marked a grim milestone. More than $3 billion in crypto was stolen in the first half alone—already exceeding the total losses recorded in all of 2024.

By year-end, estimates place total losses closer to $4–$5 billion, driven by a mix of high-profile exchange breaches, DeFi exploits, and an explosion in increasingly sophisticated phishing campaigns.

At the center of it all were well-organized threat actors.

North Korea–linked hacking groups emerged as the most prolific offenders, accounting for the majority of stolen funds.

Their operations grew more advanced, blending malware, social engineering, and AI-assisted phishing to target both centralized platforms and decentralized protocols.

What follows is a breakdown of 2025’s biggest crypto heists, the groups behind them, and the structural weaknesses they exposed.

Consider it crypto’s year-end “naughty list”—not just a tally of losses, but a look at the lessons the industry is being forced to learn heading into 2026.

Earn Crypto with These Top Mining Apps
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.
"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank">
Mining Rig Rentals<\/h3>"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank">

Mining Rig Rentals

promotions
Earn a commission on your referral\u2019s transactions.<\/strong>"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank"> Earn a commission on your referral’s transactions.
Coins
6
Claim Offer
"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank">
Hashing24<\/h3>"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank">

Hashing24

promotions
Earn 3-10% on referral purchases<\/strong>"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank"> Earn 3-10% on referral purchases
Coins
Claim Offer
"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank">
Binance Pool<\/h3>"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank">

Binance Pool

promotions
Sign up, verify, deposit 100 USDT, get 100 USDT bonus<\/strong>"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank"> Sign up, verify, deposit 100 USDT, get 100 USDT bonus
Coins
5
Claim Offer

Bybit Exchange Hack (February 21, 2025 – ~$1.46–1.5 Billion Lost)

North Korea’s Lazarus Group orchestrated the largest single cryptocurrency theft in history by exploiting the Bybit exchange.

Hackers compromised a third-party multi-signature wallet interface by injecting malware into the signing process, tricking approvers into redirecting over 400,000 ETH from Bybit’s cold wallet.

Funds were rapidly laundered across chains using bridges and mixers.

This incident alone accounted for nearly 70% of first-half losses, triggering market dips, regulatory scrutiny, and a reevaluation of third-party dependencies in exchange infrastructure.

The hack shook global markets, and the BTC price dipped 8%.

Although Bybit reimbursed users, it faced lawsuits due to security lapses. The incident highlighted the risks associated with cold wallet exchanges.

Coinbase Insider Breach (March 2025 – $200-400 Million)

The incident involved an employee leaking API keys and insider information about individuals for bribes.

As a result, unknown hackers drained hot wallets. However, it wasn’t a full-fledged direct exploit but enabled targeted thefts.

Coinbase pledged reimbursements, and it led to enhanced insider vetting industry-wide.

Nobitex Exchange Attack (June 2025 – ~$90–100 Million)

Iran’s largest crypto platform fell victim to a politically motivated breach, attributed to hacktivist group “Predatory Sparrow” in retaliation against the regime.

Hot wallets were drained, with funds partially “burned” or frozen—highlighting rare geopolitical hacks amid rising nation-state involvement.

BtcTurk Hot Wallet Exploit (August- $48—$50 Million)

In August 2025, BtcTurk, a Turkish CEX, suffered its second major hack in a little over a year.

This time, the attackers stole an estimated $48 million from the exchange’s hot wallets.

The 2025 attack on BtcTurk was a less expensive mirror of its June 2024 incident.

In both cases, the attacker gained access to the private keys used to manage the protocol’s hot wallets.

With this access, the attackers were able to drain funds from these wallets.

In 2024, the CEX lost approximately $55 million, while the more recent incident resulted in roughly $48 million being stolen from the exchange across seven blockchains.

These funds were then consolidated into a few different accounts.

Individual BTC Phishing (August-$91 Million)

In August 2025, a cryptocurrency investor was defrauded of 783 BTC (valued at approximately $91 million at the time) through a sophisticated social engineering phishing scam.

This incident is considered one of the largest individual Bitcoin losses due to this type of attack.

The scammers convinced the victim to provide sensitive access credentials or their seed phrase, allowing them to drain the entire 783 BTC from the wallet in a single transaction within minutes.

Visit Our Stablecoin Partners
  • Trade with Stablecoins Here Are Our Top Exchanges for Stablecoins
  • Buy Stablecoins Fast & Easy Buy Stablecoins & Crypto With a Credit Card
  • Bet with Stablecoins Top Crypto Casinos that Accept Stablecoins

Связанные с этим вопросы

QWhat was the total estimated value of cryptocurrency stolen in 2025 according to the article?

AThe total losses were estimated to be between $4 and $5 billion.

QWhich group was responsible for the largest single cryptocurrency theft in history in 2025, and which exchange did they target?

ANorth Korea's Lazarus Group was responsible for the theft, and they targeted the Bybit exchange, stealing an estimated $1.46 to $1.5 billion.

QWhat percentage of the year's stolen crypto was attributed to North Korea-linked hacking groups?

ANorth Korea-linked hacking groups were responsible for over 60% of the year's stolen crypto.

QWhat was the nature of the Coinbase breach in March 2025, and how much was lost?

AThe Coinbase breach was an insider incident where an employee leaked API keys and insider information for bribes, enabling targeted thefts that resulted in losses between $200 and $400 million.

QWhat was unique about the Nobitex Exchange attack in June 2025 compared to other heists mentioned?

AThe Nobitex attack was a politically motivated breach attributed to the hacktivist group 'Predatory Sparrow' in retaliation against the Iranian regime, making it a rare example of a geopolitical hack.

Похожее

A Clod of Chinese Soil Chokes Two Japanese Giants

"Chinese Soil Chokes Japanese Giants" The production of a key electronic specialty gas, tungsten hexafluoride (WF6), vital for manufacturing AI chips, was halted by two leading Japanese producers—Kanto Denka and Central Glass. Their shutdown was not due to a technological failure but a sudden, critical shortage of a raw material they had long taken for granted: ultra-high-purity (6N-grade) tungsten powder, which is almost entirely sourced from China. Following a quiet Chinese export announcement in January 2026, tungsten powder shipments to Japan dropped to zero for months. Despite frantic efforts, Japanese companies found no viable alternative; imported powder was three times more expensive and lacked the required purity. Their existing stockpiles were exhausted by mid-2026. WF6 is essential for depositing tungsten into the microscopic contact holes of High Bandwidth Memory (HBM) chips, which are crucial for advanced processors like those from Nvidia. While Japanese firms had mastered producing ultra-pure WF6 gas, their entire supply chain relied on China's 6N tungsten powder—a dependency now revealed as a fatal vulnerability. China's dominance in this "soil" results from decades of painstaking R&D by companies like Xiamen Tungsten and China Tungsten & Hightech. They overcame immense technical hurdles, such as separating chemically similar molybdenum from tungsten, to achieve mass production of the world's purest tungsten powder. With their primary suppliers gone, Kanto Denka and Central Glass announced a permanent halt to WF6 production starting July 1, 2026. This immediately created a supply crisis for major semiconductor manufacturers like Samsung and SK Hynix, forcing them to urgently seek and certify new Chinese suppliers for WF6 itself. The reversal marks a dramatic shift: China has moved from exporting low-value raw materials to controlling the high-purity foundation of a critical global tech supply chain, upending a long-established industrial hierarchy.

marsbit20 мин. назад

A Clod of Chinese Soil Chokes Two Japanese Giants

marsbit20 мин. назад

Without Tencent, What's Left for Suiyuan?

The article centers on the crucial question posed in the title: what is Seyond Technology really worth if its dominant customer, Tencent, were to stop purchasing its AI chips? As the last of China's "Four AI Chip Dragons" to secure approval for a public listing, Seyond's IPO filing reveals a profound and controversial dependency. In 2025, 74.9% to over 80% of its revenue came from Tencent. The piece argues that this extreme customer concentration is not merely a vulnerability but a strategic outcome of China's AI industry evolution. It contrasts Seyond's path with its peers (Moore Thread, Biren Technology, and MetaX), noting that while others raced to market with ambitious stories, Seyond focused first on securing and delivering for a major client. Its explosive revenue growth—with Q1 2026 up 1474.85% year-on-year—is driven by concentrated orders from Tencent, which itself faces massive, escalating AI compute demands for products like its Yuanbao and Hunyuan models. The relationship is framed as a deliberate, symbiotic cultivation of a supply chain. As both a major shareholder (20.26%) and primary client, Tencent is actively fostering Seyond to build a controllable, stable alternative to NVIDIA, similar to how global tech giants historically nurtured key suppliers. The high switching costs—involving software stacks and deployed systems—create a deep "ecological moat" for Seyond within Tencent's ecosystem. The analysis positions the AI chip landscape in three tiers: NVIDIA as the global leader, Huawei's Ascend as the state-backed player, and commercial firms like Seyond competing for market orders. Seyond is increasingly seen as "Tencent's compute foundation," with its product roadmap closely aligned with the tech giant's needs. The conclusion is that the industry's metric for success is shifting from fundraising and technical specs to real orders, delivery capability, and ecosystem binding. Seyond's value, therefore, lies not just in its chips but in holding a massive, multi-year procurement order from China's largest internet company—a tangible asset arguably more telling than any technical whitepaper in the current climate. The core insight is that for domestic chips, the ultimate challenge isn't just catching up technologically with NVIDIA, but earning the trust, scenarios, and recurring orders from a major anchor client.

marsbit1 ч. назад

Without Tencent, What's Left for Suiyuan?

marsbit1 ч. назад

War Trade Unwinding | TradeXYZ Weekend Observations

Weekend markets saw a clear return of risk appetite. Major indices rose broadly, with significant gains in tech and precious metals, while energy sectors fell sharply on the "end of war" narrative. On June 14, oil prices initially rose on reports Iran had not yet finalized a memorandum of understanding. Later, YNET reported Trump might immediately lift the maritime blockade on Iran and the Strait of Hormuz. At 21:30, Trump confirmed on Truth Terminal that a deal with Iran was done, authorizing an immediate end to the US blockade and toll-free opening of the Strait. Iran's deputy foreign minister simultaneously announced an immediate and permanent halt to military actions on multiple fronts. Oil prices had already fallen to weekend boundaries, pre-pricing the news. The S&P 500 subsequently touched 7530. Markets will likely remain in a waiting period until the formal peace deal signing on June 19. At the moment of the deal announcement, gold jumped from ~4,221 to a high of 4,337, and silver from ~67.85 to 70.83, before stabilizing at higher levels. Individual stocks and ETFs like NBIS, RKLB, and LITE performed strongly. NBIS, added to the Nasdaq index, saw a target price increase due to strong AI cloud growth. RKLB, also added to the index, benefited from positive SpaceX valuation sentiment. LITE received a $1,130 target from JPMorgan. SPCX rose quickly after Musk tweeted SpaceX could potentially reach ~$1 trillion in revenue by 2030. In summary, the market shock from the multi-month war is beginning to dissipate. Israel's actions remain the key variable before the June 19 signing. Upcoming events like Fed Chair Warsh's debut and BoJ rate hike expectations will also significantly impact markets this week.

marsbit1 ч. назад

War Trade Unwinding | TradeXYZ Weekend Observations

marsbit1 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.5k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.02

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片