Theft Is Just the Beginning: The Slow Collapse Behind Cyber Attacks

比推Xuất bản vào 2026-03-23Cập nhật gần nhất vào 2026-03-23

Tóm tắt

The article "Theft Is Just the Beginning: The Slow Collapse Behind Hacker Attacks" discusses the long-term impacts of cryptocurrency hacks beyond the initial financial loss. Based on Immunefi’s "2026 On-Chain Security Report," the analysis reveals that while attacks themselves are swift, the aftermath unfolds over months, causing prolonged damage such as declining token prices, reduced funding, halted hiring, and delayed development. Key findings include: - The median direct loss per attack is around $25 million, but tokens experience a median drop of 61% within six months, with 16% recovering to pre-attack levels. - Although the number of attacks remains steady (94 in 2024, 97 in 2025), the concentration of losses is alarming: the top five attacks accounted for 62% of total stolen funds. - Centralized platforms, though fewer in attack frequency, represent over half of the financial losses, highlighting persistent vulnerabilities in trusted intermediaries. The report emphasizes that the true crisis begins after the theft—projects face extended recovery periods, reputational harm, and operational disruption, making survival particularly challenging for less-resourced teams. The interconnected nature of DeFi ecosystems further amplifies risks, as single incidents can trigger broader market repercussions. Ultimately, the article underscores that resilience is not just about preventing hacks but enduring their prolonged secondary effects.

Author: Andjela Radmilac

Compiled by: Saoirse, Foresight News

Original title: Under the Shadow of Hackers, More Than Just the Demise of Funds


Cryptocurrency exploits can drain a wallet in minutes, but the full extent of the losses often takes months to fully materialize. Token prices continue to fall, project treasuries shrink, hiring freezes, and even projects that survive the theft may completely lose their future in the subsequent turmoil.

Cryptocurrency hacks never end the moment the wallet is emptied. The theft is swift and direct, followed by a slower collapse that begins to spread within the project.

Tokens continue to decline, funding pools shrink accordingly, hiring plans are cut, product development is delayed, and partners withdraw one after another. Projects that should be focusing on recovery end up spending months rebuilding credibility instead of building.

This is precisely the scene depicted in Immunefi's latest "2026 On-Chain Security Status Report." Its core argument applies to any market—whether in the crypto industry or traditional sectors: the initial loss is only part of the damage.

The more serious issue lies in the devastating impact of the exploit on the project's future. Immunefi data shows that the average direct amount stolen per attack in their sample was approximately $25 million, while the median drop in stolen tokens within six months was as high as 61%. During this period, 84% of the tokens failed to return to their pre-attack prices, and project teams spent at least three months on post-incident recovery, delaying normal development.

However, this data comes with a caveat: token declines have multiple causes, and many projects were already vulnerable before the attack—suffering from poor liquidity, overvaluation, or having already lost momentum.

Immunefi acknowledges that they cannot completely separate the impact of hacks from broader market weakness or the projects' own issues. Even so, the patterns revealed in the report are still noteworthy: hacker attacks are no longer isolated theft events but more like a long-tail corporate crisis.

The value of this report lies in its proof that, after the热点 news fades, the后续 effects of hacker attacks continue to cause long-term harm.

Median Attack Losses Are Decreasing, but Extreme Attacks Are Becoming More Dangerous

According to Immunefi's statistics, 191 crypto attacks occurred in 2024-2025, with total losses of $4.67 billion; over five years, 425 attacks累计 occurred, with total losses reaching $11.9 billion.

The number of attacks per year has hardly changed: 94 in 2024, 97 in 2025, roughly flat with 2023. This indicates that the overall security of the market has not significantly improved. Hacker attacks have become the norm in the crypto industry, and a few giant attacks are enough to define the industry's risk for an entire year.

The report reveals a core contradiction:

The median loss from attacks in 2024-2025 was $2.2 million, lower than the $4.5 million in 2021-2023. On the surface, this seems like progress. However, the average loss was still about $24.5 million, more than 11 times the median; previously, this gap was only 6.8 times. The top five attacks accounted for 62% of all stolen funds; the top ten accounted for 73%.

This is an extremely dangerous distribution pattern: the market appears stable and safe until a giant event tears it apart. The scale of ordinary attacks has become smaller, but the real致命 risk lies in the tail—a few特大 incidents absorb the vast majority of losses and冲击 the entire market in a single day.

The most typical case is Bybit. The exchange's $1.5 billion exploit became the most iconic hack of 2025, with this single incident accounting for 44% of all funds stolen that year.

It's easy to view such events as news spectacles, but they expose a deeper problem of risk concentration: a single failure at a core platform is enough to distort the annual loss structure of the entire industry, revealing that huge risks are still piled up on a few critical nodes.

The Protracted Decline Is Where the Project Truly Begins to Collapse

The data on stolen funds in the report is certainly noteworthy, but the most alarming part is the section on price impact.

In Immunefi's sample of 82 hacked tokens:

  • Within two days of the hack, the median drop was about 10%, roughly flat with the previous cycle;

  • But the real冲击 emerged later: the median drop expanded to 61% after six months, higher than the 53% in 2021-2023.

Six months later:

  • 56.5% of the hacked tokens had fallen more than 50%;

  • 14.5% had fallen more than 90%;

  • Only about 16% of tokens returned to or exceeded their pre-attack price levels.

Chart shows the median token price decline for 82 hacked tokens in Immunefi's sample from 2024 and 2025 (Source: Immunefi)

To understand the full impact of a hack, we can no longer view token price as an isolated market indicator. For the vast majority of crypto projects, the token is the treasury, the foundation for fundraising, and the public report card of credibility. A prolonged暴跌 directly cripples the project's operational cycle, hiring ability, bargaining power in partnerships, and internal morale.

The report points out that projects that suffer attacks often lose their security lead within weeks and enter a recovery period of at least three months. Even if the timeline varies by project, the consequences are clear: projects with crashed tokens and damaged brands have almost no breathing room or chance for a turnaround.

Many markets can withstand a theft, a bad quarter, or even a reputation crisis. But the crypto industry often compresses all three into the same event: the attack empties the treasury → the token暴跌 publicly revalues the project → partners withdraw before the internal cleanup is even finished.

Recovery in this environment is extremely difficult, and致命 for teams that were not well-funded to begin with.

Interdependency makes the situation worse. Immunefi believes the DeFi ecosystem has become increasingly interconnected, forming longer, more fragile risk chains between cross-chain bridges, stablecoins, liquid staking, restaking, and lending markets.

Although some cases in the report require external verification, the overall trend is undeniable: today's crypto systems have more complex layers, meaning the impact of a single attack will extend far beyond the affected protocol itself.

Centralized platforms remain at the epicenter of explosions.

The report shows that out of the 191 attacks in 2024-2025, only 20 targeted centralized exchanges, but these 20 caused losses of $2.55 billion, accounting for 54.6% of the total losses.

This shifts the problem from smart contract vulnerabilities back to asset custody, key management, and over-concentrated infrastructure. For an industry that often sells itself on "decentralized risk resistance," most of the huge losses still occur on highly trusted, centralized nodes.

But this does not mean all hacked projects are doomed to fail. The industry has entered a new phase: a project's survival no longer depends on whether it can withstand an attack, but on whether it can withstand the six months *after* the attack.

Theft is just the beginning of the crisis. What truly determines whether a project has a future is the long, slow,持续的 secondary damage that follows the attack.


Twitter:https://twitter.com/BitpushNewsCN

Bitpush TG Discussion Group:https://t.me/BitPushCommunity

Bitpush TG Subscription: https://t.me/bitpush

Original link:https://www.bitpush.news/articles/7622471

Câu hỏi Liên quan

QWhat is the main finding of Immunefi's '2026 On-Chain Security Status Report' regarding the impact of crypto hacks?

AThe main finding is that the initial theft is only part of the damage; the more severe problem is the devastating impact on a project's future, including prolonged token price declines, drained treasuries, halted hiring, and delayed development, which can lead to a slow, long-term collapse.

QAccording to the report, what was the median percentage drop in the price of hacked tokens after six months?

AThe median percentage drop in the price of hacked tokens after six months was 61%.

QWhat does the report reveal about the distribution of losses from crypto hacks between 2024 and 2025?

AThe report reveals a highly dangerous distribution: while the median attack loss decreased, the average loss was high, and a small number of extreme attacks accounted for the majority of the losses. The top 5 attacks represented 62% of all stolen funds, and the top 10 represented 73%.

QWhich type of platform was responsible for the majority of the financial losses from hacks in 2024-2025, despite having fewer incidents?

ACentralized exchanges were responsible for the majority of financial losses. Although only 20 attacks targeted CEXs, they resulted in losses of $2.55 billion, accounting for 54.6% of the total losses during that period.

QWhat key factor does the report suggest ultimately determines whether a project can survive a hack?

AThe report suggests that a project's survival is no longer determined by its ability to withstand the initial attack, but rather by its ability to withstand the subsequent six months of slow, prolonged secondary damage, including price collapse and reputational harm.

Nội dung Liên quan

Chỉ 153 công ty đầu tư mạo hiểm tham gia vào tháng 7: Ngành đầu tư mạo hiểm tiền mã hóa đang trải qua một cuộc "Đại Tuyệt Chủng"?

Theo số liệu từ CryptoRank, chỉ có 153 công ty đầu tư mạo hiểm (VC) riêng biệt tham gia vào các vòng gọi vốn tiền mã hóa trong tháng 7/2026, mức thấp nhất kể từ tháng 11/2020. Con số này đã giảm khoảng 87% so với mức đỉnh 1.177 công ty vào năm 2022. Sự sụt giảm này diễn ra trong bối cảnh tổng vốn đầu tư mạo hiểm toàn cầu đang mở rộng, chủ yếu được thúc đẩy bởi lĩnh vực AI. Trong 7 tháng đầu năm 2026, các dự án tiền mã hóa đã huy động được tổng cộng khoảng 11,78 tỷ USD thông qua 481 vòng gọi vốn. Tháng 5 là điểm nổi bật, đóng góp 38,89 tỷ USD (chiếm 33% tổng số). Nền tảng giao dịch, thị trường dự đoán và thanh toán là ba lĩnh vực hút vốn nhất, thu hút tổng cộng 53% tổng số tiền. Dù số vòng gọi vốn giai đoạn hạt giống (seed) nhiều nhất, phần lớn vốn lại tập trung vào một số ít các giao dịch lớn ở giai đoạn muộn (Series C trở đi). Thị trường thể hiện sự phân hóa rõ rệt: các quỹ hàng đầu như a16z crypto và Dragonfly vẫn huy động được hàng tỷ USD, trong khi số lượng quỹ mới thành lập giảm mạnh. Theo Galaxy Research, quý I/2026 chỉ có 8 quỹ VC tiền mã hóa mới gây quỹ, tổng cộng 1,1 tỷ USD, mức thấp nhất từ cuối năm 2020. Báo cáo cho rằng vốn đang chuyển hướng sang AI, các công cụ thị trường thứ cấp như ETF, và các công ty đã có sản phẩm, dẫn đến việc thu hẹp danh sách các nhà đầu tư tích cực. Điều này nâng cao ngưỡng đầu tư, đòi hỏi các dự án phải có chất lượng cao hơn, hiệu quả sử dụng vốn tốt hơn và lộ trình thoái vốn rõ ràng hơn.

marsbit2 phút trước

Chỉ 153 công ty đầu tư mạo hiểm tham gia vào tháng 7: Ngành đầu tư mạo hiểm tiền mã hóa đang trải qua một cuộc "Đại Tuyệt Chủng"?

marsbit2 phút trước

Cổ phiếu chip nhớ bật tăng dữ dội, đây là sự trở lại của thị trường bò hay chỉ là đợt phục hồi ngắn ngủi?

Thị trường chip nhớ đã có một phiên phục hồi mạnh mẽ, với mức tăng đáng kể của các cổ phiếu như SK Hynix, SanDisk và Micron. Sự phục hồi này được thúc đẩy bởi sự kết hợp của nhiều yếu tố: chính sách cứu trợ thị trường từ Hàn Quốc (bao gồm khả năng cấm bán khống và thu hẹp biên độ dao động), quá trình giảm đòn bẩy đang bước vào giai đoạn cuối, dữ liệu lạm phát Mỹ hạ nhiệt và đặc biệt là báo cáo tài chính cực kỳ mạnh mẽ từ Microsoft, khẳng định nhu cầu AI vẫn tăng trưởng vững chắc. Tuy nhiên, vẫn còn những rủi ro tiềm ẩn cần theo dõi, như kỳ vọng Ngân hàng Nhật Bản (BOJ) tiếp tục tăng lãi suất, có thể làm gia tăng chi phí cho các giao dịch carry trade và tạo áp lực lên thị trường toàn cầu. Bên cạnh đó, chu kỳ cung ứng chip nhớ và sự cạnh tranh từ các nhà sản xuất mới như Trung Quốc vẫn là những yếu tố cần được xác minh. Để đánh giá sự bền vững của đợt phục hồi này, nhà đầu tư cần theo dõi khả năng duy trì mức tăng của cổ phiếu chip nhớ, sự điều chỉnh giá và đơn đặt hàng cho HBM, DRAM, NAND, cùng các sự kiện quan trọng sắp tới như Hội nghị Tương lai Bộ nhớ, tiến độ sản xuất HBM4 của SK Hynix và báo cáo tài chính của NVIDIA. Tóm lại, trong khi các tín hiệu về đáy chính sách, giảm đòn bẩy và nhu cầu AI là tích cực, thị trường vẫn chưa thể khẳng định đã quay trở lại xu hướng tăng mạnh (bull market). Nhà đầu tư nên giữ kỷ luật, tránh hoảng loạn bán ra ở đáy hoặc đuổi đỉnh trong các đợt phục hồi mạnh, thay vào đó nên áp dụng chiến lược quản lý danh mục và chờ đợi các tín hiệu xác nhận rõ ràng hơn.

marsbit11 phút trước

Cổ phiếu chip nhớ bật tăng dữ dội, đây là sự trở lại của thị trường bò hay chỉ là đợt phục hồi ngắn ngủi?

marsbit11 phút trước

Terrorist Durov có chặn các quan chức Nga không?

Pavel Durov lần đầu lên tiếng công khai phản ứng sau khi Nga đưa ông vào danh sách "khủng bố" vì từ chối yêu cầu giám sát hàng loạt và kiểm duyệt trên Telegram. Ông nhấn mạnh rằng các quan chức Nga "rõ ràng không hiểu ai có thể chặn ai trên internet". Động thái này diễn ra sau khi Cơ quan Giám sát Tài chính Nga (Rosfinmonitoring) đưa Durov vào danh sách, dẫn đến việc đóng băng tài sản và hạn chế giao dịch tài chính của cá nhân ông, dù công ty Telegram không bị ảnh hưởng. Câu nói của Durov được cho là ám chỉ khả năng Telegram có thể hạn chế hoạt động của các kênh chính thức của các cơ quan nhà nước Nga, vốn vẫn đang hoạt động trên nền tảng này bất chấp lệnh chặn. Bối cảnh hiện tại cho thấy một nghịch lý: trong khi chính phủ Nga yêu cầu công chức chuyển sang dùng ứng dụng nhắn tin nội địa MAX và hạn chế người dùng truy cập các ứng dụng nước ngoài, nhiều quan chức vẫn bí mật sử dụng Telegram. Tình huống này gợi nhớ đến diễn biến năm 2020 khi cơ quan quản lý viễn thông Nga (Roskomnadzor) dỡ bỏ lệnh chặn Telegram. Điểm khác biệt hiện nay là Durov đang nắm quyền kiểm soát từ bên trong nền tảng. Việc tuyên bố của ông sẽ chỉ dừng ở lời nói hay dẫn đến hành động cụ thể chống lại các kênh nhà nước vẫn cần được theo dõi trong thời gian tới.

cryptonews.ru22 phút trước

Terrorist Durov có chặn các quan chức Nga không?

cryptonews.ru22 phút trước

Strategy lỗ 8,22 tỷ USD trong quý II trước bối cảnh Bitcoin giảm giá

Chiến lược Strategy, công ty nắm giữ Bitcoin lớn nhất tập đoàn, báo cáo lỗ ròng 8,22 tỷ USD trong quý II, chủ yếu do khoản lỗ chưa thực hiện 8,32 tỷ USD từ vị thế Bitcoin trong bối cảnh giá giảm. Công ty hiện sở hữu 843.775 BTC, tăng 25% từ đầu năm, cho thấy họ tiếp tục tích lũy bất chấp tổn thất trên sổ sách. Strategy cũng tiết lộ đã bán khoảng 218,4 triệu USD Bitcoin để tài trợ một phần nghĩa vụ cổ tức cổ phiếu ưu đãi, đồng thời lập một khoản dự trữ tiền mặt 3,75 tỷ USD nhằm đảm bảo hơn hai năm chi trả các nghĩa vụ này, qua đó phòng ngừa rủi ro biến động giá Bitcoin. Cổ phiếu MSTR tăng nhẹ trong phiên chính nhưng điều chỉnh giảm sau khi báo cáo được công bố. Báo cáo cho thấy Strategy vẫn kiên định với chiến lược tích lũy Bitcoin dài hạn, đồng thời xây dựng đệm tài chính. Từ góc độ phân tích dữ liệu, khoản lỗ này là một mẫu hình lặp lại, tương tự các quý trước, do phương pháp kế toán giá trị hợp lý. Một khía cạnh kỹ thuật mới là chương trình "tiền tệ hóa" Bitcoin của công ty giờ đây tạo ra áp lực bán định kỳ trên thị trường, chuyển đổi vai trò từ một bên chỉ tích trữ thuần túy sang một bên thỉnh thoảng cung cấp tài sản. Câu hỏi đặt ra là liệu khoản dự trữ tiền mặt có thể bù đắp các nghĩa vụ nếu chu kỳ giá giảm kéo dài hơn hai năm hay không.

cryptonews.ru22 phút trước

Strategy lỗ 8,22 tỷ USD trong quý II trước bối cảnh Bitcoin giảm giá

cryptonews.ru22 phút trước

DeepSeek V4 chính thức ra mắt, năng lực mới hé lộ, chiến tranh vương giả về giá trị

Ngày 31/7, DeepSeek đã chính thức ra mắt phiên bản API công khai của DeepSeek-V4-Flash. Phiên bản này cho thấy một tín hiệu đáng chú ý: hiệu suất của Flash trong nhiều bài kiểm tra tiêu chuẩn về Agent đã tiếp cận hoặc thậm chí vượt qua mức của V4-Pro bản xem trước từ ba tháng trước, dù chỉ có 130 tỷ tham số kích hoạt so với 490 tỷ của Pro. Bản cập nhật nhấn mạnh rằng V4-Flash vẫn giữ nguyên kiến trúc và quy mô mô hình, chỉ được tối ưu hóa thông qua quá trình "hậu huấn luyện". Điều này cho thấy phương pháp và chất lượng dữ liệu huấn luyện có thể đang đóng vai trò quan trọng hơn việc chỉ thuần túy mở rộng quy mô tham số. DeepSeek cũng đã giới thiệu khung tự phát triển DeepSeek Harness để tối ưu hóa hiệu suất Agent. Chiến lược rõ ràng là sử dụng mô hình nhẹ nhưng hiệu quả cao để thâm nhập thị trường ứng dụng Agent đang bùng nổ, nơi tốc độ suy luận và chi phí là yếu tố then chốt. Việc hỗ trợ native format API Responses và tối ưu cho Codex cho tham vọng xây dựng hệ sinh thái cạnh tranh, đặc biệt trong lĩnh vực phát triển phần mềm. Động thái này diễn ra sau khi DeepSeek huy động thành công hơn 50 tỷ USD (khoảng 500 tỷ NDT) trong vòng gọi vốn đầu tiên, đưa định giá công ty lên khoảng 52 tỷ USD, và đang có kế hoạch gọi vốn mới với định giá khoảng 71 tỷ USD. Việc nâng cấp Flash được xem như một bước chứng minh năng lực công nghệ dưới sự hỗ trợ của vốn, đồng thời đặt ra câu hỏi về sự thay đổi trong logic cạnh tranh của các mô hình lớn khi lợi thế từ hậu huấn luyện ngày càng rõ rệt.

marsbit26 phút trước

DeepSeek V4 chính thức ra mắt, năng lực mới hé lộ, chiến tranh vương giả về giá trị

marsbit26 phút trước

Giao dịch

Giao ngay
活动图片