Crypto Santa’s Naughty List — List of Top Heists in 2025

ccn.com发布于2025-12-25更新于2025-12-25

文章摘要

Crypto Santa’s Naughty List: 2025 was a record-breaking year for crypto theft, with total losses estimated between $4–5 billion. North Korean hacking groups, particularly Lazarus, were responsible for over 60% of stolen funds. The largest single heist was the February Bybit breach, where $1.5 billion was stolen via a compromised multi-signature wallet. Other major incidents included a $200–400 million Coinbase insider breach, a $90–100 million attack on Iran’s Nobitex, a $48–50 million hot wallet exploit at BtcTurk, and a $91 million phishing scam against an individual Bitcoin holder. The year highlighted growing threats from state-backed actors, sophisticated social engineering, and vulnerabilities in both centralized and DeFi platforms.

Key Takeaways

  • 2025 was one of the most profitable years on record for crypto scammers, with losses topping $4 billion.
  • The February Bybit breach became the largest centralized exchange hack in history, draining more than $1.5 billion.
  • North Korea–linked hacking groups were responsible for over 60% of the year’s stolen crypto.

As 2025 comes to a close, the crypto industry is taking stock of a year defined by sharp contrasts.

On one side were record-breaking ETF inflows, growing institutional adoption, and long-awaited regulatory clarity.

On the other hand, there was a relentless surge in hacks, scams, and state-backed cybercrime that quietly drained billions from the ecosystem.

This year marked a grim milestone. More than $3 billion in crypto was stolen in the first half alone—already exceeding the total losses recorded in all of 2024.

By year-end, estimates place total losses closer to $4–$5 billion, driven by a mix of high-profile exchange breaches, DeFi exploits, and an explosion in increasingly sophisticated phishing campaigns.

At the center of it all were well-organized threat actors.

North Korea–linked hacking groups emerged as the most prolific offenders, accounting for the majority of stolen funds.

Their operations grew more advanced, blending malware, social engineering, and AI-assisted phishing to target both centralized platforms and decentralized protocols.

What follows is a breakdown of 2025’s biggest crypto heists, the groups behind them, and the structural weaknesses they exposed.

Consider it crypto’s year-end “naughty list”—not just a tally of losses, but a look at the lessons the industry is being forced to learn heading into 2026.

Earn Crypto with These Top Mining Apps
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.
"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank">
Mining Rig Rentals<\/h3>"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank">

Mining Rig Rentals

promotions
Earn a commission on your referral\u2019s transactions.<\/strong>"}' data-trk="67d19e1ff74d32de176c1b03" href="https://www.miningrigrentals.com?ref=2742248" rel="nofollow" target="_blank"> Earn a commission on your referral’s transactions.
Coins
6
Claim Offer
"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank">
Hashing24<\/h3>"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank">

Hashing24

promotions
Earn 3-10% on referral purchases<\/strong>"}' data-trk="67d19ee2f74d32de176c1b5f" href="https://hashing24.com/?rid=53616c7465645f5fe8657fbf16217f483baff299e53f4db4" rel="nofollow" target="_blank"> Earn 3-10% on referral purchases
Coins
Claim Offer
"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank">
Binance Pool<\/h3>"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank">

Binance Pool

promotions
Sign up, verify, deposit 100 USDT, get 100 USDT bonus<\/strong>"}' data-trk="67d1a119f74d32de176c1be1" href="https://accounts.binance.com/en/register?ref=DTDJBNX1" rel="nofollow" target="_blank"> Sign up, verify, deposit 100 USDT, get 100 USDT bonus
Coins
5
Claim Offer

Bybit Exchange Hack (February 21, 2025 – ~$1.46–1.5 Billion Lost)

North Korea’s Lazarus Group orchestrated the largest single cryptocurrency theft in history by exploiting the Bybit exchange.

Hackers compromised a third-party multi-signature wallet interface by injecting malware into the signing process, tricking approvers into redirecting over 400,000 ETH from Bybit’s cold wallet.

Funds were rapidly laundered across chains using bridges and mixers.

This incident alone accounted for nearly 70% of first-half losses, triggering market dips, regulatory scrutiny, and a reevaluation of third-party dependencies in exchange infrastructure.

The hack shook global markets, and the BTC price dipped 8%.

Although Bybit reimbursed users, it faced lawsuits due to security lapses. The incident highlighted the risks associated with cold wallet exchanges.

Coinbase Insider Breach (March 2025 – $200-400 Million)

The incident involved an employee leaking API keys and insider information about individuals for bribes.

As a result, unknown hackers drained hot wallets. However, it wasn’t a full-fledged direct exploit but enabled targeted thefts.

Coinbase pledged reimbursements, and it led to enhanced insider vetting industry-wide.

Nobitex Exchange Attack (June 2025 – ~$90–100 Million)

Iran’s largest crypto platform fell victim to a politically motivated breach, attributed to hacktivist group “Predatory Sparrow” in retaliation against the regime.

Hot wallets were drained, with funds partially “burned” or frozen—highlighting rare geopolitical hacks amid rising nation-state involvement.

BtcTurk Hot Wallet Exploit (August- $48—$50 Million)

In August 2025, BtcTurk, a Turkish CEX, suffered its second major hack in a little over a year.

This time, the attackers stole an estimated $48 million from the exchange’s hot wallets.

The 2025 attack on BtcTurk was a less expensive mirror of its June 2024 incident.

In both cases, the attacker gained access to the private keys used to manage the protocol’s hot wallets.

With this access, the attackers were able to drain funds from these wallets.

In 2024, the CEX lost approximately $55 million, while the more recent incident resulted in roughly $48 million being stolen from the exchange across seven blockchains.

These funds were then consolidated into a few different accounts.

Individual BTC Phishing (August-$91 Million)

In August 2025, a cryptocurrency investor was defrauded of 783 BTC (valued at approximately $91 million at the time) through a sophisticated social engineering phishing scam.

This incident is considered one of the largest individual Bitcoin losses due to this type of attack.

The scammers convinced the victim to provide sensitive access credentials or their seed phrase, allowing them to drain the entire 783 BTC from the wallet in a single transaction within minutes.

Visit Our Stablecoin Partners
  • Trade with Stablecoins Here Are Our Top Exchanges for Stablecoins
  • Buy Stablecoins Fast & Easy Buy Stablecoins & Crypto With a Credit Card
  • Bet with Stablecoins Top Crypto Casinos that Accept Stablecoins

相关问答

QWhat was the total estimated value of cryptocurrency stolen in 2025 according to the article?

AThe total losses were estimated to be between $4 and $5 billion.

QWhich group was responsible for the largest single cryptocurrency theft in history in 2025, and which exchange did they target?

ANorth Korea's Lazarus Group was responsible for the theft, and they targeted the Bybit exchange, stealing an estimated $1.46 to $1.5 billion.

QWhat percentage of the year's stolen crypto was attributed to North Korea-linked hacking groups?

ANorth Korea-linked hacking groups were responsible for over 60% of the year's stolen crypto.

QWhat was the nature of the Coinbase breach in March 2025, and how much was lost?

AThe Coinbase breach was an insider incident where an employee leaked API keys and insider information for bribes, enabling targeted thefts that resulted in losses between $200 and $400 million.

QWhat was unique about the Nobitex Exchange attack in June 2025 compared to other heists mentioned?

AThe Nobitex attack was a politically motivated breach attributed to the hacktivist group 'Predatory Sparrow' in retaliation against the Iranian regime, making it a rare example of a geopolitical hack.

你可能也喜欢

SharpLink CEO:如何理解以太坊开发者刚刚突破 100 万?

作者Joseph Chalom从亚洲之行中感受到以太坊生态的活力与建设者的雄心。他指出,Electric Capital数据显示以太坊历史开发者总数已突破100万,其中约23.2万人在过去一年保持活跃,这是加密领域最大的技术人才库。 Chalom认为,加密领域的核心问题并非哪条链最快,而是顶尖建设者选择在哪里长期建设。以太坊的显著优势源于十年积累的制度、文化、经济和生态结构,使其成为可编程金融和互联网原生资本形成的默认操作系统。 这百万建设者正致力于解决行业最难的问题:核心协议的可扩展性、隐私、抗量子能力及智能体系统。例如,2026年预计进行的Glamsterdam升级将在不破坏核心原则下提升性能;同步可组合性技术让众多Rollup能像一条链般运作;以太坊在抗量子准备上也处于明显领先地位。 以太坊的深层护城河在于开发者聚集产生的复利效应,以及由此强化的可组合性、共享标准(如EVM和Solidity)和信任。其可信中立性(由超90万验证者保障)、模块化架构(如Base、Arbitrum等Rollup)以及吸引顶尖研究人员的文化,共同巩固了其作为大型机构首选互联网原生金融协调层的地位。Chalom坚信,以太坊的生态系统优势及其汇聚的人才,将持续推动下一代金融基础设施的变革。

marsbit1小时前

SharpLink CEO:如何理解以太坊开发者刚刚突破 100 万?

marsbit1小时前

SharpLink CEO:如何理解以太坊开发者刚刚突破 100 万?

SharpLink CEO分享了其对以太坊开发者总数突破100万的见解。根据Electric Capital数据,以太坊历史开发者总数已达1,012,824人,其中约23.2万人在过去一年保持活跃,构成了加密领域最庞大的技术人才库。 作者认为,加密领域的核心竞争并非单纯追求速度与低费用,而是顶尖建设者的选择。以太坊凭借十年积累的制度、文化、经济与生态结构,形成了难以复制的综合优势,已成为可编程金融和互联网原生资本的默认操作系统。 这百万开发者正致力于攻克行业最前沿的挑战:通过预计2026年的Glamsterdam升级提升核心协议可扩展性;通过同步可组合性技术让众多Rollup如一条链般协同工作;以及积极布局抗量子能力,以太坊基金会已成立专门团队推进,目标是2029年前完成迁移。 更深层的护城河在于网络效应:以太坊的可组合性让应用像乐高积木一样互操作,EVM和Solidity技能在数百个网络中通用,形成了“更多开发者→更多工具与流动性→更多应用”的飞轮。此外,由超90万验证者保障的可信中立性、模块化扩展架构以及顶尖的研究与文化氛围,共同巩固了其作为大型机构首选信任层的地位。 作者在访问亚洲以太坊社区后强调,以太坊的竞争优势在于汇聚了改变未来金融的建设者,其生态不仅是链上活跃,更在成为互联网原生金融的长期协调层。

链捕手1小时前

SharpLink CEO:如何理解以太坊开发者刚刚突破 100 万?

链捕手1小时前

交易

现货
合约

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

2.6k人学过发布于 2025.01.15更新于 2026.06.02

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片