Crypto Scams and Hacks Surge to $370M in January: CertiK

TheNewsCrypto发布于2026-02-02更新于2026-02-02

文章摘要

In January, cryptocurrency scams and hacks surged to $370.3 million, marking the highest monthly loss in 11 months and a fourfold increase from January of the previous year. The majority of the stolen funds came from a single social engineering scam that resulted in a $284 million loss. Phishing attacks accounted for over $311.3 million of the total. The month's largest incidents included a $28.9 million hack on Step Finance, a $26.4 million exploit of the Truebit protocol due to a smart contract bug, and a $13.3 million attack on SwapNet. Overall, 16 major hacks were recorded, causing $86.01 million in losses—a slight decrease from the previous year but a 13% rise from December. The figures represent a 214% increase from December's losses and highlight a significant escalation in crypto security breaches.

The total value of stolen cryptocurrencies via exploits and scams extended to $370.3 million last month, the biggest monthly figure hit in 11 months and around a fourfold increase from January of last year.

CertiK, the biggest Web3 security service provider, stated on January 31 that out of 40 scam incidents that happened in January, the major portion of the total value stolen came from one victim that lost about $284 million because of a social engineering scam.

Around over $370 million stolen was accounted for by phishing scams, which stole over $311.3 million over the month. This month’s figure is the biggest loss, followed by the Bybit hack in February 2025.

In February 2025, the hackers swept off around $1.5 billion overall over the month, a major portion of which came from the $1.4 billion hack on crypto exchange Bybit. The recent amount marks over a 277% surge from January 2025, when attackers swept in and stole $98 million.

The Biggest Surge

CertiK also mentioned that it is also a 214% surge from December, witnessing $117.8 million lost to crypto theft. The blockchain security and data analytics company, PeckShield, revealed on February 1 that the hack of Step Finance in the last month of January was the biggest for the month.

Attackers swept $28.9 million in the attack on the decentralised finance portfolio tracker, where a lot of its treasury wallets were risked, having over 261,000 Solana (SOL) taken. After this, the biggest exploit for the month was the $26.4 million attack on the Truebit protocol on January 8, when a bug in a smart contract permitted an attacker to mint tokens almost for free. This also banged the price of the Truebit (TRU) token.

PeckShield also highlighted the $13.3 million hack on liquidity provider SwapNet on January 26 and the $7 million hack against the blockchain protocol Saga on January 21. The firm mentioned that there were around 16 hacks overall in January, equating to $86.01 million in losses, a 1.42% fall from a year ago, but over a 13% rise from December.

Highlighted Crypto News Today:

CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TagsCertiKHackScam

相关问答

QWhat was the total value of stolen cryptocurrencies in January according to CertiK?

A$370.3 million

QWhich single incident accounted for the majority of the stolen funds in January?

AA social engineering scam that resulted in a loss of about $284 million to one victim.

QWhat was the most significant hack prior to January's surge, as mentioned in the article?

AThe Bybit hack in February 2025, where approximately $1.4 billion was stolen.

QAccording to PeckShield, which was the largest individual hack incident in January?

AThe $28.9 million hack of Step Finance.

QWhat type of attack was responsible for the majority of the stolen funds in January?

APhishing scams, which stole over $311.3 million.

你可能也喜欢

中国科技产业,正在批量越过“可见线”

最近,中国科技产业多个领域接连进入全球视野,如大模型Kimi K3和DeepSeek-V4-Flash发布、机器人设备受国际关注、辉瑞与信达生物达成创新药合作等。这标志着中国产业能力正集中越过“可见线”——即从内部积累进入全球市场验证的阶段。 回顾过去,中国出口主力从服装家电“老三样”,到新能源汽车等“新三样”,再到如今人工智能、机器人、创新药“新新三样”,产业迭代周期明显缩短。越过“可见线”的产业通常具备四大特征:形成规模、优势突出、增长加速、带动产业链。与以往不同,当前中国产业不再只是跟进成熟市场,而是通过降低门槛、开放生态,主动参与定义新产品和新需求。 这种变化源于中国产业体系从“完整”走向“稠密”:不同领域共享技术、人才与供应链,形成能力迁移。例如,新能源汽车积累的技术向机器人产业延伸,算力需求带动芯片、存储、光通信等整条产业链。产业与研发的距离缩短,真实应用反馈加速创新,规模化成为创新的一部分。 越过“可见线”意味着中国产业的竞争焦点,从“做出产品”延伸至构建包含专利、标准、生态的持续价值系统。未来,中国需在开放中筑牢产业护城河,通过开源、协同研发扩大生态,推动技术迭代与广泛应用。 “十五五”规划已布局战略性新兴产业与未来产业,持续将新产业推向市场检验。一批又一批产业越过“可见线”,不仅体现单点突破,更意味着中国正形成持续产生新产业的能力。

marsbit21分钟前

中国科技产业,正在批量越过“可见线”

marsbit21分钟前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

《福布斯》文章指出,量子计算对比特币构成潜在威胁。据估计,约有700万枚比特币(价值约4700亿美元)因公钥已在链上暴露而面临风险,这主要包括中本聪时代地址和重复使用的地址。不过,暴露不等于立即被盗,关键在于能破解椭圆曲线密码学的量子计算机尚未出现。 谷歌等机构研究显示,量子计算能力进步迅速,破解加密所需的量子比特数预估持续降低。以太坊基金会研究员预估,到2032年,量子计算机从暴露公钥破解私钥的概率约为10%。 比特币社区对应对方案存在分歧。BIP-360提案建议新增抗量子地址类型;BIP-361则提议分阶段淘汰旧签名,长期未迁移的币(包括可能属于中本聪的)将无法花费,此举被部分人视同“没收”。与此同时,Algorand等区块链已采用抗量子签名。 多家创业公司正积极开发解决方案。例如,American Fortress宣称其技术能让所有链上地址免迁移获得抗量子性,并计划通过软分叉自动冻结高风险休眠钱包。但其技术细节未公开、未经审计,部分说法有待验证。该公司还计划构建一个结合合规与隐私的交易层。 尽管修复方案不断涌现,但黄金支持者等质疑比特币能否像黄金那样经受超长时期的考验。当前,量子威胁虽未迫在眉睫,但已引发密码学升级与资产安全的广泛关注和提前布局。

marsbit27分钟前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

marsbit27分钟前

WEEX API Fast Connect:10秒内将每次登录转化为实盘交易者

WEEX宣布推出API快速连接(API Fast Connect),一种一键式OAuth授权系统。该系统允许用户无需手动处理API密钥即可关联其WEEX账户。该解决方案专为WEEX经纪商合作伙伴设计,旨在通过无缝的一键体验取代传统复杂的技术接入流程,从而在合作伙伴平台上实现更快的用户转化和更强的长期留存。 **核心要点:** * **功能:** 类似“使用Google登录”的一键授权系统,让用户无需创建或管理API密钥即可将其WEEX账户连接到第三方平台。 * **解决问题:** 手动API密钥设置是阻碍潜在用户成为活跃交易者的最大障碍。快速连接彻底消除了这一步骤。 * **获益:** 实现无摩擦转化,降低用户流失,提高留存率,使用户能在数秒内(而非数分钟)从登录进入实盘交易。 * **目标用户:** AI信号平台、量化策略工具、交易机器人以及任何目前需要用户手动配置API访问的WEEX经纪商合作伙伴。 **运作流程:** 1. 用户在合作平台点击“使用WEEX登录”。 2. 系统重定向至官方WEEX授权页面进行验证。 3. 用户确认API密钥的授权范围(默认为交易和读取权限)。 4. 确认后,系统在后台生成API密钥并通过加密通道直接绑定至合作平台。 **优势对比:** 与传统手动API密钥方式相比,快速连接在用户体验(一键操作 vs 手动碎片化流程)、权限管理(预设防错 vs 易出错)、密钥安全(后端加密,用户不接触密钥 vs 前端暴露高风险)和连接速度(即时绑定 vs 手动复制粘贴)方面均有显著提升。 API快速连接是WEEX经纪商工具包的核心组件之一,旨在帮助合作伙伴将感兴趣的用户迅速转化为实际交易者。

TheNewsCrypto52分钟前

WEEX API Fast Connect:10秒内将每次登录转化为实盘交易者

TheNewsCrypto52分钟前

交易

现货
活动图片