In 2025, crypto hacks totaled $3.4B across 300+ incidents, where social-engineering and access-control failures dominated. Let's look at the major ones. The postIn 2025, crypto hacks totaled $3.4B across 300+ incidents, where social-engineering and access-control failures dominated. Let's look at the major ones. The post

Biggest Crypto Hacks of 2025

2025/12/31 01:49
4 min read

2025 was a bruising year for cybersecurity in digital assets, ending with over $3.4 billion in crypto stolen across hundreds of incidents. Independent tallies show over 300 major security incidents for the year. At least $2 million of those thefts was attributed to North Korean hackers, mainly in the Bybit hack case.

Below are the five biggest heists of 2025, including one driven primarily by social engineering.

Bybit: $1.5b (February 2025)

U.S. authorities attributed the largest crypto theft in history to North Korea’s Lazarus Group. Investigators said attackers took control of a cold ETH wallet, then rapidly laundered funds across chains via BTC $88 282 24h volatility: 0.9% Market cap: $1.76 T Vol. 24h: $40.38 B and other currencies. Exchange disclosures and later forensic analysis showed that large portions were routed through THORChain and split across tens of thousands of addresses.

According to a later report by Crystal Intelligence, the attack Bybit faced was a sophisticated operation that compromised its frontend, thereby tricking employees into believing they were signing legitimate transactions. WazirX and Phemex were hacked similarly.

Following the incident, Bybit launched a 10% recovery bounty and engaged blockchain investigators to help freeze the stolen funds. Portions were tracked, though most remain in motion.

Cetus DEX (Sui): $220m (May)

Sui’s largest DEX and liquidity provider, Cetus, was drained $220 million in just 15 minutes. According to Merkle Science, the hackers did not exploit a smart contract vulnerability, which is typical in the industry. Instead, they benefited from a rounding bug in a third-party math library, used for liquidity and pricing calculations.

An attacker abused a rounding/MSB-check flaw to manipulate pool parameters and extract assets. Teams moved quickly to pause contracts and later claimed that around $160 million had been frozen or recovered.

However, more than $60M remained at risk. This was the year’s most significant DeFi exploit and briefly halted trading in the Sui ecosystem.

Balancer: $116m (November)

A breach in Balancer, a popular DeFi protocol, was initially spotted by crypto sleuths on X. An attacker exploited a rounding bug in Balancer V2’s stable pool logic across Ethereum and several L2s and sidechains. Balancer’s disclosure confirms the technical root cause.

The initial estimates placed losses near $120, with the bulk on the Ethereum mainnet. Moreover, a dormant whale withdrew $6,5 million just after the hack. Balancer’s Total Value Locked (TVL) halved from $442 million to $214.5 million in a single day.

However, according to Crystal Intelligence, most of the funds were traced. The wallets are now closely monitored for potential transactions to freeze the stolen funds.

Phemex (CEX): $73m (January)

Phemex, a centralized exchange (CEX) based in Singapore, saw its hot-wallet compromised across 16 chains. Security firms flagged dozens of suspicious outflows from Phemex hot wallets spanning major networks.

This was the first big hack of 2025 that shook the community. Prominent expert on X, ZachXBT, who participated in the Bybit investigation, proved that the Phemex and Bybit attacks were carried out by Lazarus and used similar addresses.

After the incident, the company completely halted deposits and withdrawals, but by February, services were fully resumed with additional security hardening.

Upbit (CEX): over $30m (November)

South Korea’s largest exchange, Upbit, reported a hack in November, with a total impact of 44.5 billion won (around $34 million). Customers were made whole from reserves, while 5.9B ($4 million) in Upbit corporate funds was lost. Just a small portion of $1.77 million got frozen through tracing.

Upbit halted Solana flows, moved funds to cold storage, coordinated freezes with issuers/exchanges, and gradually reopened wallets using new deposit addresses. Even with reimbursement, the incident underscored CeFi’s concentration risk.

2025 Crypto Hacks in Numbers

  • Total stolen: $3.3-3.4 billion (range reflects differing methodologies across Chainalysis and Beosin/Footprint).
  • Incident count: ~313 major cases (Beosin/Footprint).
  • H1 snapshot: around $2.5 billion stolen across over 300 incidents. According to CertiK, this already exceeds the total for 2024.
  • Typical attacks: compromised wallets and phishing/social engineering were material drivers.
  • Platforms targeted: A few infrastructure-level attacks dominated losses (e.g., Bybit), while overall DeFi incident counts remained much higher, though with more minor losses.

Why Social Engineering Mattered More

In general, security firms noted a shift toward human-factor and supply-chain compromises. Hackers moved from poisoned frontends and multisig UI tricks to executive impersonation and key theft, thus reducing the relative share of pure solidity bugs. 2025’s outlier losses were overwhelmingly due to access-control failures, not to novel on-chain math.

next

The post Biggest Crypto Hacks of 2025 appeared first on Coinspeaker.

Market Opportunity
LOOK Logo
LOOK Price(LOOK)
$0.00956
$0.00956$0.00956
-1.54%
USD
LOOK (LOOK) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Let insiders trade – Blockworks

Let insiders trade – Blockworks

The post Let insiders trade – Blockworks appeared on BitcoinEthereumNews.com. This is a segment from The Breakdown newsletter. To read more editions, subscribe ​​“The most valuable commodity I know of is information.” — Gordon Gekko, Wall Street Ten months ago, FBI agents raided Shayne Coplan’s Manhattan apartment, ostensibly in search of evidence that the prediction market he founded, Polymarket, had illegally allowed US residents to place bets on the US election. Two weeks ago, the CFTC gave Polymarket the green light to allow those very same US residents to place bets on whatever they like. This is quite the turn of events — and it’s not just about elections or politics. With its US government seal of approval in hand, Polymarket is reportedly raising capital at a valuation of $9 billion — a reflection of the growing belief that prediction markets will be used for much more than betting on elections once every four years. Instead, proponents say prediction markets can provide a real service to the world by providing it with better information about nearly everything. I think they might, too — but only if insiders are free to participate. Yesterday, for example, Polymarket announced new betting markets on company earnings reports, with a promise that it would improve the information that investors have to work with.  Instead of waiting three months to find out how a company is faring, investors could simply watch the odds on Polymarket.  If the probability of an earnings beat is rising, for example, investors would know at a glance that things are going well. But that will only happen if enough of the people betting actually know how things are going. Relying on the wisdom of crowds to magically discern how a business is doing won’t add much incremental knowledge to the world; everyone’s guesses are unlikely to average out to the truth. If…
Share
BitcoinEthereumNews2025/09/18 05:16
Morning Crypto Report: 'I Am Capitulating': What's Vitalik Buterin Talking About? Bitcoin Quantum Threat Drama Gets 20,000 BTC Twist, Cardano out of Top 10 as Bitcoin Cash Wins Back 25% of BCH Price

Morning Crypto Report: 'I Am Capitulating': What's Vitalik Buterin Talking About? Bitcoin Quantum Threat Drama Gets 20,000 BTC Twist, Cardano out of Top 10 as Bitcoin Cash Wins Back 25% of BCH Price

February 8, Sunday: Buterin says he is "capitulating" as X naming drama spills into the crypto market, Bitcoin's quantum threat adds a 20,000 BTC angle and Bitcoin
Share
Coinstats2026/02/08 21:51
Pi Network Users Criticize Core Team After Celebratory Post

Pi Network Users Criticize Core Team After Celebratory Post

The post Pi Network Users Criticize Core Team After Celebratory Post appeared on BitcoinEthereumNews.com. Home » Crypto Bits The first Friday of February was supposed
Share
BitcoinEthereumNews2026/02/08 22:11