Cryptocurrency losses from hacks, exploits, and scams reached $3.35 billion in 2025, according to blockchain security firm CertiK, marking a significant increase from the previous year and highlighting ongoing security challenges as the digital asset ecosystem continues expanding despite improved defensive measures and heightened awareness of vulnerabilities affecting decentralized finance protocols, cross-chain bridges, centralized exchanges, and individual users.Cryptocurrency losses from hacks, exploits, and scams reached $3.35 billion in 2025, according to blockchain security firm CertiK, marking a significant increase from the previous year and highlighting ongoing security challenges as the digital asset ecosystem continues expanding despite improved defensive measures and heightened awareness of vulnerabilities affecting decentralized finance protocols, cross-chain bridges, centralized exchanges, and individual users.

Crypto Losses Hit $3.35 Billion in 2025: CertiK Security Report

2025/12/25 14:52
News Brief
Cryptocurrency losses from hacks, exploits, and scams reached $3.35 billion in 2025, according to blockchain security firm CertiK, marking a significant increase from the previous year and highlighting ongoing security challenges as the digital asset ecosystem continues expanding despite improved defensive measures and heightened awareness of vulnerabilities affecting decentralized finance protocols, cross-chain bridges, centralized exchanges, and individual users.

Annual theft figures reveal persistent vulnerabilities across DeFi protocols, bridges, and exchanges despite security improvements

Cryptocurrency losses from hacks, exploits, and scams reached $3.35 billion in 2025, according to blockchain security firm CertiK, marking a significant increase from the previous year and highlighting ongoing security challenges as the digital asset ecosystem continues expanding despite improved defensive measures and heightened awareness of vulnerabilities affecting decentralized finance protocols, cross-chain bridges, centralized exchanges, and individual users.

Understanding the $3.35 Billion Loss Figure

The total encompasses multiple attack categories affecting different segments of the cryptocurrency ecosystem throughout 2025.

Smart contract exploits targeting DeFi protocols likely represent the largest category, with hackers identifying vulnerabilities in lending platforms, decentralized exchanges, and yield farming protocols to drain funds through logic errors, reentrancy attacks, and oracle manipulation.

Bridge hacks attacking cross-chain infrastructure contributed substantially to losses as these protocols holding locked value for asset transfers between blockchains create attractive targets for sophisticated attackers.

Exchange breaches affected both centralized and decentralized platforms through hot wallet compromises, private key theft, and withdrawal system exploits enabling unauthorized fund extraction.

Scams and rug pulls added hundreds of millions as fraudulent projects disappeared with investor capital, fake tokens mimicked legitimate assets, and phishing campaigns convinced victims to approve malicious transactions.

Individual theft through phishing, malware, and social engineering targeted personal wallets without requiring protocol-level vulnerabilities.

The diverse attack surface reflects cryptocurrency's complexity where protocols, platforms, and users all face distinct security challenges requiring different protective approaches.

Year-Over-Year Comparison

Comparing 2025 losses to previous years provides context for security trend analysis.

2024 saw approximately $2.2 billion in cryptocurrency theft according to various security firms, meaning 2025 represents roughly 52% increase in absolute dollar terms.

2022 recorded $3.8 billion in losses including massive incidents like Ronin Bridge ($625 million) and Wormhole ($325 million), making it the worst year for cryptocurrency security.

2023 registered about $1.8 billion across similar attack vectors with notable DeFi exploits and bridge hacks dominating headlines.

2021 totaled $1.3 billion as DeFi summer attracted both legitimate users and malicious actors exploiting rapidly deployed protocols.

The 2025 increase versus 2024 suggests security improvements haven't kept pace with ecosystem growth and rising asset values, though remaining below 2022's record indicates some defensive progress despite persistent threats.

Major Attack Categories

Several exploit types contributed disproportionately to the annual total based on historical patterns.

DeFi protocol hacks target smart contract vulnerabilities including reentrancy bugs where attackers recursively call functions before state updates complete, integer overflow issues, and access control failures enabling unauthorized administrative actions.

Flash loan attacks exploit DeFi composability by borrowing millions, manipulating protocol states, and repaying loans within single transactions to extract profits without capital requirements.

Bridge exploits compromise validator sets through multi-signature scheme attacks, exploit cross-chain messaging vulnerabilities, or manipulate consensus mechanisms to authorize fraudulent transfers.

Exchange compromises access hot wallets through private key theft, employee social engineering, or system vulnerabilities bypassing withdrawal controls and approval workflows.

Phishing campaigns create fake websites, impersonate support staff, or send malicious tokens to trick users into revealing credentials or approving fund-draining transactions.

Rug pulls involve developers abandoning projects after collecting investor capital, often through liquidity removal, minting excessive tokens, or implementing hidden backdoors in smart contracts.

The distribution typically sees a few massive incidents accounting for the majority of losses while hundreds of smaller attacks contribute the remainder.

CertiK's Monitoring Methodology

Understanding how CertiK calculates the $3.35 billion requires examining their data collection approach.

Blockchain forensics enables tracking stolen funds on-chain by identifying theft addresses, following flows through mixers and exchanges, and attributing attacks based on transaction patterns.

Incident reporting from affected protocols, exchanges, and users provides direct confirmation of breaches, though not all victims publicly disclose incidents creating potential underreporting.

Automated monitoring through smart contract analysis tools detects unusual transactions, exploit patterns, and emergency pause activations indicating security incidents.

Community intelligence from security researchers, white hat hackers, and blockchain investigators contributes to comprehensive incident tracking across diverse protocols.

Cross-verification against other security firms including Chainalysis, SlowMist, and PeckShield ensures accuracy and prevents double-counting.

Methodology variations between security vendors create discrepancies in annual totals, with different firms reporting ranges from $3-4 billion for 2025 depending on inclusion criteria and classification standards.

North Korean State-Sponsored Attacks

Sophisticated threat actors including North Korean groups contributed significantly to 2025 losses.

Lazarus Group and associated organizations historically execute the largest and most sophisticated cryptocurrency thefts using custom malware, extensive social engineering, and patient reconnaissance.

State-level resources enable North Korean hackers to develop advanced persistent threat capabilities bypassing security measures that stop typical financially-motivated criminals.

Sanction evasion motivates persistent attacks as stolen cryptocurrency helps North Korea fund programs despite international restrictions, creating determination beyond typical profit motives.

Historical attacks attributed to these groups include Ronin Bridge ($625M), Harmony Horizon Bridge ($100M), and Atomic Wallet ($100M) demonstrating consistent high-value targeting.

Laundering infrastructure involving mixers like Tornado Cash, chain-hopping across blockchains, and nested exchange accounts enables converting stolen funds despite blockchain transparency.

Evolving tactics show continuous adaptation as groups shift from centralized exchanges toward DeFi protocols and bridges reflecting improved security at traditional targets.

International cooperation between U.S. FBI, South Korean agencies, and others has improved attribution but hasn't deterred attacks given regime-level backing.

DeFi Vulnerabilities

Decentralized finance applications represent particularly vulnerable infrastructure contributing substantially to annual losses.

Smart contract complexity creates numerous potential vulnerability points as protocols interact with multiple external contracts, oracles, and user inputs requiring flawless logic.

Oracle manipulation exploits price feeds by temporarily distorting spot prices on low-liquidity exchanges to trigger profitable liquidations or enable arbitrage extraction.

Economic exploits take advantage of protocol design flaws where intended mechanisms create unintended manipulation opportunities requiring no code vulnerabilities.

Governance attacks accumulate voting tokens to pass malicious proposals upgrading contracts to vulnerable versions or extracting treasury funds through authorized but harmful actions.

Composability risks emerge as protocols build on other protocols, where vulnerabilities cascade and interactions create unexpected exploit opportunities.

Rapid deployment pressure leads some teams to launch without comprehensive audits or testing, prioritizing speed over security with predictable consequences.

The permissionless innovation enabling DeFi's rapid growth simultaneously creates security challenges as unaudited code manages billions in user assets.

Cross-Chain Bridge Security

Bridge protocols facilitating asset transfers between blockchains suffered major exploits throughout 2025.

Concentrated value in bridge contracts creates attractive targets as successful attacks immediately access hundreds of millions held in escrow.

Validator compromises exploit multi-signature schemes by obtaining threshold keys through phishing, social engineering, or technical vulnerabilities.

Smart contract bugs in bridge logic enable unauthorized minting on destination chains or withdrawals from source chain escrows without proper validation.

Consensus manipulation attacks bridge validators to confirm fraudulent messages through eclipse attacks isolating nodes or Sybil attacks creating fake validators.

Complexity challenges arise from coordinating state across multiple chains with different security models, finality guarantees, and consensus mechanisms.

Notable bridge incidents in previous years suggest 2025 likely included at least one $100+ million theft from cross-chain infrastructure based on historical patterns.

Exchange Security Challenges

Centralized platforms managing customer funds continued experiencing breaches despite improving practices.

Hot wallet exposure creates vulnerability as internet-connected wallets used for daily operations and withdrawals require balancing accessibility against security.

Employee targeting through social engineering convinces staff with privileged access to approve malicious actions or reveal credentials via executive impersonation.

Withdrawal system exploits manipulate verification processes or accounting systems to authorize fraudulent withdrawals exceeding actual balances.

Infrastructure attacks target cloud providers, DNS services, or network infrastructure to intercept communications or redirect deposits.

Insider threats from malicious employees with system access represent persistent risk requiring background checks, access controls, and monitoring.

Major exchanges like Coinbase, Kraken, and Binance maintain stronger security than smaller platforms, concentrating breaches in services with less robust controls.

Market Opportunity
FINANCE Logo
FINANCE Price(FINANCE)
$0.0001863
$0.0001863$0.0001863
-0.16%
USD
FINANCE (FINANCE) Live Price Chart
Disclaimer: The articles published on this page are written by independent contributors and do not necessarily reflect the official views of MEXC. All content is intended for informational and educational purposes only and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC. Cryptocurrency markets are highly volatile — please conduct your own research and consult a licensed financial advisor before making any investment decisions.

You May Also Like

FTX Trust Sues Genesis Digital for $1.15B Clawback Over Alleged Fraudulent Transfers

FTX Trust Sues Genesis Digital for $1.15B Clawback Over Alleged Fraudulent Transfers

The FTX Recovery Trust has filed a $1.15 billion lawsuit against the Bitcoin mining firm Genesis Digital Assets, alleging fraudulent transfers. The complaint, filed on Monday in U.S. Bankruptcy Court for the District of Delaware, alleges that Sam Bankman-Fried used misappropriated FTX customer funds to purchase Genesis Digital shares at “outrageously inflated prices” through his hedge fund, Alameda Research, between August 2021 and April 2022. Genesis Digital co-founders Rashit Makhat and Marco Krohn received $470 million and $80.9 million, respectively, for their shares in February 2022, according to court documents. The trust contends that only Alameda, and by extension Bankman-Fried, as its 90% owner, benefited from the investments, while FTX customers and creditors suffered losses from the diverted exchange funds.Court Document (Source: Bloomberg Law) Genesis Investment Timeline Reveals Systematic Fund Diversion Court documents reveal that discussions between Bankman-Fried and Genesis Digital began in July 2021, when the Kazakhstan-based mining company was seeking capital to expand its operations into the United States. Bankman-Fried joined Genesis Digital’s board in October 2021, according to Bloomberg, positioning himself to oversee what would become one of Alameda’s largest venture investments. The complaint describes how the FTX founder caused Alameda to purchase multiple tranches of Genesis shares over an eight-month period, with the lawsuit characterizing Genesis as “one of Bankman-Fried’s most reckless investments with commingled and misappropriated funds.“ Between August 2021 and April 2022, Alameda invested $1.15 billion across four distinct funding rounds: $100 million in August 2021, $550 million in January 2022, $250 million in February, and $250 million in April 2022. The trust alleges that FTX insiders regularly caused Alameda to “borrow” billions from the FTX.com exchange to fund “profligate lifestyles and vanity investments” while hiding the source of these funds from investors and creditors. Bankman-Fried resigned from Genesis Digital’s board one day before FTX filed for bankruptcy in November 2022, according to the court filing. Mining Sector Faces Renewed Scrutiny Amid FTX Fallout The Genesis Digital lawsuit is the latest effort by FTX’s bankruptcy estate to recover assets for creditors, with the trust having already distributed $6.2 billion across two previous rounds of payments. The trust completed a $1.2 billion distribution in February, followed by a larger $5 billion payout in May, with an additional $1.6 billion distribution scheduled for September 30, bringing total recoveries to nearly half of the $16.5 billion earmarked for victims. These recovery efforts come as Genesis Digital, which operates over 500 megawatts of mining capacity across 20 data centers on four continents, saw its valuation reach $5.5 billion during an April 2022 fundraising round shortly before cryptocurrency prices collapsed later that year. The mining company was exploring an initial public offering in the United States as recently as July 2024, working with advisors to evaluate a potential listing and planning a pre-IPO funding round amid the crypto industry’s recovery from the 2022 market downturn. However, the FTX lawsuit adds another layer of complexity to Genesis Digital’s corporate structure, which includes an extensive network of U.S. subsidiaries with names like Dog House TX-1, Mother Whale LLC, and White Deer LLC. The complaint alleges that these U.S. subsidiaries operate as “alter egos” of the parent company, potentially exposing the entire corporate structure to clawback claims under both federal bankruptcy law and Delaware state fraudulent transfer statutes. Meanwhile, Bankman-Fried continues to serve his 25-year prison sentence following his conviction on seven felony charges, with oral arguments for his appeal scheduled for November 4, 2025. The lawsuit adds to the complex web of litigation following the $175 million settlement earlier this year with Genesis Global, a subsidiary of Digital Currency Group, as creditors and bankruptcy trustees pursue recovery efforts across multiple jurisdictions and corporate entities tied to the failed exchange
Share
CryptoNews2025/09/24 03:14
Ripple-Backed Evernorth Faces $220M Loss on XRP Holdings Amid Market Slump

Ripple-Backed Evernorth Faces $220M Loss on XRP Holdings Amid Market Slump

TLDR Evernorth invested $947M in XRP, now valued at $724M, a loss of over $220M. XRP’s price dropped 16% in the last 30 days, leading to Evernorth’s paper losses
Share
Coincentral2025/12/26 03:56
New Trump appointee Miran calls for half-point cut in only dissent as rest of Fed bands together

New Trump appointee Miran calls for half-point cut in only dissent as rest of Fed bands together

The post New Trump appointee Miran calls for half-point cut in only dissent as rest of Fed bands together appeared on BitcoinEthereumNews.com. Stephen Miran, chairman of the Council of Economic Advisers and US Federal Reserve governor nominee for US President Donald Trump, arrives for a Senate Banking, Housing, and Urban Affairs Committee confirmation hearing in Washington, DC, US, on Thursday, Sept. 4, 2025. The Senate Banking Committee’s examination of Stephen Miran’s appointment will provide the first extended look at how prominent Republican senators balance their long-standing support of an independent central bank against loyalty to their party leader. Photographer: Daniel Heuer/Bloomberg via Getty Images Daniel Heuer | Bloomberg | Getty Images Newly-confirmed Federal Reserve Governor Stephen Miran dissented from the central bank’s decision to lower the federal funds rate by a quarter percentage point on Wednesday, choosing instead to call for a half-point cut. Miran, who was confirmed by the Senate to the Fed Board of Governors on Monday, was the sole dissenter in the Federal Open Market Committee’s statement. Governors Michelle Bowman and Christopher Waller, who had dissented at the Fed’s prior meeting in favor of a quarter-point move, were aligned with Fed Chair Jerome Powell and the others besides Miran this time. Miran was selected by Trump back in August to fill the seat that was vacated by former Governor Adriana Kugler after she suddenly announced her resignation without stating a reason for doing so. He has said that he will take an unpaid leave of absence as chair of the White House’s Council of Economic Advisors rather than fully resign from the position. Miran’s place on the board, which will last until Jan. 31, 2026 when Kugler’s term was due to end, has been viewed by critics as a threat from Trump to the Fed’s independence, as the president has nominated three of the seven members. Trump also said in August that he had fired Federal Reserve Board Governor…
Share
BitcoinEthereumNews2025/09/18 02:26