Crypto hacks: 2026 Guide

Crypto hacks: 2026 Guide

Marcus Reid
April 20, 2026· 8 min read

If you search for crypto hacks, many articles simply rank incidents by the amount stolen. But the point is not only who lost the most. The real lesson is why these attacks keep happening. Chainalysis reported in its 2025 mid-year update that stolen funds from crypto services had already exceeded $2.17 billion in the first half of 2025, with the Bybit incident making up a large share of that total.[1]

In other words, the industry is not dealing with isolated accidents. It is dealing with mature, persistent, professional attack chains.

Use the online security guide as the baseline: it connects this risk to account, device, browser, and network hardening.

Key Takeaways

  • The largest attacks often expose the weakest governance points: key management, bridge logic, permission design, and employee social engineering.[1][2][3]
  • Major crypto hacks do not only hit small projects. Centralized exchanges and cross-chain infrastructure are also high-risk targets.[1][2]
  • Bybit, Ronin, Poly Network, and BNB Bridge show that "the code is fine" does not mean the whole system is fine.[1][2][3]
  • For everyday users, the most realistic risks are still phishing, fake jobs, fake support agents, SIM swaps, and private key exposure.[4][5]
  • When the industry focuses only on reimbursement totals, the next attack often slips in through permissions and process boundaries.

Why look at these incidents together?

Because they are not the same kind of failure.

Some attacks broke bridge or contract logic. Some exploited multisig and cold wallet workflows. Some started with employee social engineering. Others came from permissions that were too broad from the beginning. When you put these cases side by side, "the hackers were good" becomes the shallow answer. The deeper pattern is governance.

1. Bybit: one of the largest known single incidents in the industry

In February 2025, Bybit suffered a large-scale virtual asset theft. The FBI later attributed the activity to TraderTraitor, a North Korea-linked cyber actor.[2]

The key lesson is not simply that "cold wallets can be stolen." It is that if a high-value transfer workflow can be disguised and the signing path can be manipulated, even a strong custody model can fail.

2. Ronin Network: a few validators cannot secure huge asset pools

Ronin lost about $615 million in 2022. U.S. Treasury sanctions material and later public law-enforcement documents linked the incident to Lazarus Group.[3][6]

The case made one issue painfully clear: When validation or approval power is too concentrated, attackers do not need to break the blockchain. They only need to compromise the few critical control points.

3. Poly Network: bridge complexity is itself an attack surface

Poly Network lost about $610 million in 2021, although most of the assets were later returned. The incident became a classic not only because of its size, but because it showed that a cross-chain bridge is not a simple asset-moving tool. It stacks trust boundaries across multiple systems.[7]

The more complex the bridge, the less you can rely on luck for audits and permission modeling.

4. BNB Bridge: code-level defects can become real money

After the BNB Smart Chain Bridge was exploited in 2022, the attacker minted and moved a large amount of BNB. Binance's post-incident explanation pointed to an issue with proof verification logic.[8]

The lesson is direct: on-chain systems do not become safe automatically because they are public and transparent. If critical logic can be reused in the wrong way, attackers can turn a mathematical flaw into an asset loss.

5. Coincheck: hot wallets and weak operational controls fail fast

Coincheck lost a large amount of NEM tokens in 2018. Japan's Financial Services Agency later issued related administrative actions and improvement requirements.[9]

The case still matters because it illustrates an old problem: The more assets you keep in a hot environment, the more risk you expose to a continuously online attack surface.

6. FTX-related theft: chaotic periods amplify social engineering and identity takeover

Large amounts of assets were stolen during the chaos around FTX's bankruptcy. Details later charged by the U.S. Department of Justice showed that SIM swapping and employee impersonation were not fringe tactics in crypto crime.[4]

Many people assume crypto theft must involve a brilliant smart contract exploit. In reality, identity verification workflows are often the entry point.

7. DMM Bitcoin: cross-organization social engineering is not a "basic mistake"

In a 2024 joint notice, the FBI, DC3, and Japanese police stated that the roughly $308 million theft from DMM Bitcoin was linked to North Korea-related actors and involved targeted social engineering, including recruiter impersonation.[5]

That points to a frequently underestimated truth: even the strongest system is operated by people. If employees, partners, or wallet software supply chains are compromised, the assets follow.

What do these 7 incidents have in common?

PatternWhat it looks like
Excessive permissionsA small number of validators, multisig participants, or internal roles hold too much power
Complex trust boundariesBridges, cold wallet workflows, and supply-chain collaboration paths become too long
Effective social engineeringRecruiting, support, and employee identity takeover keep appearing
Weak key and approval governanceTechnical security and operational process do not line up
Not enough pre-incident drillsMany teams discover monitoring and response gaps only after the incident

What can everyday users learn from these major cases?

Do not treat security as only a code problem

Many losses happen because someone clicked a fake link, revealed a seed phrase, or trusted fake support, not because they failed to audit a contract.

Wallets and exchanges are not "safe once deposited"

Custody, bridges, approvals, devices, phone numbers, and email accounts are all attack surfaces.

High-yield projects usually have more complex trust chains

If you cannot explain which bridges, signers, and scripts your assets pass through, your risk assessment is already behind.

If you recently clicked an unfamiliar link or received a "wallet issue" notice, read what to do after clicking a phishing link.

My take: crypto security has never been only about whether "the chain is safe"

The real questions are:

  • Who has permission?
  • How are those permissions verified?
  • How is verification monitored?
  • If monitoring fails, can losses be contained quickly?

Attackers look at the whole operating system, not just one smart contract. You should too.

Summary

  • The biggest crypto hacks repeatedly expose governance, permissions, and social engineering failures, not just one technical bug.
  • Bridges, multisigs, cold wallets, employee identities, and supply chains are links in the same risk chain.
  • Everyday users should focus first on seed phrase exposure, fake support, fake jobs, SIM swaps, and spoofed alerts.
  • The dollar amount is the result. The failure point is what you should remember.

FAQ

What is the biggest crypto hack?

Based on currently public information, the Bybit incident is widely treated as one of the largest known single thefts in the industry, far larger than most earlier cases.[1][2]

Is stolen cryptocurrency always caused by a contract bug?

No. Key management, employee social engineering, bridge permissions, and identity verification workflows are also common entry points.[4][5]

Are centralized exchanges safer than on-chain protocols?

Not always. Exchanges have custody advantages, but they also concentrate risk. On-chain protocols are transparent, but may be exposed to logic and bridge flaws.

What should everyday users defend against first?

Start with phishing links, fake support agents, fake recruiting messages, fake airdrops, and seed phrase exposure. These often determine real losses more than reading 20 audit reports.[4][5]

Can a hardware wallet fully prevent these problems?

No. A hardware wallet can reduce some private key exposure risk, but it cannot identify fake transactions, fake approvals, or social engineering for you.

Why should individuals study large historical hacks?

Because they show that security is not a slogan. It is whether permissions, workflows, and verification can survive real attacks.


Disclaimer

This article is for general security education only and does not constitute investment, legal, or compliance advice. Amounts and attribution are based on public disclosures and may change as investigations continue.

As the publisher, AethoVPN notes that crypto hacks remains outside what a VPN can fix.

Sources

  1. Chainalysis, 2025 Crypto Crime Mid-year Update: https://www.chainalysis.com/blog/2025-crypto-crime-mid-year-update/
  2. FBI, Alert on TraderTraitor and Bybit theft activity: https://www.ic3.gov/PSA/2025/PSA250226
  3. U.S. Department of the Treasury, Lazarus Group Sanctions for Ronin theft: https://home.treasury.gov/news/press-releases/jy0701
  4. U.S. Department of Justice, Charges tied to theft from FTX: https://www.justice.gov/usao-dc/pr/three-charged-connection-400-million-ftx-theft-through-sim-swapping-attacks
  5. FBI, DC3, and NPA Identification of North Korean Cyber Actors Responsible for Theft from DMM Bitcoin: https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom
  6. FBI, Lazarus Group and the Ronin compromise: https://www.ic3.gov/Media/Y2022/PSA220418
  7. Poly Network, Announcement and incident updates: https://poly.network/
  8. BNB Chain, Post-mortem on the BSC Token Hub exploit: https://www.bnbchain.org/en/blog/bnb-smart-chain-update-bsc-token-hub-exploit/
  9. Financial Services Agency of Japan, Administrative actions regarding Coincheck: https://www.fsa.go.jp/en/news/2018/20180308-1.html

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Crypto hacks: 2026 Guide | AethoVPN