Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If you search for crypto hacks, many articles simply rank incidents by the amount stolen. But the point is not only who lost the most. The real lesson is why these attacks keep happening. Chainalysis reported in its 2025 mid-year update that stolen funds from crypto services had already exceeded $2.17 billion in the first half of 2025, with the Bybit incident making up a large share of that total.[1]
In other words, the industry is not dealing with isolated accidents. It is dealing with mature, persistent, professional attack chains.
Use the online security guide as the baseline: it connects this risk to account, device, browser, and network hardening.
Key Takeaways
- The largest attacks often expose the weakest governance points: key management, bridge logic, permission design, and employee social engineering.[1][2][3]
- Major crypto hacks do not only hit small projects. Centralized exchanges and cross-chain infrastructure are also high-risk targets.[1][2]
- Bybit, Ronin, Poly Network, and BNB Bridge show that "the code is fine" does not mean the whole system is fine.[1][2][3]
- For everyday users, the most realistic risks are still phishing, fake jobs, fake support agents, SIM swaps, and private key exposure.[4][5]
- When the industry focuses only on reimbursement totals, the next attack often slips in through permissions and process boundaries.
Because they are not the same kind of failure.
Some attacks broke bridge or contract logic. Some exploited multisig and cold wallet workflows. Some started with employee social engineering. Others came from permissions that were too broad from the beginning. When you put these cases side by side, "the hackers were good" becomes the shallow answer. The deeper pattern is governance.
In February 2025, Bybit suffered a large-scale virtual asset theft. The FBI later attributed the activity to TraderTraitor, a North Korea-linked cyber actor.[2]
The key lesson is not simply that "cold wallets can be stolen." It is that if a high-value transfer workflow can be disguised and the signing path can be manipulated, even a strong custody model can fail.
Ronin lost about $615 million in 2022. U.S. Treasury sanctions material and later public law-enforcement documents linked the incident to Lazarus Group.[3][6]
The case made one issue painfully clear: When validation or approval power is too concentrated, attackers do not need to break the blockchain. They only need to compromise the few critical control points.
Poly Network lost about $610 million in 2021, although most of the assets were later returned. The incident became a classic not only because of its size, but because it showed that a cross-chain bridge is not a simple asset-moving tool. It stacks trust boundaries across multiple systems.[7]
The more complex the bridge, the less you can rely on luck for audits and permission modeling.
After the BNB Smart Chain Bridge was exploited in 2022, the attacker minted and moved a large amount of BNB. Binance's post-incident explanation pointed to an issue with proof verification logic.[8]
The lesson is direct: on-chain systems do not become safe automatically because they are public and transparent. If critical logic can be reused in the wrong way, attackers can turn a mathematical flaw into an asset loss.
Coincheck lost a large amount of NEM tokens in 2018. Japan's Financial Services Agency later issued related administrative actions and improvement requirements.[9]
The case still matters because it illustrates an old problem: The more assets you keep in a hot environment, the more risk you expose to a continuously online attack surface.
Large amounts of assets were stolen during the chaos around FTX's bankruptcy. Details later charged by the U.S. Department of Justice showed that SIM swapping and employee impersonation were not fringe tactics in crypto crime.[4]
Many people assume crypto theft must involve a brilliant smart contract exploit. In reality, identity verification workflows are often the entry point.
In a 2024 joint notice, the FBI, DC3, and Japanese police stated that the roughly $308 million theft from DMM Bitcoin was linked to North Korea-related actors and involved targeted social engineering, including recruiter impersonation.[5]
That points to a frequently underestimated truth: even the strongest system is operated by people. If employees, partners, or wallet software supply chains are compromised, the assets follow.
| Pattern | What it looks like |
|---|---|
| Excessive permissions | A small number of validators, multisig participants, or internal roles hold too much power |
| Complex trust boundaries | Bridges, cold wallet workflows, and supply-chain collaboration paths become too long |
| Effective social engineering | Recruiting, support, and employee identity takeover keep appearing |
| Weak key and approval governance | Technical security and operational process do not line up |
| Not enough pre-incident drills | Many teams discover monitoring and response gaps only after the incident |
Many losses happen because someone clicked a fake link, revealed a seed phrase, or trusted fake support, not because they failed to audit a contract.
Custody, bridges, approvals, devices, phone numbers, and email accounts are all attack surfaces.
If you cannot explain which bridges, signers, and scripts your assets pass through, your risk assessment is already behind.
If you recently clicked an unfamiliar link or received a "wallet issue" notice, read what to do after clicking a phishing link.
The real questions are:
Attackers look at the whole operating system, not just one smart contract. You should too.
Based on currently public information, the Bybit incident is widely treated as one of the largest known single thefts in the industry, far larger than most earlier cases.[1][2]
No. Key management, employee social engineering, bridge permissions, and identity verification workflows are also common entry points.[4][5]
Not always. Exchanges have custody advantages, but they also concentrate risk. On-chain protocols are transparent, but may be exposed to logic and bridge flaws.
Start with phishing links, fake support agents, fake recruiting messages, fake airdrops, and seed phrase exposure. These often determine real losses more than reading 20 audit reports.[4][5]
No. A hardware wallet can reduce some private key exposure risk, but it cannot identify fake transactions, fake approvals, or social engineering for you.
Because they show that security is not a slogan. It is whether permissions, workflows, and verification can survive real attacks.
Disclaimer
This article is for general security education only and does not constitute investment, legal, or compliance advice. Amounts and attribution are based on public disclosures and may change as investigations continue.
As the publisher, AethoVPN notes that crypto hacks remains outside what a VPN can fix.
Sources
Sources checked 8 May 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.