Crypto hacks cost the industry $1.5 billion in 2024. In 2025, losses have already blown past that figure — led by the $1.5B Bybit breach alone. Here's what the Crypto hacks cost the industry $1.5 billion in 2024. In 2025, losses have already blown past that figure — led by the $1.5B Bybit breach alone. Here's what the

Crypto Hacks Drained $1.5B in 2024 — 2025 Is Already Worse

2026/03/20 06:23
5 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto hacks drained nearly $1.5 billion from the industry in 2024 across 232 separate incidents, according to Immunefi’s annual report. That figure represented a 17% decline from the $1.8 billion lost in 2023. But the improvement was short-lived: by the end of Q1 2025, losses had already blown past the entire 2024 total, driven by the largest single hack in crypto history.

$1.5B
Total crypto losses in 2024 across 232 incidents, per Immunefi’s annual report.

$1.5 Billion Stolen in 2024: Two Hacks Drove More Than a Third of All Losses

The $1,495,487,055 in total 2024 losses was spread across hundreds of incidents, but two exchange breaches accounted for a disproportionate share. Japan’s DMM Bitcoin lost $305 million in a May 2024 hack, while India’s WazirX suffered a $235 million breach in July. Together, those two incidents represented 36% of the year’s total.

Hacking, not fraud, was the dominant threat vector. Exploits accounted for 98.1% of all losses ($1.47 billion), while scams and rug pulls made up just 1.9%. Q2 2024 was the worst quarter, with $572.7 million stolen, a 115.7% increase over Q2 2023. May alone saw $358.5 million drained.

The most striking structural shift in 2024 was the divergence between centralized and decentralized finance. CeFi losses surged 77.5% year-over-year to $726.2 million across just 11 incidents, meaning each CeFi breach averaged roughly $66 million. DeFi losses, by contrast, fell 44.8% to $769.3 million, but were spread across 221 incidents.

That split matters. DeFi protocols were hit more often but for smaller amounts, suggesting that improved smart contract auditing and security practices are having an effect. CeFi platforms, which hold larger concentrated pools of user funds, became higher-value targets with fewer but far more damaging breaches. For investors weighing custodial risk, the data suggests that exchange security has not kept pace with the threat landscape, even as broader regulatory scrutiny of banks and financial institutions, including eased capital requirements for large banks, continues to evolve.

2025 Surpassed 2024’s Total Before the Year Was Half Over

In February 2025, a single incident rewrote the record books. Bybit, one of the world’s largest crypto exchanges, lost approximately $1.4 billion in what blockchain forensics firms and the FBI attributed to North Korea’s Lazarus Group. It was the largest crypto hack ever recorded, surpassing every prior incident by a wide margin.

The Bybit breach alone nearly matched the entire 2024 industry total. By the end of Q1 2025, cumulative losses had reached $1.64 billion, already exceeding the full-year 2024 figure. By April 2025, Immunefi data showed $1.7 billion in total losses, four times higher year-over-year and 14% above the full 2024 total.

Ethereum and BNB Chain together accounted for roughly 60% of total chain-level losses in 2025, reflecting both the concentration of DeFi activity and the scale of assets held on those networks. The acceleration in losses has contributed to a sharp deterioration in market sentiment, with the ongoing regulatory debate around crypto yield products adding further uncertainty.

The Fear & Greed Index sat at 23 (Extreme Fear) as of mid-March 2026, reflecting lingering investor anxiety from the scale of 2025 breaches. The Bybit hack, in particular, reignited debates about whether centralized exchanges can be trusted with large-scale custody, a question that extends into the growing institutional push around products like spot Bitcoin ETFs.

State-Sponsored Hackers and Social Engineering Are Changing the Threat Model

The Bybit attack was not a smart contract exploit. Reports indicate the breach involved manipulation of front-end signing interfaces, a social engineering vector that bypasses traditional cold storage protections. This represents a fundamental shift from the protocol-level exploits that defined earlier DeFi hacks toward supply chain and human-layer attacks.

North Korea’s Lazarus Group has become the single most significant threat actor in crypto security. The group has systematically targeted exchanges and DeFi protocols to fund state activities, with U.S. Treasury and FBI designations confirming the pattern. In 2024 alone, North Korean-linked actors were responsible for a substantial share of all crypto theft globally.

Mitchell Amador, CEO of Immunefi, acknowledged the structural challenge while pointing to emerging defenses.

On DeFi specifically, Amador noted that “we could argue that DeFi is getting safer due to improved security maturity, though DeFi still operates in one of the most adversarial environments in software.”

The data supports a cautiously mixed picture. DeFi’s 44.8% year-over-year decline in losses suggests that audit culture, formal verification, and bug bounty programs are working at the protocol level. But CeFi’s 77.5% surge, combined with the Bybit breach, shows that the industry’s largest custodial platforms remain vulnerable to sophisticated, targeted attacks that exploit human processes rather than code.

Concrete defensive measures gaining traction include multi-signature verification improvements, front-end integrity checks, and expanded bug bounty programs. Immunefi alone has facilitated over $100 million in bounty payouts to white-hat hackers. Whether these measures can scale fast enough to outpace state-sponsored attackers with billion-dollar incentives will define the next phase of crypto’s security evolution.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0003249
$0.0003249$0.0003249
-0.36%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52
Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

Vistra (VST) Stock Drops 7% as Insider Sales Spook the Market

TLDR Vistra (VST) stock fell as much as 7.16% as investors reacted to heavy insider selling by the CEO and top executives filed with the SEC. The stock also hit
Share
Coincentral2026/03/21 01:25
BlockchainFX or Based Eggman $GGs Presale: Which 2025 Crypto Presale Is Traders’ Top Pick?

BlockchainFX or Based Eggman $GGs Presale: Which 2025 Crypto Presale Is Traders’ Top Pick?

Traders compare Blockchain FX and Based Eggman ($GGs) as token presales compete for attention. Explore which presale crypto stands out in the 2025 crypto presale list and attracts whale capital.
Share
Blockchainreporter2025/09/18 00:30