$2B lost to crypto hacks in Q1 2025, $1.63B from access control flaws
Over $2 billion was lost to cryptocurrency hacks in the first quarter of 2025.According to a report shared with Cointelegraph by crypto cybersecurity firm Hacken, in Q1 2025, nearly $1.63 billion was lost just to access...
Over $2 billion was lost to cryptocurrency hacks in the first quarter of 2025.
According to a report shared with Cointelegraph by crypto cybersecurity firm Hacken, in Q1 2025, nearly $1.63 billion was lost just to access control exploits. Anmol Jain, vice president of investigations at crypto forensics firm AMLBot, told Cointelegraph that the exceptionally high figure is mainly attributable to the recent hack of the crypto exchange Bybit.
The data is similar to that recently shared by crypto cybersecurity firm PeckShield. The competing firm’s report — which excludes scams — suggested that crypto hacks total at $1.6 billion in Q1 2025.
Total 2025 Q1 crypto hack losses by category. Source: Hacken
Late February reports indicate that the North Korean hackers behind the $1.4 billion Bybit hack control over 11,000 cryptocurrency wallets used to launder stolen funds. The increasing participation of North Korean state actors highlights increasing sophistication and scale.
This hack had a significant impact on this quarter’s figures. This is particularly clear when one considers that the entirety of 2024 saw a total loss of $2.25 billion. Hacken shared a key lesson on the subject:
“Securing digital assets requires more than just secure on-chain code — the entire infrastructure, from front-end interfaces to internal processes, must be equally hardened, as all it takes is a single weak spot to wreck the entire system.“No one is safeHacken’s report highlighted that the past few months saw “even the biggest centralized and decentralized players falling victim to operational failures, access control weaknesses, and in a few cases, social engineering.” The quarter did not see any notable new exploits, “but rather the continued effectiveness of existing attack vectors.”
The report further highlights that, while smart contract vulnerabilities remain an issue, “most damage is now caused by failures in people, processes, or permission systems.” This is also reportedly the third quarter in a row that has seen the top exploit be a multisignature wallet-related hack.
The ByBit hackers compromised the Safe{Wallet} front end. Previous hacks involving multisignature wallet implementations or management include the Radiant Capital hack in Q4 2024 and the WazirX hack in Q3 2024.
The crypto scam industryScams also resulted in large-scale damage, with Hacken data attributing $96.37 million of losses to phishing scams and $300 million to rug pulls. Jain also highlighted a troubling trend in crypto scams becoming an industry:
“The most worrying trend is the professionalization of scam networks, where criminals operate with startup-like efficiency, including ‘training programs’ for scammers, internal quotas, and multi-stage laundering schemes using platforms like Huione Pay.“The statement follows mid-January reports that Huione, often described as”“the largest online illicit marketplace to have ever operated”” highlighted that the service has seen its monthly inflows increase by 51% in just half a year. This growth followed the platform's deployment of its USD-pegged stablecoin and financial services dedicated to illegal activities.
Anmol highlighted that “most pig butchering scams originate from Southeast Asian cybercrime compounds,” with many being located in Cambodia, Myanmar and Laos, with some presence in Thailand. The operators also often “employ” human trafficked young people from India, Nepal, Vietnam, and the Philippines.
Magazine: China’s ‘point running’ crypto scams, pig butchers kidnap kids: Asia Express
Original source
Read on CointelegraphRelated market context
Defillama: Q2 2026 Has Been Crypto’s Most-Hacked Quarter on Record With Nearly 70 Exploits
The last three months of 2026 have become the most-hacked quarter in crypto history, with roughly 70 separate exploits draining ab...
Humanity Protocol’s $36M hack linked to suspected North Korean hackers, Quantstamp reports
The incident underscores the urgent need for improved cybersecurity measures and key management practices to protect against sophi...
SpaceX’s $75 Billion IPO at $135 Sparks Fresh Crypto Bets
Key Takeaways: SpaceX’s IPO was priced at $135 a share to raise a record $75 billion. Offering will value the company at about $1....
Banks are buying Bitcoin vaults, but a quantum problem may be waiting inside
The banks are finally buying the vaults. In May, BNY, the world's largest custodian with $59.4 trillion in assets under custody an...
Coinbase Quantum Report Warns Millions Of Bitcoin Could Face Future Security Risks
TL;DR Coinbase’s Quantum Advisory Council published a report on post-quantum migration and abandoned coins. The report estimates t...
Kraken Enables USDCx Deposits And Withdrawals On Canton Network
TL;DR Kraken has enabled deposits and withdrawals of USDCx on Canton Network. USDCx is backed 1:1 by USDC held in Circle’s xReserv...