Largest Crypto Hacks 2025-2026: $3.63B Stolen | KarCrypto
SECURITY · STATISTICS · COINGECKO REPORT

Largest Crypto Hacks 2025–2026: $3.63B Stolen

From January 2025 through July 2026, hackers drained $3.63 billion from crypto platforms across 245 separate incidents. We break down CoinGecko's report data, the top 20 hacks, and why a completed security audit doesn't guarantee your funds are safe.

Largest crypto hacks 2025-2026, CoinGecko statistics

Quick answer

From January 2025 through July 2026, hackers stole $3.63 billion from crypto platforms across 245 incidents (CoinGecko State of Crypto Security Report 2026). The largest was the Bybit hack at $1.436 billion in February 2025, attributed to North Korea's Lazarus Group. The top 10 attacks made up more than 72.5% of total losses, and 60% of hacked platforms had passed an independent security audit — yet those audited projects accounted for 88.44% of the stolen funds.

The crypto industry keeps losing billions of dollars to hacks, and the scale of the problem isn't shrinking year over year. The CoinGecko State of Crypto Security Report 2026, published on August 27, 2026, tracked 245 confirmed hack incidents across crypto platforms between January 2025 and July 2026. Combined losses reached $3.63 billion, and that's only counting the largest tracked incidents.

Below we break down the full top-20 hack ranking, details on the five largest incidents with links to primary sources, North Korea's role in this picture, and the report's most uncomfortable finding: a completed smart contract audit is nowhere near a safety guarantee.

Top 20 Largest Crypto Hacks, 2025–2026

The table below ranks the 20 largest confirmed incidents from the reporting period by amount stolen.

#PlatformLoss
1Bybit$1,436M
2KelpDAO$292M
3Drift Protocol$285M
4Cetus$223M
5Balancer$128M
6Bitget$100M
7Nobitex$90M
8Phemex$74M
9BTCTurk$52M
10Infini$50M
11CoinDCX$44M
12GMX$42M
13Swissborg$42M
14UXLink$41M
15Humanity Protocol$36M
16Step Finance$27M
17BigONE$27M
18Truebit$26M
19Resolv Labs$25M
20SBI Crypto$24M

Source: CoinGecko, State of Crypto Security Report 2026. Figures reflect reported loss amounts at time of publication.

Notice the gap between first and second place: the Bybit hack is nearly five times larger than the next biggest incident. From third place down to twentieth, though, the list looks much more uniform. These aren't exchange giants anymore, they're mostly mid-size DeFi protocols, which points to something important: attackers aren't only going after the platforms with the biggest reserves, they're going after whoever has the weakest defenses.

Bybit: The Largest Crypto Heist in History

On February 21, 2025, Bybit lost more than $1.4 billion, including 401,347 ETH, drained from its cold wallet. This is the largest cryptocurrency theft ever recorded, as confirmed by NCC Group's technical analysis.

Attackers compromised the development environment of Safe{Wallet}, a widely used multisig wallet solution that Bybit relied on, requiring at least three signers to approve any transaction. During a routine transfer from the cold wallet to a hot wallet, hackers altered what Bybit's signers saw when approving the transaction, causing them to unknowingly authorize a transfer to attacker-controlled addresses.

Within 48 hours, blockchain investigators linked the attack to North Korea's Lazarus Group. The FBI confirmed that the group, also known as TraderTraitor and APT38, was behind the theft. An estimated $160 million of the stolen funds was laundered within the first 48 hours, with the remainder quickly converted into Bitcoin and other assets and dispersed across thousands of addresses to obscure the trail.

KelpDAO: 2026's Largest DeFi Exploit

In April 2026, an attacker exploited Kelp DAO's LayerZero-powered bridge and drained 116,500 rsETH, worth approximately $292 million and representing roughly 18% of the token's circulating supply. Per Chainalysis's breakdown, the root cause was the bridge's 1-of-1 verifier configuration: when receiving messages over the cross-chain LayerZero protocol, only a single node checked those messages before releasing funds.

By forcing legitimate nodes offline, the attackers isolated the sole verifier in a controlled environment and got it to approve a fraudulent instruction. After obtaining the tokens, the attacker deposited 89,567 rsETH as collateral on Aave and borrowed $190.86 million in wrapped Ether against it, before Aave managed to freeze rsETH markets. The company attributed the incident to TraderTraitor (also tracked as UNC4899), a group linked to North Korea, citing research from Mandiant, CrowdStrike, and other security firms.

Drift Protocol: $285M in 12 Minutes

On April 1, 2026, Solana's largest decentralized derivatives platform, Drift Protocol, lost roughly $285 million in a coordinated window lasting about 12 minutes. Per TRM Labs' investigation, the attack was the culmination of a months-long, meticulously planned social engineering operation by the DPRK that began in the fall of 2025.

Attackers used a fake token and a compromised admin key to manipulate oracles and drain vaults. Drift attributed the hack with medium confidence to a North Korean state-sponsored group tracked under the cryptonyms UNC4736, AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. According to Chainalysis's analysis, the attack wiped out more than half of the protocol's total value locked.

Cetus: A $223M Overflow Bug

On May 22, 2025, Cetus Protocol, a major decentralized exchange on the Sui blockchain, suffered an exploit through a subtle arithmetic overflow bug that allowed an attacker to drain approximately $223 million. Per Halborn's breakdown, the vulnerability lived in the checked_shlw function of Cetus's smart contract library.

The attack began with a flash loan, followed by opening a position with an extremely narrow tick range, causing the liquidity calculation to overflow so that depositing just one token registered as depositing a vastly larger amount of liquidity. Following the incident, Cetus suspended the affected smart contract and froze roughly $162 million of the stolen assets directly on the Sui blockchain, while about $60 million had already been bridged to Ethereum. The project offered to drop all legal action against the attacker in exchange for returning the funds and announced a $5 million bounty for information leading to their identification.

Balancer: $128M Through a Rounding Error

On November 3, 2025, Balancer, a DeFi liquidity protocol managing $678 million in investor assets, lost $128 million in a suspected malicious exploit. Per DL News, the exploit combined two attack vectors: a precision rounding error in the vault's swap calculations, which the attacker exploited by chaining multiple swaps, and invariant manipulation through deploying malicious contracts and minting fake tokens.

The heaviest impact hit the Ethereum deployment, with $100 million drained from it. Several other protocols that reused Balancer's open-source code were also exposed, with Beets Finance reporting roughly $3 million in losses.

Dealing with a similar situation?

We check addresses for exposure to hacked platforms and prepare an evidentiary package for an exchange or law enforcement.

Blockchain Analysis

North Korea's Role: The Bigger Picture

Of the five largest hacks broken down above, at least three (Bybit, KelpDAO, and Drift Protocol) have been attributed to North Korean hacking groups. This isn't a coincidence, it's a systemic trend documented in a separate Chainalysis 2026 Crypto Crime Report.

According to Chainalysis, North Korean hackers stole at least $2.02 billion in cryptocurrency in 2025, a 51% increase year over year. That means the DPRK was responsible for roughly 60% of all funds stolen that year, and the cumulative lower-bound estimate for cryptocurrency stolen by North Korea since 2017 now exceeds $6.75 billion. The same report notes that North Korean groups increasingly achieve these outsized results by embedding their own IT workers directly inside crypto companies under the guise of ordinary employees, gaining privileged access to infrastructure: DPRK-linked activity accounted for a record 76% of all service compromises through insider access. The stolen funds reportedly end up funding the regime's weapons of mass destruction program.

Why Security Audits Don't Save You

One of the report's most uncomfortable findings concerns the role of smart contract audits. Of the 245 platforms hacked during the reporting period, 147, roughly 60%, had previously completed an independent security audit. Yet those audited projects accounted for 88.44% of all funds stolen. Only 11% of breaches involved vulnerabilities that a standard smart contract audit would even cover.

The explanation is fairly simple: an audit checks smart contract code for known vulnerability classes, but it doesn't cover infrastructure and organizational risk, things like a compromised development environment (as in the Bybit case), social engineering targeting employees (as in the Drift Protocol case), or a cross-chain bridge with a single point of failure (as in the KelpDAO case). Per the report, infrastructure and supply-chain vulnerabilities were the single largest source of losses, more than $1.8 billion, while smart contract exploits at DeFi applications directly cost the industry $546 million. Centralized exchanges, for their part, were hit most often through private key compromises.

The practical takeaway: a line reading "audited by [well-known firm]" on a project's website is not a guarantee that your funds are safe. An audit reduces one class of risk while leaving the rest wide open.

Attack Vectors: Where the Money Actually Goes

Grouping all 245 incidents by root cause produces a fairly clear picture. Per the CoinGecko report, the largest source of losses was infrastructure and supply-chain vulnerabilities, more than $1.8 billion, roughly half of the total stolen. This category covers everything that isn't a bug in the smart contract itself: a compromised development environment (Bybit), a compromised admin key (Drift Protocol), a single point of failure in a cross-chain bridge (KelpDAO). What these attacks have in common is that they don't happen in publicly reviewable code, they happen inside a company's closed infrastructure, somewhere an external auditor simply doesn't have access.

The second-largest source of losses was smart contract exploits at DeFi applications, accounting for $546 million. This is the category an audit is theoretically supposed to catch: rounding errors (Balancer), integer overflows (Cetus), logic bugs in liquidity calculations. That's exactly why an audit, while no silver bullet, still matters, without it this category of attack would almost certainly be much larger.

The third vector is specific to centralized exchanges: private key compromise. Unlike DeFi protocols, where the attack logic usually hinges on code, exchanges more often lose funds due to plain operational negligence: poorly secured key storage, insufficient separation of signing authority, no multi-layer review before large transfers. That's ultimately what brought down Bybit: the exchange technically had a multisig setup, but a compromised development environment at its wallet provider erased the extra protection that setup was supposed to provide.

What to Do If You Use One of the Affected Platforms

If you held or still hold funds on one of the platforms listed above, there are a few concrete steps worth taking now rather than waiting for the next incident.

Check for compensation programs. After major hacks, some exchanges and protocols launch partial reimbursement programs (as happened, at least in part, following the Bybit and Cetus attacks). This information is usually posted through the platform's official channels and requires an active claim within a set deadline.

Don't rely on a single custody model. If a significant sum is sitting on an exchange purely out of convenience, it's worth reconsidering. A non-custodial wallet with cold storage of the seed phrase removes the risk tied specifically to third-party infrastructure, though it shifts responsibility for safekeeping the wallet itself onto you.

Watch for overlap with attacker-controlled addresses. If you received transfers from counterparties on any of the affected platforms shortly before or after an incident, there's a chance a portion of stolen funds passed through a chain that included your address, even without your knowledge. This doesn't imply wrongdoing, but it can trigger an automatic freeze when you try to withdraw on another exchange.

What This Means for You

Even if you've never used any of the platforms listed above, your exposure isn't limited to directly using a hacked service. Stolen funds pass through dozens of intermediary addresses, mixers, and bridges before landing on an exchange for cash-out, and any address that ever touched that chain risks getting an AML flag when trying to withdraw on a legitimate exchange, even if the address owner has nothing to do with the original hack.

If you received cryptocurrency from a counterparty whose reputation you don't know, or your exchange account was suddenly frozen without explanation after one of the platforms above was hacked, it's worth checking the address beforehand rather than after the fact. We cover this mechanic in more detail in our article on how to recover stolen crypto.

The report's core finding

Losses aren't shrinking despite a growing number of completed audits, which means the burden of protection increasingly falls on users and companies themselves, through monitoring counterparty addresses, independent AML screening of incoming funds, and reacting quickly at the first sign of compromise. Waiting for the platform to protect you is no longer a viable strategy.

"Every major hack from 2025 and 2026 shares one thing in common: the money doesn't disappear, it moves. The earlier tracing begins after an incident, the higher the chance of freezing funds before they dissolve into a chain of intermediaries for good."

If you're dealing with a frozen exchange account, suspect you received tainted cryptocurrency, or your address turned out to be connected to a hacked platform, we work these cases every week. A good place to start is our exchange unfreeze service.

Frequently Asked Questions

How much crypto was stolen in 2025-2026?
According to CoinGecko's State of Crypto Security Report 2026, hackers stole $3.63 billion from crypto platforms across 245 separate incidents between January 2025 and July 2026. The top 10 attacks alone accounted for more than 72.5% of total losses.
What was the largest crypto hack?
The largest was the Bybit hack on February 21, 2025, worth roughly $1.4-1.5 billion. Hackers from the North Korean Lazarus Group compromised the development environment of the Safe{Wallet} multisig solution and spoofed the transaction data that Bybit's signers saw when approving a routine transfer.
Why is North Korea connected to so many of these hacks?
According to Chainalysis, North Korean hacking groups (Lazarus, TraderTraitor, APT38, and related units) stole at least $2.02 billion in cryptocurrency in 2025 alone, roughly 60% of all funds stolen that year. The cumulative lower-bound estimate for DPRK crypto theft since 2017 exceeds $6.75 billion.
Do security audits protect against hacks?
Not fully. Per CoinGecko, 147 of 245 hacked platforms in this period (60%) had completed an independent security audit before the attack, yet these audited platforms accounted for 88.44% of all funds drained. Only 11% of breaches involved vulnerabilities that a standard smart contract audit would even cover.
Can stolen funds be recovered after a crypto exchange or protocol hack?
Sometimes. If stolen funds land on a centralized exchange, they can be frozen through compliance procedures or traced with blockchain forensics for a subsequent law enforcement filing. The odds of recovery depend heavily on how quickly you act after the incident.

Check If Your Address Is Connected to a Hack

Free address check plus full transaction analysis for complex cases. From $500.

Free initial address check
NDA signed before case details are shared
Chainalysis, TRM Labs, Elliptic
We work with Binance, Bybit, OKX, MEXC and more
Tell us about your case
We respond on Telegram within 15 minutes
Address check Account frozen Transaction analysis Other
under $5K $5K-$50K $50K-$500K $500K+

By submitting you agree to data processing. NDA available on request.