Cryptopolitan
2025-06-27 09:25:43

Infrastructure attacks caused a loss of $2.1 billion in 2025

TRM Labs reports over $2.1 billion stolen across 75 cryptocurrency incidents during first half of 2025. Infrastructure attacks targeting private keys and seed phrases dominate theft methods while state-sponsored hackers increasingly use cryptocurrency crime for geopolitical objectives. Bybit breach reshapes cryptocurrency theft landscape with $1.5 billion loss The February 2025 Bybit hack was the largest crypto heist ever, with $1.5 billion stolen from the exchange in what TRM Labs attributes to North Korean state actors. The single breach accounted for nearly 70% of overall cryptocurrency losses for the first half of 2025 and changed the dynamics of theft. The Bybit hack escalated the average hack size to almost $30 million, double the $15 million average recorded in H1 2024. Even as much as February was skewed in sheer numbers, January, April, May, and June each recorded over $100 million in total thefts, pointing towards ongoing and widespread threats to the cryptocurrency space. Source: TRM Labs The magnitude of the Bybit hack rendered H1 2025 a record-breaking season for cryptocurrency theft, recording higher volumes of theft than the former H1 record of 2022 by a margin of around 10% and matching total losses of 2024. The trend of theft in this direction is towards the risk concentration at larger centralized exchanges and towards their appeal to experienced threat actors. TRM Labs noted : “This incident alone accounted for nearly 70% of total losses so far this year, pushing the average hack size to nearly USD 30 million, double the USD 15 million average in H1 2024.” North Korean state actors dominate cryptocurrency theft operations TRM Labs data identifies North Korea-linked actors as being behind $1.6 billion of the total of stolen assets in H1 2025 and accountable for approximately 70% of total crypto theft for the period. The all-time high figure, combined with the Bybit hack, indicates continued upward activity by the Democratic People’s Republic of Korea to utilize illicit cryptocurrency gains for strategic purposes. North Korean actions extend from sanctions evasion to support nuclear weapons initiatives and become part of state policy as central components. The quantity of actions cements North Korea’s position as the most active state actor threat within the cryptocurrency space, using digital asset theft as an essential statecraft capability. Other government actors are increasingly using cryptocurrency hacks for geopolitical ends. The reputed Israel-linked Gonjeshke Darande, or Predatory Sparrow, hacked Iran’s largest cryptocurrency exchange Nobitex on June 18, 2025, and stole more than $90 million in what seems politically motivated rather than financially. The hackers transferred the stolen Nobitex funds into unspendable vanity addresses without corresponding private keys. This suggests symbolic or political motivations as opposed to economic ones. Infrastructure attacks dominate theft methods Infrastructure attacks account for over 80% of funds stolen in H1 2025 and are ten times larger on average than all other types of attacks on cryptocurrency infrastructure. Infrastructure attacks target the technical underpinnings of digital asset infrastructure with the goal of achieving unauthorized control, influencing users, or diverting assets through compromised foundational security elements. Private key and seed phrase theft and front-end compromise are the main infrastructure attack vectors that take advantage of the intrinsic vulnerabilities in cryptocurrency security infrastructures. Social engineering and insider actors are normally behind these attacks, revealing vulnerabilities at the core of cryptographic security systems. Protocol exploits were another 12% of total losses, showing continued exposures within decentralized finance smart contracts. They take advantage of exposures within blockchain protocol smart contracts or underlying logic to pilfer or take control of system behavior through techniques such as flash loan and re-entrancy exploits. Cryptopolitan Academy: Tired of market swings? Learn how DeFi can help you build steady passive income. Register Now

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.