Crypto platforms have lost more than $3.1 billion to hacks and exploits since the beginning of 2025, according to data from CoinGecko’s 2026 State of Crypto Security Report.
The single largest incident remains Bybit’s February 2025 breach, in which attackers drained approximately $1.4 billion, mostly in Ethereum from the exchange’s multisig wallets, marking the biggest cryptocurrency theft on record.
Bybit’s CEO and co-founder, Ben Zhou, revealed in a livestream announcement that hackers managed to drain 401,346 ETH from one of the company’s cold wallets.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Cold wallets, which are designed to store cryptocurrency offline and away from internet exposure, are considered the most secure way to hold digital assets.
The breach, which was described as a sophisticated attack, sent ripples throughout the digital currency world, raising fresh concerns over the security of even the most well-established crypto exchanges.
After Bybit, the next largest incidents include KelpDAO at roughly $292 million, Drift Protocol at $285 million, and Cetus at $223 million.
KelpDAO Hack
On April 18, 2026, attackers linked to North Korea’s Lazarus Group stole $292 million (116,500 rsETH) from KelpDAO’s LayerZero bridge.
The attackers compromised internal RPC nodes and DDoS’d external nodes to feed false data to a single-point-of-failure verification network (a 1-of-1 DVN setup). This tricked the Ethereum contract into releasing funds based on a phantom token “burn” on the source chain.
Rapid intervention prevented further damage. KelpDAO successfully paused contracts to block a second $95 million theft, and the Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker’s downstream funds.
Drift Protocol Hack
Solana-based decentralized finance platform Drift Protocol was drained of $285 million on April 1, 2026, in one of the largest exploits in crypto history.
Beginning in the 1st of April 2026, an attacker gained admin control of the Drift protocol and proceeded to drain an estimated $285 million from its vaults over the following hours, wiping out more than 50% of its total value locked (TVL).
Strong signals from Drift’s investigation so far indicate that the attack is linked to actors associated with the Democratic People’s Republic of Korea (DPRK), though this is yet to be confirmed.
Cetus Hack
On May 22, 2025, the decentralized exchange Cetus Protocol suffered a major security breach, losing approximately $223 million in under 15 minutes.
The exploit was caused by a rounding/overflow bug in a third-party shared math library (integer-mate and its checked_shlw function) used for pricing and liquidity calculations.
The hacker used flash loans and deposited small amounts of spoof/fake tokens to manipulate price curves and reserve calculations, allowing them to drain real assets like SUI and USDC far beyond what was deposited.
Together, the top ten exploits represent more than 70 percent of all recorded stolen funds during the period covering 2025 through mid-2026.
Many of the biggest breaches targeted infrastructure and operational security rather than pure smart-contract code. Compromised private keys, supply-chain attacks on wallet software, and failures in multisignature approval processes proved especially damaging.
Even platforms that had undergone security audits were not immune; audited protocols still accounted for the large majority of total losses, underscoring the limits of conventional code reviews when the attack surface extends to keys, interfaces, and third-party systems.
Centralized exchanges proved particularly vulnerable to key-compromise incidents, while decentralized applications suffered significant smart-contract exploits totaling hundreds of millions.
Overall incident volume has risen in 2026, yet the average size of each breach has declined compared with the outsized Bybit event that defined 2025. Insurance coverage on-chain has also contracted during the same period, leaving less of a financial backstop for users and protocols.
The pattern points to a persistent structural challenge. As the industry scales, attackers continue to find high-value targets in both centralized and decentralized infrastructure.
The Bybit case, widely attributed to sophisticated actors linked to North Korea’s Lazarus Group, illustrated how a single well-executed compromise of signing infrastructure can produce losses measured in the billions.
Subsequent large exploits against DeFi protocols have reinforced that the threat is not confined to any one segment of the market. While recovery efforts, improved monitoring, and emergency liquidity have mitigated some immediate damage for certain platforms, the cumulative toll continues to climb.
Outlook
Looking ahead, crypto security is likely to remain a major challenge as the industry expands and increasingly valuable assets move across exchanges, DeFi protocols, bridges, and digital wallets.
The growing sophistication of attackers means that security strategies will need to extend beyond traditional smart-contract audits to include stronger key management, transaction monitoring, multisignature controls, infrastructure protection, and third-party risk assessments.



