
{"id":129626,"date":"2026-01-24T11:30:41","date_gmt":"2026-01-24T11:30:41","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=129626"},"modified":"2026-01-24T11:30:41","modified_gmt":"2026-01-24T11:30:41","slug":"navigating-the-storm-lessons-from-2025-crypto-attacks-in","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=129626","title":{"rendered":"Navigating the Storm: Lessons From 2025 Crypto Attacks in"},"content":{"rendered":"<h3>Navigating the Storm: Lessons From 2025 Crypto\u00a0Attacks<\/h3>\n<p>2025 was a turbulent year for crypto security. According to blockchain analytics firm <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2026\/\">Chainalysis, <strong>over $3.4 billion<\/strong><\/a><strong> <\/strong>was stolen through <strong>hacks and thefts<\/strong>, and about <strong>$17 billion<\/strong> was stolen in <strong>crypto scams and fraud<\/strong> in 2025 (with at least $14 billion identified onchain so far). <a href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2010960699766563200\">PeckShield reported<\/a> <strong>~$4.04 billion <\/strong>in combined losses in 2025, split between <strong>~$2.67 billion<\/strong> (up ~24.2% YoY) from hacks and <strong>~$1.37 billion<\/strong> from scams and phishing. <a href=\"https:\/\/www.certik.com\/resources\/blog\/hack3d-the-web3-security-report-2025\">CertiK reported<\/a> <strong>$3.35 billion <\/strong>lost in 2025 across hacks, scams, and exploits (about +37% vs. 2024), while stressing the theme of <strong>fewer but larger\u00a0attacks<\/strong>.<\/p>\n<p>According to <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2026\/\">Chainalysis<\/a>, total value stolen from <strong>centralized services<\/strong> hit <strong>$2.5 billion<\/strong> across fewer incidents in 2025: <strong>the top three hacks<\/strong> accounted for <strong>69% of all service losses<\/strong>. The number of personal wallet <strong>compromises<\/strong> is rising and DeFi hack losses stayed comparatively muted even as TVL recovered. <a href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2010960699766563200\">PeckShield<\/a> reported that attackers shifted from DeFi to CEXs and large organizations, using <strong>supply-chain attacks<\/strong> and <strong>private-key compromises<\/strong>, driving these targets\u2019 share of total losses to 75%, up <strong>46%<\/strong> from\u00a02024.<\/p>\n<p>In this blog post, we focus on software-related attacks, excluding phishing and scam. We rely on major reports for metrics like total value stolen (TVS), incident counts, and year-over-year changes, and include hands-on technical examples from forensic investigations showing how vulnerabilities were exploited. One pattern stands out: While <strong>DeFi hack losses<\/strong> stayed comparatively <strong>muted<\/strong> even as TVL recovered, <strong>attackers shifted attention to<\/strong> <strong>personal wallets<\/strong> and <strong>centralized services<\/strong>.<\/p>\n<p>Source: <a href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2011325790580056492\/photo\/1\">Peckshield<\/a><\/p>\n<h3>Supply Chain and Software Distribution Compromises<\/h3>\n<p>Certik called the Supply Chain (exploits of blockchain-based dependencies, CI\/CD, and wallet integrations) \u201cthe most costly attack vector\u201d, totaling <strong>$1.4 billion<\/strong> losses across <strong>2<\/strong> incidents.<\/p>\n<h4>Technical Details and Attack\u00a0Examples<\/h4>\n<p>Centralized platforms breaches often blend <strong>social engineering<\/strong> with <strong>operational access<\/strong>. A common method involves \u201cembedded IT worker\u201d infiltration and related recruiter impersonation, which can yield privileged access to systems, source code, and signing workflows. Once inside, attackers exploit private key infrastructure by bypassing cold wallet controls\u200a\u2014\u200ae.g., tricking multisig signers into approving malicious transactions via altered interfaces.<\/p>\n<p><a href=\"https:\/\/learn.bybit.com\/en\/this-week-in-bybit\/bybit-security-incident-timeline\"><strong>Bybit \/ Safe{Wallet} UI Compromise<\/strong><\/a><strong> (February 2025)<\/strong>: Bybit suffered the largest cryptocurrency theft ever. Attackers induced signer to sign a malicious transaction during what appeared to be a routine cold-to-hot transfer, stealing <strong>~401,000 ETH<\/strong> (<strong>~$1.5 billion<\/strong>). <a href=\"https:\/\/www.nccgroup.com\/research-blog\/in-depth-technical-analysis-of-the-bybit-hack\/\">Post-incident analyses<\/a> revealed that attackers injected malicious JavaScript code into the Safe{Wallet} UI on a compromised developer machine, altering transaction displays to deceive signers into authorizing fund transfers. <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2026\/\">Chainalysis reported<\/a> that an experienced group of hackers was behind the\u00a0attack.<a href=\"https:\/\/thehackernews.com\/2025\/12\/trust-wallet-chrome-extension-bug.html\"><strong>Trust Wallet Extension Exploit <\/strong><\/a><strong>(December 2025)<\/strong>: <a href=\"https:\/\/trustwallet.com\/blog\/announcements\/trust-wallet-browser-extension-v268-incident-community-update\">Trust Wallet posted<\/a> about a malicious Chrome Web Store <strong>browser extension (v2.68) <\/strong>published outside its normal release process. The malware could access sensitive wallet data, transmit recovery phrases to phishing domains like metrics-trustwallet.com and trigger unauthorized transactions. Trust Wallet reported <strong>2,520<\/strong> affected wallet <strong>addresses<\/strong>, with <strong>~$8.5M<\/strong> in impacted assets tied to <strong>17<\/strong> attacker-controlled addresses.<a href=\"https:\/\/thehackernews.com\/2025\/08\/ai-generated-malicious-npm-package.html\"><strong>AI-generated npm Drainer<\/strong><\/a><strong> (Jul 2025): <\/strong>Malware showed up as \u201cdeveloper tooling,\u201d like the AI-generated npm package <strong>@kodane\/patch-manager<\/strong>, reported to have <strong>1,500+ downloads<\/strong> before takedown and designed to drain Solana\u00a0wallets.<a href=\"https:\/\/bigone.zendesk.com\/hc\/en-us\/articles\/48916067512345-BigONE-Security-Incident-Disclosure-and-Progress-Update-July-16\"><strong>BigONE Exchange Back-End Logic Tampering<\/strong><\/a><strong> (Jul 2025)<\/strong>: <a href=\"https:\/\/bigone.zendesk.com\/hc\/en-us\/articles\/48916067512345-BigONE-Security-Incident-Disclosure-and-Progress-Update-July-16\">BigONE reported<\/a> abnormal movements of some platform\u2019s assets. <a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-big-one-hack-july-2025\">Halborn explained<\/a> that the attackers exploited their access to alter BigONE\u2019s <strong>backend account<\/strong> and risk-control logic to auto-approve withdrawals. A <strong>back-end logic tampering <\/strong>allowed them to submit unauthorized withdrawal requests to steal about <strong>$27 million<\/strong> in total across multiple\u00a0chains.<strong>SwissBorg \/ Kiln Endpoint Compromise (Sep 2025): <\/strong><a href=\"https:\/\/swissborg.com\/blog\/sol-earn-incident-swissborg-recovery\">Swissborg reported<\/a> a third-party endpoint compromise, a malicious transaction path leading the loss of funds from SOL Earn. Blockchain investigator ZachXBT reported that Swissborg lost approximately $40 million worth of\u00a0SOL.<\/p>\n<h3>Protocol Exploits<\/h3>\n<p>DeFi hacks declined relatively to 2024, with losses suppressed despite Total Value Locked (TVL) growth. <a href=\"https:\/\/www.chainalysis.com\/blog\/crypto-hacking-stolen-funds-2026\/\">Chainalysis<\/a> attributes this to improved security and \u201ctarget substitution\u201d toward wallets and centralized services. <a href=\"https:\/\/www.certik.com\/resources\/blog\/hack3d-the-web3-security-report-2025\">CertiK reported<\/a> DeFi total value stolen around <strong>$500\u2013700 million<\/strong> across <strong>344<\/strong> incidents in\u00a02025.<\/p>\n<h4>Technical Details and Attack\u00a0Examples<\/h4>\n<p>Common DeFi smart contract flaws include: reentrancy (recursive calls draining funds), faulty input validation (34.6% of cases), oracle manipulation, access-control mistakes, and governance logic weaknesses. <strong>Flash loans, <\/strong>borrowing uncollateralized funds to manipulate markets, remain a frequent accelerator for\u00a0attacks.<\/p>\n<p><a href=\"https:\/\/slowmist.medium.com\/slowmist-analysis-of-the-230-million-cetus-hack-ee569af040f2\"><strong>Cetus DEX Exploit<\/strong><\/a><strong> (May 2025)<\/strong>: Cetus, a leading DEX on the Sui blockchain, was <a href=\"https:\/\/cetusprotocol.notion.site\/Cetus-Incident-Report-May-22-2025-Attack-Disclosure-1ff1dbf3ac8680d7a98de6158597d416\">exploited<\/a> via a flaw in its <strong>math<\/strong> logic, allowing the attacker to drain liquidity across 46 liquidity pairs. Reported estimates put the stolen amount at ~$230\u00a0million.<a href=\"https:\/\/x.com\/Balancer\/status\/1986104426667401241\"><strong>Balancer v2 Pools Exploit<\/strong><\/a><strong> (November 2025)<\/strong>: About <a href=\"https:\/\/www.dlnews.com\/articles\/defi\/balancer-suffers-128m-exploit-despite-multiple-audits\/\">$128 million<\/a> was drained from Balancer v2 Composable Stable Pools after attackers exploited the <strong>incorrect rounding behavior<\/strong> in the protocol. Using carefully crafted batchSwap sequences, the attackers manipulated pool balances and extracted value repeatedly across multiple chains. Some believe that the attack was <a href=\"https:\/\/x.com\/AdiFlips\/status\/1985311134308573467\">vibe-coded<\/a>.Source: <a href=\"https:\/\/slowmist.medium.com\/when-small-flaws-collapse-a-giant-inside-balancers-100m-hack-85b9e92a9ae3\">Slowmist<\/a><a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-upcx-hack-april-2025\"><strong>UPCX Malicious Smart Contract Upgrade<\/strong><\/a><strong> (Apr 2025): <\/strong>The attackers, according to <a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-upcx-hack-april-2025\">Halborn\u2019s analysis<\/a>, compromised private key of a privileged admin account, probably via social engineering or malware. They exploited this access to perform an unauthorized upgrade of the ProxyAdmin contract to steal <strong>18.4 million UPC tokens<\/strong> (~<strong>$70 million<\/strong>) from multiple management accounts.<a href=\"https:\/\/x.com\/Shibtoken\/status\/1968419499528581286\"><strong>Shibarium Bridge Exploit<\/strong><\/a><strong> (September 2025)<\/strong>: Attackers combined a <strong>flash loan<\/strong> with <strong>compromised validator keys <\/strong>to steal <strong>$2.4\u200a\u2014\u200a4.1<\/strong> million in assets. They used the flash loan to acquire a large amount of BONE, then delegated it to gain over two-thirds of voting power and push a <strong>fake network update<\/strong>. With validator key access, they were able to sign the malicious update and execute <strong>unauthorized withdrawals<\/strong> from the\u00a0bridge.<\/p>\n<h3>Key and Signing Infrastructure Compromises<\/h3>\n<p>Key and signing infrastructure compromises happen when attackers gain or abuse the ability to <strong>sign transactions<\/strong>, rather than exploiting smart contract code. These incidents look like attackers stealing keys, extracting signing shares, or subverting approval workflows so legitimate-looking signatures authorize malicious withdrawals across one or many\u00a0chains.<\/p>\n<h4>Technical Details and Attack\u00a0Examples<\/h4>\n<p>These attacks target hot wallets, signing servers, MPC\/HSM systems, validator keys, or approval workflows, so malicious withdrawals look legitimate onchain. Once signing authority is compromised, funds can be moved quickly across multiple networks with little chance of reversal.<\/p>\n<p><a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-wemix-hack-march-2025\"><strong>Wemix Auth Keys Compromise<\/strong><\/a><strong> (detected Feb 2025, disclosed later):<\/strong> Halborn\u2019s analysis reports that attackers allegedly <strong>stole authentication<\/strong> <strong>keys<\/strong> used to access a <strong>service monitoring system<\/strong> (NILE). The keys may have been exposed via a shared repository. The attacker then executed withdrawals of <strong>8.6 million<\/strong> WEMIX tokens, with the incident resulting in over <strong>$6 million<\/strong> in losses per <a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-wemix-hack-march-2025\">Halborn<\/a>, and disclosure lagged by\u00a0weeks.<strong>ModStealer (reported in Sep 2025):<\/strong> <a href=\"https:\/\/metamask.io\/news\/metamask-security-report-september-2025\">MetaMask\u2019s security report<\/a> described ModStealer as <strong>cross-platform infostealer<\/strong> (Windows, Linux, macOS) that hunts for <strong>browser wallet extensions and credentials. <\/strong>Campaigns were distributed through <strong>fake job postings<\/strong> aimed at developers, trying to lure targets into running an installer. MetaMask warned that stolen <strong>private keys and seed phrases<\/strong> can provide direct access to\u00a0funds.<a href=\"https:\/\/finance.yahoo.com\/news\/south-korea-upbit-reports-36-062806194.html\"><strong>Upbit Hot Wallet Breach <\/strong><\/a><strong>(Nov 27, 2025): <\/strong>Upbit exchange disclosed abnormal withdrawals from a <strong>Solana-based hot wallet<\/strong>, revising loss estimate to <strong>KRW 44.5 billion (~$33 million)<\/strong>. <a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-upbit-hack-november-2025\">Halborn\u2019s analysis supposed<\/a> that the incident was potentially related to weaknesses in Upbit\u2019s digital signature algorithm<strong>.<\/strong><a href=\"https:\/\/phemex.com\/announcements\/phemex-hot-wallet-security-incident-update-and-timeline\"><strong>Phemex Hot Wallet Hack<\/strong><\/a><strong> (Jan 2025)<\/strong>: <a href=\"https:\/\/phemex.com\/announcements\/phemex-hot-wallet-security-incident-update-and-timeline\">Phemex exchange disclosed<\/a> that they detected unusual activity in their hot wallet. About <strong>$73 million <\/strong>were<strong> <\/strong>stolen across 16 blockchains. <a href=\"https:\/\/www.halborn.com\/blog\/post\/explained-the-phemex-hack-january-2025\">Halborn<\/a> frames the likely root cause as <strong>compromised private keys<\/strong>. <a href=\"https:\/\/www.theblock.co\/post\/342265\/millions-worth-stolen-funds-phemex-hack-move-tornado-cash-crypto-mixer\">TheBlock reported<\/a> that the hack was likely perpetrated by an experienced group of\u00a0hackers.<\/p>\n<h3>Conclusion<\/h3>\n<p>2025 made one thing obvious: strong cryptography and audited contracts don\u2019t stop losses when attackers compromise the software and workflows that sit around them. The biggest incidents weren\u2019t \u201cblockchain bugs\u201d as much as failures in distribution and signing: tampered wallet interfaces, poisoned dependencies, back-end logic changes, and stolen credentials that turned invalid withdrawals into valid ones. DeFi exploits stayed comparatively muted even as TVL recovered, but centralized services and personal-wallet infrastructure became the easiest way to capture outsized\u00a0value.<\/p>\n<p>Going into 2026, the priority should be hardening the full signing path: We need better digital asset management tools, which are built on multi-factor authentication but without introducing centralization risks, as we notice that attacks target every bit of supply chain. We need to tighten operational controls, secret handling, and transaction verification, because attackers are increasingly targeting wallet infrastructure and signature flow.<\/p>\n<p><em>Note: OKcontract is building <\/em><a href=\"https:\/\/chainwall.org\/\"><em>Chainwall<\/em><\/a><em>, a fully decentralized asset management suite for yield products.<\/em><\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/navigating-the-storm-lessons-from-2025-crypto-attacks-in-d440026d5836\">Navigating the Storm: Lessons From 2025 Crypto Attacks in<\/a> was originally published in <a href=\"https:\/\/medium.com\/coinmonks\">Coinmonks<\/a> on Medium, where people are continuing the conversation by highlighting and responding to this story.<\/p>","protected":false},"excerpt":{"rendered":"<p>Navigating the Storm: Lessons From 2025 Crypto\u00a0Attacks 2025 was a turbulent year for crypto security. According to blockchain analytics firm Chainalysis, over $3.4 billion was stolen through hacks and thefts, and about $17 billion was stolen in crypto scams and fraud in 2025 (with at least $14 billion identified onchain so far). PeckShield reported ~$4.04 [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":129627,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-129626","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interesting"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/129626"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=129626"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/129626\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/129627"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=129626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=129626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=129626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}