
2025 Crypto Theft Reaches $3.4 Billion, North Korea Leads Attacks
Total cryptocurrency theft passed $3.4 billion from January through early December 2025, with the February breach of the Bybit exchange alone accounting for $1.5 billion, according to the Chainalysis 2026 Crypto Crime Report. The data reveals a shift in theft patterns across four key areas: North Korea's persistent role as the primary threat, increasingly severe attacks on centralized services, a surge in personal wallet compromises, and an unexpected divergence in DeFi hack trends. North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a year-over-year increase that pushed their all-time total to $6.75 billion despite carrying out fewer attacks. Chainalysis notes that the DPRK is achieving larger thefts with fewer incidents by embedding IT workers inside crypto services to gain privileged access, and more recently by inverting that model: DPRK-linked operators now impersonate recruiters for prominent web3 and AI firms, running fake hiring processes with 'technical screens' designed to harvest credentials, source code, and VPN or SSO access to the victim's current employer. At the executive level, similar social engineering comes in the form of bogus outreach from purported strategic investors or acquirers, who use pitch meetings and pseudo-due diligence to probe for sensitive systems information and potential access paths into high-value infrastructure. The report also finds that North Korea shows clear preferences for Chinese-language money laundering services, bridge services, and mixing protocols, with a 45-day laundering cycle following major thefts. Personal wallet compromises surged to 158,000 incidents affecting 80,000 unique victims in 2025, though the total value stolen from these wallets fell to $713 million, down from 2024. Chainalysis said that without the outsized impact of the Bybit attack, the share of personal wallet thefts in overall stolen value would have been higher. Centralized services continue to experience increasingly large losses due to sophisticated attacks on private key infrastructure and signing processes. Despite institutional resources and professional security teams, these platforms remain vulnerable to advanced threats that can circumvent cold wallet controls. Many attackers have developed methods to exploit third-party wallet integrations and trick legitimate signers into authorizing malicious transactions, Chainalysis said. Stolen fund activity has always been outlier-driven, but 2025 reveals a striking escalation: the ratio between the largest hack and the median of all incidents crossed the 1,000x threshold for the first time, surpassing even the 2021 bull market peak. The calculations are based on the USD values of funds stolen at the time of the theft. The top three hacks of 2025 account for a major share of all service losses, concentrating the year's damage in a few catastrophic events. Meanwhile, in decentralized finance (DeFi), hack losses remained suppressed in 2024-2025 despite increased total value locked, which Chainalysis says suggests improved security practices are making a meaningful difference. The 2026 Crypto Crime Report highlights these four developments and warns that while some areas of crypto security may be improving, attackers continue to find success across multiple vectors. The persistence of high theft volumes shows that the industry still faces significant challenges even as individual defenses strengthen. The 158,000 personal wallet compromises are a direct concern for Somali crypto users, whether they hold funds on exchanges or use digital currency for remittances. Unsolicited job offers or investment pitches may be attempts to steal credentials, and private keys or VPN/SSO access should never be shared. The Bybit loss shows even major platforms can be compromised, so verifying any request through official channels is now essential.
Read our sourcing and corrections policy



Be the first to comment on this story!