Bybit lost nearly $1.5 billion worth of Ether on February 21, 2025, in the largest digital heist in the history of cryptocurrency, according to Chainalysis. Elliptic sizes the same theft at approximately $1.46 billion, and the gap between the two figures is a measurement problem rather than a dispute. Across the full year, Chainalysis counted over $3.4 billion in theft from January through early December 2025. Bybit heads every ranking of the biggest crypto hacks by value stolen.
The eleven largest incidents split across centralized exchanges, cross-chain bridges and DeFi protocols, and only two ended with the money coming back. Every dollar figure below is the value recorded at the time of the heist, which is how both firms report them, so Mt. Gox’s $470 million is a 2014 number and not a present-day one.
Key Takeaways
- The top three hacks of 2025 accounted for 69% of all service losses, so a single bad quarter moves the annual total more than the rest of the year combined.
- North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, despite fewer attacks.
- DPRK attacks accounted for a record 76% of all service compromises in the same year.
- Personal wallet compromises grew from just 7.3% of total stolen value in 2022 to 44% in 2024, moving the target away from custodians.
- TRM Labs counts a smaller pot: North Korea stole over half of the total $2.7 billion lost in 2025 in crypto hacks.
- Tornado Cash laundered more than $7 billion worth of virtual currency since its creation in 2019, including over $455 million stolen by the Lazarus Group, which is why the US Treasury sanctioned it.
- The largest incident of 2026 so far drained $285 million, over 50% of Drift Protocol’s total value locked.
Editor’s Choice
- Bybit remains the record holder at nearly $1.5 billion in ether, or approximately $1.46 billion on Elliptic’s count.
- Poly Network lost $611 million in cryptoassets from a system that moves tokens between blockchains.
- The BSC Token Hub exploit minted BNB with a value of $569 million, after the attacker minted two million BNB into a BSC address.
- Ronin Network lost 173,600 Ether and 25.5 million USD Coins, amounting to $540 million from its cross-chain bridge.
- Coincheck lost $532 million in crypto, carried off as 523 million NEM tokens.
- Criminals raided Mt. Gox of 850,000 BTC, and the exchange collapsed into bankruptcy.
- KelpDAO’s LayerZero bridge released approximately $292 million, or 116,500 rsETH, against a burn that never happened.
The Largest Crypto Hacks Ranked by Value Stolen
- The eleven incidents below total $5.56 billion at the values recorded when each occurred.
- Bybit alone accounts for 26.2% of that combined figure.
- The distance between first and second place is $849 million, wider than any other gap in the ranking.
- Mt. Gox’s stolen bitcoin, adjusted for today’s prices, would amount to around $25 billion, which is why the ranking uses contemporaneous values.
- Drift Protocol’s loss was the largest hack of the year so far and the second-largest security failure in Solana’s history.
- The KelpDAO exploit was not a smart contract hack, but a sophisticated attack on off-chain infrastructure.
- Coincheck is the one unattributed entry, since the hackers are still unknown to this day.
- Euler Finance suffered a loss of $199 million following a flash-loan attack, the smallest entry and the only lending protocol in the ranking.
| Rank | Incident | Value stolen at the time | Date | Target type | Funds recovered |
|---|---|---|---|---|---|
| 1 | Bybit | Nearly $1.5 billion (Chainalysis); approximately $1.46 billion (Elliptic) | February 21, 2025 | Centralized exchange | No; dispersed across thousands of addresses |
| 2 | Poly Network | $611 million | 2021 | Cross-chain bridge | Yes; vast majority returned by the hacker |
| 3 | BNB Chain (BSC Token Hub) | $569 million | October 7, 2022 | Cross-chain bridge | Partly; vast majority kept under control |
| 4 | Ronin Network | $540 million | March 29, 2022 (announced) | Cross-chain bridge | Not stated |
| 5 | Coincheck | $532 million | January 2018 | Centralized exchange | Not stated |
| 6 | Mt Gox | $470 million | February 2014 | Centralized exchange | Not stated |
| 7 | Wormhole Portal | $325 million | February, year not stated | Cross-chain bridge | Yes; Jump Crypto repaid all ether that month |
| 8 | KelpDAO | approximately $292 million | April 18, 2026 | Cross-chain bridge | Not stated; a follow-up attempt was blocked |
| 9 | Drift Protocol | $285 million | April 1, 2026 | DeFi protocol | Not stated |
| 10 | KuCoin | $281 million | September 2020 | Centralized exchange | Not stated |
| 11 | Euler Finance | $199 million | Not stated | DeFi lending protocol | Not stated |
Source: Chainalysis, Elliptic, BNB Chain, FBI IC3, 2014 to 2026
About This Data
Eleven incidents compiled from 30 captured source excerpts across six publishers, spanning 2022-08 to 2026-04. Tier 1 primary and regulatory material supplies most of it, from Chainalysis, the FBI’s IC3, the US Treasury, and BNB Chain. Tier 2 forensics come from Elliptic and TRM Labs. A cell reads Not stated where the cited source does not state it, and figures update when these publishers issue new editions.
Rankings of the biggest crypto hacks built from value stolen at the time are the only version checkable against a contemporaneous source. They are also the version that ages worst. The crypto exchange hack and cyber-risk trends page tracks the aggregate series that sits underneath these individual events.
Crypto Theft by Target Category
- Centralized exchanges account for four entries worth $2,743 million combined.
- Cross-chain bridges account for five entries worth $2,337 million.
- DeFi protocols account for two entries worth $484 million, the smallest of the three groups.
- TRM Labs describes a Bridges Era covering 2021 and 2022, when North Korea aggressively targeted cross-chain bridges like the Ronin Network and Horizon Bridge.
- Attack targets have since shifted from bridges to centralized targets more susceptible to social engineering and developer compromise.
- Compromises of people and platforms yielded consistently higher returns than protocol exploits during the 2024 and 2025 window TRM Labs examined.
By the numbers: Cross-chain bridges supply five of the eleven largest thefts on record, worth $2,337 million together, against $2,743 million from four exchange breaches. TRM Labs records that North Korea aggressively targeted cross-chain bridges like the Ronin Network and Horizon Bridge across 2021 and 2022, and that targets have since shifted from bridges to centralized targets more susceptible to social engineering and developer compromise.
The category split is the part of this dataset that keeps moving. Bridges dominated the middle of the decade because they held pooled collateral behind thin verification logic. Attention swung back to exchanges once social engineering proved cheaper than cryptography. A closer read of how the most expensive exchange breaches unfolded shows the same rotation from the victim side.
Recent Developments
- April 18, 2026: attackers linked to North Korea’s Lazarus Group stole approximately $292 million, or 116,500 rsETH, from KelpDAO’s LayerZero bridge.
- April 2026: LayerZero attributed the operation to the DPRK’s Lazarus Group, and specifically the sub-group known as TraderTraitor, and a follow-up attempt to drain an additional 40,000 rsETH, roughly $95 million, was blocked.
- April 1, 2026: Solana’s Drift Protocol was drained of $285 million, over 50% of its TVL, in an attack likely linked to North Korean actors.
- April 2026: Drift’s loss ranked as the second-largest security failure in Solana’s history.
- March 12, 2026: The US Treasury’s OFAC sanctioned six individuals and two entities for their roles in North Korean IT worker fraud schemes that generated nearly $800 million in 2024.
- December 2025: Chainalysis closed its annual count at over $3.4 billion in theft, with the February compromise of Bybit alone accounting for $1.5 billion of that total.
Bybit, the Largest Crypto Theft on Record
- Attackers moved approximately 401,000 ETH, valued at nearly $1.5 billion at the time, during what looked like a routine cold-wallet transfer.
- The intrusion began off-chain: the hackers gained access to a Safe developer’s computer to control the Safe UI that was specifically used for Bybit transactions.
- They then added the malicious JavaScript to the frontend code to make it look like the signers were signing a legitimate transaction.
- North Korea was responsible for the theft of approximately $1.5 billion in virtual assets from Bybit on or about February 21, 2025, per the FBI’s public service announcement on the Bybit theft.
- TRM Labs reads the same event as evidence that even high-liquidity venues face risks.
| Detail | Bybit, February 21, 2025 |
|---|---|
| Value stolen | nearly $1.5 billion in ether |
| Assets moved | approximately 401,000 ETH |
| Entry point | a Safe developer’s computer and the Safe UI |
| Method | malicious JavaScript in the frontend signing flow |
| Attribution | FBI: North Korea, activity named TraderTraitor |
| Laundering | converted to Bitcoin, dispersed across thousands of addresses |
Source: Chainalysis, FBI IC3, 2025
No smart contract failed here. The signers approved a transaction that had been redrawn in front of them. The incident reads as an interface compromise rather than a protocol one. Custody arrangements and crypto insurance coverage for exchange hacks matter more in that scenario than any audit of the underlying contract.
Ronin Bridge Hack and the Axie Infinity Sidechain
- Ronin announced on March 29, 2022, that 173,600 Ether and 25.5 million USD Coins amounting to $540 million had been stolen from its cross-chain bridge six days earlier.
- Nobody noticed for almost a week: the exploit was only discovered after a 5,000 ETH withdrawal attempt from one of their users failed.
- TRM Labs places the breach inside the Bridges Era, when North Korea aggressively targeted cross-chain bridges like the Ronin Network and Horizon Bridge.
- Those attacks targeted the decentralized finance ecosystem, but the hackers bypassed the digital lock entirely.
The six-day detection gap is the number worth holding onto. A bridge with pooled collateral and no withdrawal monitoring gives an attacker a working week to move funds before anyone reconciles the balance.
Poly Network, the $611 Million Hack That Came Back
- Poly Network lost $611 million in cryptoassets from a protocol that lets users move digital tokens from one blockchain to another.
- Elliptic records the theft as a 2021 event and notes that the vast majority of these funds were eventually returned by the hacker.
- Elliptic describes Bybit as dwarfing the $611 million stolen from Poly Network, the record Poly Network had held until then.
Worth noting: Poly Network sits second on the all-time list and is simultaneously the largest crypto theft that ended with victims made whole. Elliptic records that the vast majority of these funds were eventually returned by the hacker, an outcome no exchange breach of comparable size has ever produced. Attacker motive decides recovery more reliably than incident size does.
BNB Chain and the BSC Token Hub Bridge Exploit
- Binance confirmed an exploit on the Binance Smart Chain (BSC) that resulted in BNB being minted with a value of $569 million.
- The attacker became a relayer for the Binance Bridge (BSC Token Hub) before exploiting a verification proof vulnerability within it, allowing them to mint two million BNB into a BSC address.
- BNB Chain’s own disclosure states that a total of 2 million BNB was withdrawn through the native cross-chain bridge.
- The chain stopped the bleeding by hand: BNB Smart Chain has 26 active validators at present and 44 in total across different time zones, and each was contacted individually.
- The team reported that the vast majority of the funds remain under control.
BNB Chain is the only entry where the minted value and the realized loss diverge sharply. Validators halted the chain before most of the newly minted BNB could leave. The headline figure is what the exploit produced, not what the attacker kept.
Coincheck and Japan’s NEM Theft
- Coincheck lost $532 million in crypto in January 2018, at a Japanese digital asset exchange with no cold-storage separation for the affected asset.
- Elliptic describes it as the world’s biggest heist of its kind at the time.
- The attackers took 523 million NEM tokens in a single sweep.
- Detection lagged badly: the attack wasn’t actually discovered until over eight hours later.
Coincheck is the only incident in the ranking whose attackers remain positively unidentified after eight years, which makes it a useful control case. Most other entries of comparable size, including the larger bridge and exchange thefts, carry no named attribution in this dataset either.
Mt. Gox, the Original Exchange Collapse
- Mt. Gox was breached in February 2014, and Elliptic calls it arguably the most famous crypto hack on its list.
- What was then the world’s largest Bitcoin exchange collapsed into bankruptcy after criminals raided the platform for 850,000 BTC.
- The value of the stolen assets came in at $470 million at the time.
- Adjusted for today’s prices, that same holding would amount to around $25 billion.
The present-day valuation runs roughly 53 times the 2014 figure, which is the single strongest argument for ranking these events at contemporaneous value. A list that marks historic thefts to today’s prices puts the Tokyo exchange at the top by a wide margin. It also tells the reader nothing about how large the breach felt at the time.
Wormhole and Cross-Chain Bridge Exploits
- The Wormhole Portal, a DeFi bridge between Solana and other blockchains, suffered an exploit that saw the theft of 120,000 Ether, worth $325 million at the time.
- Recovery came from the balance sheet, not the chain: Wormhole’s parent company Jump Crypto paid back all of the Ether lost in the attack that same month.
- The US Treasury records that Tornado Cash was subsequently used to launder more than $96 million of malicious cyber actors’ funds derived from the June 24, 2022 Harmony Bridge Heist, and at least $7.8 million from the August 2, 2022 Nomad Heist.
- The pattern reached 2026 intact: KelpDAO’s attackers compromised internal RPC nodes and DDoS’d external nodes to feed false data to a single-point-of-failure verification network.
- That trick tricked the Ethereum contract into releasing funds based on a phantom token burn on the source chain.
Can stolen crypto be recovered?
Recovery is rare and depends on who took the funds. At Poly Network, Elliptic records that the vast majority of these funds were eventually returned by the hacker. At Wormhole, Jump Crypto paid back all of the Ether lost in the attack that same month. Where a state-linked group is the attacker, as with Bybit and KelpDAO, funds have instead been dispersed and laundered.
How Stolen Crypto Moves After a Hack
- Tornado Cash has been used to launder more than $7 billion worth of virtual currency since its creation in 2019, per OFAC’s Tornado Cash sanctions notice.
- That figure includes over $455 million stolen by the Lazarus Group, a Democratic People’s Republic of Korea state-sponsored hacking group that was sanctioned by the US in 2019.
- The FBI reported that Bybit’s attackers converted some of the stolen assets to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains.
- The agency expected these assets would be further laundered and eventually converted to fiat currency.
- Not every attempt clears: Kelp paused the relevant contract on Ethereum and its L2 deployments, blacklisted the attacker’s addresses, and engaged SEAL-911.
| Funds traced to Tornado Cash | Amount |
|---|---|
| All virtual currency laundered since 2019 | more than $7 billion |
| Stolen by the Lazarus Group | over $455 million |
| Harmony Bridge Heist, June 24, 2022 | more than $96 million |
| Nomad Heist, August 2, 2022 | at least $7.8 million |
Source: US Department of the Treasury, OFAC, 2022
Mixer volume is the closest thing the sector has to a leading indicator of non-recovery. Broader cryptocurrency security and fraud statistics track the same laundering routes across smaller incidents that never reach a ranking like this one.
KuCoin and Euler Finance, the Smaller Two
- KuCoin lost $281 million in cryptoassets in September 2020, the last major exchange breach before the bridge era began.
- According to the company, hackers had acquired private keys to its hot wallets.
- The haul spanned seven assets: Ether, Bitcoin, Litecoin (LTC), Ripple (XRP), Stellar Lumens (XLM), Tether (USDT) and Tron (TRX).
- Euler Finance, a crypto lending protocol, suffered a loss of $199 million following a flash-loan attack.
- Elliptic notes that the Euler figure is based on Elliptic’s analysis of on-chain transactions rather than a company disclosure.
KuCoin’s hot-wallet key compromise is the classic exchange failure mode. That is why hot wallet usage and risk data still matter when sizing custodial exposure.
Euler sits at the other end of the mechanism spectrum. A flash-loan attack needs no stolen credential, only a pricing or liquidation flaw the protocol itself exposes. That is a different risk from anything on the exchange side of DeFi lending protocol data.
Annual Crypto Stolen-Funds Totals
- Chainalysis recorded over $3.4 billion in theft from January through early December 2025, with the February compromise of Bybit alone accounting for $1.5 billion.
- Concentration was extreme: the top three hacks in 2025 account for 69% of all service losses.
- TRM Labs put the same year lower, recording that North Korea stole over half of the total $2.7 billion lost in 2025 in crypto hacks.
- TRM sizes Bybit at approximately $1.5 billion in losses, matching Chainalysis and the FBI rather than Elliptic.
| Measurement source | 2025 total stolen | Bybit component | Basis stated |
|---|---|---|---|
| Chainalysis | over $3.4 billion | $1.5 billion | January through early December 2025 |
| TRM Labs | $2.7 billion | approximately $1.5 billion | full year, North Korea over half |
| Elliptic | not published | approximately $1.46 billion | value at the time of the heist |
Source: Chainalysis, TRM Labs, Elliptic, 2025
Neither total is wrong. Publishing both with the basis attached is the only honest answer to a question the industry has not standardized. The spread matters for anyone benchmarking losses against crypto exchange market data.
How much cryptocurrency is stolen each year?
Estimates for 2025 range from $2.7 billion to over $3.4 billion depending on the firm counting. Chainalysis reports the higher total across January through early December 2025, while TRM Labs records the total of $2.7 billion lost in 2025 in crypto hacks. The spread reflects different inclusion rules and valuation timing.
North Korea’s Share of Stolen Crypto
- North Korean hackers stole $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase, despite fewer attacks.
- Chainalysis calls 2025 the most severe year on record for DPRK crypto theft in terms of value stolen.
- DPRK attacks also accounted for a record 76% of all service compromises.
- The FBI states that it refers to this specific North Korean malicious cyber activity as TraderTraitor, the same programme it blames for Bybit.
- Preliminary indicators on Drift were consistent with previously attributed DPRK operations, though formal attribution remains pending.
Key finding: Chainalysis records North Korean hackers at $2.02 billion stolen in 2025, a 51% year-over-year rise achieved with fewer attacks, and a record 76% of all service compromises. Fewer operations returning more value is the signature of improved targeting rather than reduced activity.
Personal Wallets Versus Services as Theft Targets
- Personal wallet compromises grew from just 7.3% of total stolen value in 2022 to 44% in 2024.
- For 2025, Chainalysis notes the share would have been 37% if it weren’t for the outsized impact of the Bybit attack.
- TRM Labs records that targets have shifted from bridges to centralized targets more susceptible to social engineering and developer compromise.
- Across the venues TRM examined, people-and-platform compromises yielded consistently higher returns than protocol exploits.
The wallet share matters because it changes who the loss lands on. Service breaches concentrate risk on a balance sheet that may absorb it, as Jump Crypto did for Wormhole. Individual losses have no such backstop, which is the tension running through self-custody wallet adoption data.
| Incident | Attribution stated by | Named actor |
|---|---|---|
| Bybit | FBI, IC3 public service announcement | North Korea, TraderTraitor |
| KelpDAO | LayerZero | DPRK Lazarus Group, TraderTraitor |
| Drift Protocol | Chainalysis, preliminary indicators | DPRK actors, formal attribution pending |
| Ronin Network | TRM Labs | North Korea |
| Tornado Cash laundering | US Treasury, OFAC | Lazarus Group |
| Coincheck | none | hackers still unknown |
Source: FBI IC3, Chainalysis, TRM Labs, US Treasury, Elliptic, 2018 to 2026
Who has been blamed for the biggest crypto hacks?
Named authorities have confirmed North Korea in three of the eleven biggest crypto hacks, with a fourth, Drift, still only under preliminary indicators. The FBI stated that North Korea was responsible for the Bybit theft and named the activity TraderTraitor. LayerZero attributed the KelpDAO exploit to the DPRK’s Lazarus Group and the same TraderTraitor sub-group. Chainalysis described the Drift indicators as consistent with previously attributed DPRK operations, with formal attribution still pending.
Sanctions have followed attribution more consistently than charges have. OFAC’s Tornado Cash action names the Lazarus Group, a Democratic People’s Republic of Korea state-sponsored hacking group that was sanctioned by the US in 2019. On March 12, 2026, the agency sanctioned six individuals and two entities for their roles in North Korean IT worker fraud schemes. Coincheck remains the outlier, since Elliptic records that the hackers are still unknown to this day.
Conclusion
Bybit’s nearly $1.5 billion loss still sits at the top of the ranking. Chainalysis counted over $3.4 billion stolen across 2025, concentrated enough that the top three hacks account for 69% of all service losses. The eleven biggest crypto hacks total $5.56 billion at contemporaneous value, spread across four exchange breaches, five bridge exploits and two DeFi protocol failures. Only Poly Network and Wormhole ended with victims made whole.
Attribution has become far more certain than recovery. Named agencies have confirmed North Korea in three of the eleven entries, with preliminary indicators on one more, while funds came back in only two. Our coverage of exchange failures shows the same asymmetry widening each cycle, with forensics improving faster than restitution. Practical exposure now turns on whether the attacker wants money or wants it gone, more than on which venue was hit.