Key Takeaways

Six Years, More Than $16 Billion Gone

Crypto theft is no longer a phase that the digital asset industry is slowly getting out of but an industry unto itself. To this point, over the past half a decade alone, onchain sleuths have counted ballooning stolen totals ($3.7 billion in 2022, $1.7 billion in 2023, $2.2 billion in 2024, and $3.4 billion in 2025), figures that have shown no signs of stopping.

In fact, it bears mentioning that nearly half of last year’s total came from a single event, i.e. the February 2025 Bybit hack, in which attackers compromised the exchange’s cold-wallet signing process and walked away with $1.5 billion (making it the largest crypto theft in history).

Stolen crypto amounts per year.

The first half of this year was eerily similar, adding roughly $1.1 billion across a record 212 incidents, per security firm Blockaid. The largest single hit was the April 19 exploit of restaking protocol KelpDAO (at $293 million), and TRM Labs counted 207 incidents over these six months, more than double the same period a year earlier.

The 45-Day Playbook

What typically happens after the aforementioned thefts has become almost like a script at this point, with researchers describing a distinctive laundering cycle that runs roughly 45 days in three waves.

During days zero through five, speed matters most and the stolen tokens are typically swapped through decentralized finance (DeFi) protocols (activity spikes as much as 370%) and pushed into mixing services, which pool and shuffle coins to break the link between source and destination. During days six through ten, the funds hop chains via cross-chain bridges and flow through exchanges with limited know-your-customer (KYC) checks.

Then, from roughly day 20 to day 45, the coins are cashed out in small tranches (typically under $500,000 to stay beneath reporting thresholds) through no-KYC venues, instant exchangers, and Chinese-language over-the-counter (OTC) networks and guarantee services such as the sanctioned Huione marketplace.

Consequently, by the end of the cycle, the money has crossed through so many chains, mixers and jurisdictions that even though attribution remains possible (since blockchains never forget), recovery rarely is. For perspective’s sake, less than 5% of Bybit’s stolen funds were ever recovered, even though the exchange had some of the most prolific white hat personnel on their side.

2026: More Hacks, Smaller Hauls

This year, attackers have widened their targets because, alongside protocol exploits like KelpDAO’s, April alone set a monthly record with $641.67 million stolen. Lazarus-linked North Korean crews were behind about 55% of first-half losses, and CertiK’s count, which includes phishing and personal-wallet drains, puts the period’s damage at $1.32 billion across 344 incidents.

Most recently, the Coldcard hardware-wallet exploit showed how the playbook is adapting to bitcoin as well. After draining roughly $116 million from weak-seed wallets, the attacker began consolidating coins while onlookers watched every hop. In light of the incident, bitcoin’s core USPs, ala transparency and irreversibility, became double-edged swords almost overnight because even though everyone could see the stolen coins move, no one could move them back.

Why Recovery Almost Never Happens

When all of these attacks are going down, the one lever that has time and again worked reliably is the centralized stablecoin freeze. Tether and Circle can blacklist addresses at the contract level, instantly stranding any USDT or USDC that thieves are still holding, which is precisely why sophisticated attackers swap stolen stablecoins into ether or bitcoin within minutes of a breach, accepting price risk to escape the freeze radius.

It’s a revealing asymmetry, i.e. the most censorship-resistant assets are the easiest to launder, and the most freezable ones are the easiest to recover. Every laundering playbook is ultimately a race to convert the catchable into the uncatchable before anyone with a pause button notices.

The uncomfortable math of crypto theft is that prevention is nearly the whole game. Exchanges and analytics firms can freeze funds that touch compliant platforms, which is exactly why launderers front-load DeFi and mixers, where no one can freeze anything.

Sanctions on mixers and services like Huione raise costs but merely push flows to successors rather than stopping them. And the 45-day clock means that by the time cross-border legal process is even underway, the coins have usually finished their journey.

For users and platforms, the lesson is that, once stolen, the overwhelming majority of their funds are never coming back. Furthermore, the attackers’ cycle is faster than compliance, and every year that “crypto theft is declining” appears in a headline, the next billion-dollar counterexample is already in motion. The blockchain records everything and returns nothing.



Source link


author

Leave a Reply

Your email address will not be published. Required fields are marked *