📈 Get daily crypto insights that make you smarter about your money

Crypto Hack Losses Surpass $2.47 Billion in H1 2025, Already Exceeding 2024 Total: CertiK Report

The first half of 2025 has etched itself into cryptocurrency security history for all the wrong reasons. According to blockchain security firm CertiK, approximately $2.47 billion in digital assets were stolen through scams, hacks, and exploits between January and June 2025 — already surpassing the total losses recorded throughout the entirety of 2024. This staggering figure underscores a sobering reality: as the crypto ecosystem matures and asset values climb, the incentives for malicious actors grow proportionally.

The Exploit Mechanics

The surge in crypto losses during H1 2025 was predominantly driven by two catastrophic security incidents that together accounted for 72% of total losses. The Bybit breach in February 2025 stands as the largest cryptocurrency theft in history, with hackers — widely attributed to North Korea’s Lazarus Group — stealing approximately $1.4 billion in Ethereum-based assets from the Dubai-based exchange. The attack vector involved a sophisticated supply chain compromise that targeted Bybit’s Safe (formerly Gnosis Safe) multisig wallet infrastructure, allowing attackers to redirect transactions without triggering immediate detection.

The second major incident struck in May 2025, when attackers exploited Cetus Protocol — the largest decentralized exchange on the Sui blockchain — making off with approximately $225 million in digital assets. Notably, Sui validators responded with unprecedented coordination, freezing and returning $162 million of the stolen funds through an emergency governance proposal, demonstrating that rapid collective action can mitigate even the most damaging exploits.

Beyond these headline-grabbing events, CertiK documented a total of 344 individual security incidents across H1 2025. The average loss per incident reached $7.18 million, more than double the $3.1 million average recorded in 2024. When excluding frozen or recovered funds, net losses stood at $2.29 billion — already exceeding 2024’s full-year net losses of $1.98 billion.

Affected Systems

Ethereum bore the brunt of attacks in H1 2025, experiencing 175 security incidents resulting in $1.63 billion in losses — heavily influenced by the Bybit breach. However, the threat landscape shifted noticeably between quarters. In Q1, wallet compromise was the dominant attack vector, with $1.7 billion stolen across just 34 incidents, primarily concentrated in three massive breaches including Bybit.

By Q2 2025, phishing had resurged as the most lucrative attack vector, accounting for $395.06 million in losses across 52 incidents. This marked a significant tactical shift, as wallet compromise dropped to the fifth costliest vector in Q2 with only $11.2 million in losses. Bitcoin networks also saw increased targeting in Q2, with $373.6 million lost across nine incidents — suggesting attackers are diversifying beyond Ethereum-centric targets.

The Mitigation Strategy

CertiK co-founder Ronghui Gu emphasized that while the headline figures are alarming, the concentration of losses in two incidents suggests the broader security posture may not be deteriorating as dramatically as raw numbers imply. Without those two events, total H1 losses would have stood at $690 million — a more manageable figure relative to the ecosystem’s growth.

The industry response has been multi-pronged. Multi-signature wallet providers have strengthened their UI verification processes following the Bybit incident. Cross-chain bridge protocols have implemented additional validation layers. The Cetus incident demonstrated that blockchain governance mechanisms can serve as an effective emergency brake when validators act swiftly and cooperatively.

Security professionals recommend a layered defense approach encompassing formal code verification, real-time monitoring systems, comprehensive incident response plans, regular vulnerability assessments, and continuous employee awareness training. As CertiK notes, these measures should be treated as standard operational requirements rather than optional enhancements.

Lessons Learned

The H1 2025 data reveals several critical patterns. First, single points of failure — whether in multisig infrastructure or cross-chain bridges — continue to present outsized risk. Second, the rapid recovery of $162 million in the Cetus incident proves that community-coordinated responses can meaningfully limit attacker success. Third, the resurgence of phishing as the top Q2 vector indicates that social engineering remains the most persistent threat to individual users and organizations alike.

User Action Required

With Bitcoin trading around $105,700 and Ethereum near $2,400 as of July 1, 2025, the total value at risk in the crypto ecosystem continues to grow. Users should verify all transaction details through multiple independent channels before signing, enable hardware wallet authentication for large holdings, and maintain heightened skepticism toward unsolicited communications. The $2.47 billion lost in H1 2025 serves as a stark reminder that security vigilance is not optional — it is the price of participation in decentralized finance.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

23 thoughts on “Crypto Hack Losses Surpass $2.47 Billion in H1 2025, Already Exceeding 2024 Total: CertiK Report”

  1. long_tail_risk

    everyone focuses on Bybit 1.4B but the real damage is 342 incidents at 7.18M average. thats a protocol dying every 13 hours and nobody blinks

  2. safe_ui_skeptic

    Bybit lost 1.4B because someone got tricked into signing a malicious Safe transaction. not even a contract bug, just a really convincing UI spoof. blow your mind how cheap that attack was to execute

  3. supply_chain_void_

    Lazarus targeting the Safe wallet infrastructure was a supply chain attack on DeFi itself. every protocol using that multisig stack was exposed

    1. Lazarus basically turned the Safe multisig into their personal ATM. every DeFi protocol using Safe had to audit after Bybit and nobody talked about the downstream cost

  4. two incidents causing 72% of 2.47B in losses means the long tail of smaller exploits actually improved year over year. the headline number hides that

  5. rekt_again_404

    2.47 billion in h1 alone? that certik report is brutal. we’re already past the 2024 total and it’s only july.

    1. cold_storage_or_die

      rekt_again_404 and people wonder why institutional adoption is slow. $2.47B in 6 months is not a bug, its a feature of an immature ecosystem

      1. Samuel Adeyemi

        cold_storage_or_die the $7.18M average per incident across 344 events is the scary number. small hacks dont make headlines but they add up fast

  6. The certik report is a grim reminder of how far we have to go. 2.47 billion dollars lost in just six months is an insane number.

    1. Bybit at $1.4B and Cetus at $225M. two incidents make up 72% of all losses. the long tail of 344 other incidents at $7.18M average is the real concern

      1. two incidents making up 72 percent of all losses is the real stat. the other 342 incidents at 7.18m average each dont get headlines but bleed the ecosystem dry

      2. north_korea_watch

        Igor Petrov Lazarus behind Bybit is state sponsored theft. $1.4B from one exchange and the industry just moves on like nothing happened

        1. supply_chain_nerd

          55173 the Bybit attack was a Safe multisig UI compromise not a smart contract bug. $1.4B gone because someone signed what looked normal on screen

          1. bridge_auditor_

            supply_chain_nerd the Safe multisig UI compromise changed the whole security conversation. after Bybit every team should have been checking calldata on the hardware device itself not the screen

          2. bybit_autopsy_

            1.4B from Bybit alone is 57 percent of all H1 losses. the Safe multisig compromise was the single biggest crypto theft in history and it happened via UI trickery not a smart contract bug

          3. Bybit at 1.4B is 57% of all H1 losses. one attack. one team. the entire industry security budget outspent by north korea in a single afternoon

  7. seeing that 2.47 billion figure from certik makes me want to move everything to cold storage. h1 2025 is setting a terrible record.

  8. 342 incidents at 7.18M average is where the real bleeding happens. one big hack makes headlines but the small ones drain the ecosystem silently

    1. Idris B. two incidents accounting for 72 percent of 2.47B means the rest of the ecosystem actually improved. the headline number is misleading without that context

    2. 薛定谔的猫_

      Idris B. the long tail problem. nobody audits a protocol for a 7M exploit threshold because those dont get press. so they keep happening

      1. 薛定谔的猫_ exactly. protocols budget for a 50K bug bounty but the average exploit nets 7.18M. the incentive structure is completely upside down

  9. Bybit alone was 1.4B of the 2.47B total. one attack basically half the entire years losses. insane concentration risk

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,934.00+0.2%ETH$1,918.22+0.3%SOL$76.18+3.5%BNB$600.46+1.4%XRP$1.04+2.1%ADA$0.1982-1.2%DOGE$0.0706+1.4%DOT$0.8162+0.6%AVAX$6.48+0.8%LINK$8.33+2.1%UNI$4.00+1.6%ATOM$1.39+2.3%LTC$45.97+1.2%ARB$0.0786-0.1%NEAR$1.62+1.7%FIL$0.7135+4.6%SUI$0.6935+3.4%BTC$64,934.00+0.2%ETH$1,918.22+0.3%SOL$76.18+3.5%BNB$600.46+1.4%XRP$1.04+2.1%ADA$0.1982-1.2%DOGE$0.0706+1.4%DOT$0.8162+0.6%AVAX$6.48+0.8%LINK$8.33+2.1%UNI$4.00+1.6%ATOM$1.39+2.3%LTC$45.97+1.2%ARB$0.0786-0.1%NEAR$1.62+1.7%FIL$0.7135+4.6%SUI$0.6935+3.4%
Scroll to Top