The first half of 2025 has etched itself into cryptocurrency security history for all the wrong reasons. According to blockchain security firm CertiK, approximately $2.47 billion in digital assets were stolen through scams, hacks, and exploits between January and June 2025 — already surpassing the total losses recorded throughout the entirety of 2024. This staggering figure underscores a sobering reality: as the crypto ecosystem matures and asset values climb, the incentives for malicious actors grow proportionally.
The Exploit Mechanics
The surge in crypto losses during H1 2025 was predominantly driven by two catastrophic security incidents that together accounted for 72% of total losses. The Bybit breach in February 2025 stands as the largest cryptocurrency theft in history, with hackers — widely attributed to North Korea’s Lazarus Group — stealing approximately $1.4 billion in Ethereum-based assets from the Dubai-based exchange. The attack vector involved a sophisticated supply chain compromise that targeted Bybit’s Safe (formerly Gnosis Safe) multisig wallet infrastructure, allowing attackers to redirect transactions without triggering immediate detection.
The second major incident struck in May 2025, when attackers exploited Cetus Protocol — the largest decentralized exchange on the Sui blockchain — making off with approximately $225 million in digital assets. Notably, Sui validators responded with unprecedented coordination, freezing and returning $162 million of the stolen funds through an emergency governance proposal, demonstrating that rapid collective action can mitigate even the most damaging exploits.
Beyond these headline-grabbing events, CertiK documented a total of 344 individual security incidents across H1 2025. The average loss per incident reached $7.18 million, more than double the $3.1 million average recorded in 2024. When excluding frozen or recovered funds, net losses stood at $2.29 billion — already exceeding 2024’s full-year net losses of $1.98 billion.
Affected Systems
Ethereum bore the brunt of attacks in H1 2025, experiencing 175 security incidents resulting in $1.63 billion in losses — heavily influenced by the Bybit breach. However, the threat landscape shifted noticeably between quarters. In Q1, wallet compromise was the dominant attack vector, with $1.7 billion stolen across just 34 incidents, primarily concentrated in three massive breaches including Bybit.
By Q2 2025, phishing had resurged as the most lucrative attack vector, accounting for $395.06 million in losses across 52 incidents. This marked a significant tactical shift, as wallet compromise dropped to the fifth costliest vector in Q2 with only $11.2 million in losses. Bitcoin networks also saw increased targeting in Q2, with $373.6 million lost across nine incidents — suggesting attackers are diversifying beyond Ethereum-centric targets.
The Mitigation Strategy
CertiK co-founder Ronghui Gu emphasized that while the headline figures are alarming, the concentration of losses in two incidents suggests the broader security posture may not be deteriorating as dramatically as raw numbers imply. Without those two events, total H1 losses would have stood at $690 million — a more manageable figure relative to the ecosystem’s growth.
The industry response has been multi-pronged. Multi-signature wallet providers have strengthened their UI verification processes following the Bybit incident. Cross-chain bridge protocols have implemented additional validation layers. The Cetus incident demonstrated that blockchain governance mechanisms can serve as an effective emergency brake when validators act swiftly and cooperatively.
Security professionals recommend a layered defense approach encompassing formal code verification, real-time monitoring systems, comprehensive incident response plans, regular vulnerability assessments, and continuous employee awareness training. As CertiK notes, these measures should be treated as standard operational requirements rather than optional enhancements.
Lessons Learned
The H1 2025 data reveals several critical patterns. First, single points of failure — whether in multisig infrastructure or cross-chain bridges — continue to present outsized risk. Second, the rapid recovery of $162 million in the Cetus incident proves that community-coordinated responses can meaningfully limit attacker success. Third, the resurgence of phishing as the top Q2 vector indicates that social engineering remains the most persistent threat to individual users and organizations alike.
User Action Required
With Bitcoin trading around $105,700 and Ethereum near $2,400 as of July 1, 2025, the total value at risk in the crypto ecosystem continues to grow. Users should verify all transaction details through multiple independent channels before signing, enable hardware wallet authentication for large holdings, and maintain heightened skepticism toward unsolicited communications. The $2.47 billion lost in H1 2025 serves as a stark reminder that security vigilance is not optional — it is the price of participation in decentralized finance.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.
everyone focuses on Bybit 1.4B but the real damage is 342 incidents at 7.18M average. thats a protocol dying every 13 hours and nobody blinks
Bybit lost 1.4B because someone got tricked into signing a malicious Safe transaction. not even a contract bug, just a really convincing UI spoof. blow your mind how cheap that attack was to execute
Lazarus targeting the Safe wallet infrastructure was a supply chain attack on DeFi itself. every protocol using that multisig stack was exposed
Lazarus basically turned the Safe multisig into their personal ATM. every DeFi protocol using Safe had to audit after Bybit and nobody talked about the downstream cost
two incidents causing 72% of 2.47B in losses means the long tail of smaller exploits actually improved year over year. the headline number hides that
2.47 billion in h1 alone? that certik report is brutal. we’re already past the 2024 total and it’s only july.
rekt_again_404 and people wonder why institutional adoption is slow. $2.47B in 6 months is not a bug, its a feature of an immature ecosystem
cold_storage_or_die the $7.18M average per incident across 344 events is the scary number. small hacks dont make headlines but they add up fast
The certik report is a grim reminder of how far we have to go. 2.47 billion dollars lost in just six months is an insane number.
Bybit at $1.4B and Cetus at $225M. two incidents make up 72% of all losses. the long tail of 344 other incidents at $7.18M average is the real concern
two incidents making up 72 percent of all losses is the real stat. the other 342 incidents at 7.18m average each dont get headlines but bleed the ecosystem dry
Igor Petrov Lazarus behind Bybit is state sponsored theft. $1.4B from one exchange and the industry just moves on like nothing happened
55173 the Bybit attack was a Safe multisig UI compromise not a smart contract bug. $1.4B gone because someone signed what looked normal on screen
supply_chain_nerd the Safe multisig UI compromise changed the whole security conversation. after Bybit every team should have been checking calldata on the hardware device itself not the screen
1.4B from Bybit alone is 57 percent of all H1 losses. the Safe multisig compromise was the single biggest crypto theft in history and it happened via UI trickery not a smart contract bug
Bybit at 1.4B is 57% of all H1 losses. one attack. one team. the entire industry security budget outspent by north korea in a single afternoon
north_korea_watch lazarus bybit hit at 1.4b was state level but the ui safe sign was the weak spot
seeing that 2.47 billion figure from certik makes me want to move everything to cold storage. h1 2025 is setting a terrible record.
342 incidents at 7.18M average is where the real bleeding happens. one big hack makes headlines but the small ones drain the ecosystem silently
Idris B. two incidents accounting for 72 percent of 2.47B means the rest of the ecosystem actually improved. the headline number is misleading without that context
Idris B. the long tail problem. nobody audits a protocol for a 7M exploit threshold because those dont get press. so they keep happening
薛定谔的猫_ exactly. protocols budget for a 50K bug bounty but the average exploit nets 7.18M. the incentive structure is completely upside down
Bybit alone was 1.4B of the 2.47B total. one attack basically half the entire years losses. insane concentration risk