Crypto Investors Lost $2.5B to Hacks and Scams in the First Half of 2025: Certik
Cryptocurrency theft surged to record levels in the first half of 2025, with hackers stealing over $2.47 billion, surpassing the total for all of 2024. This alarming figure, detailed in CertiK’s Hack3d Report, highlights a significant increase in cybercrime targeting the digital asset space.
Two mega-breaches account for a substantial portion of the losses: the Bybit breach and the Cetus Protocol exploit, cumulatively resulting in $1.78 billion in stolen funds. This underscores the vulnerability of large centralized exchanges and DeFi protocols to sophisticated hacking attempts.
The report identifies wallet compromise as the primary attack vector, responsible for $1.7 billion in losses. This method involves gaining unauthorized access to users’ digital wallets, directly pilfering their cryptocurrency holdings. Phishing attacks, a persistent threat, also contributed significantly, netting hackers $410 million across 132 incidents. These attacks often involve deceptive emails or websites designed to trick users into revealing their login credentials.
While the overall numbers are staggering, CertiK co-founder Ronghui Gu emphasizes that the majority of losses stemmed from two major events. This indicates that while the potential for large-scale breaches exists, many individual incidents involved smaller amounts. Nevertheless, Gu stresses the ongoing need for improved security measures across the cryptocurrency ecosystem.
The second quarter of 2025 saw a decline in losses, with $801 million stolen—a 52% decrease from Q1. This fluctuation highlights the unpredictable nature of cryptocurrency theft, potentially influenced by factors like evolving security protocols and changes in hacker tactics.
Ethereum was the most targeted blockchain, suffering $1.5 billion in losses across 164 incidents. Bitcoin, while less frequently targeted, still experienced significant losses, totaling $373 million across just 10 incidents. This disparity suggests differing vulnerabilities between the two leading cryptocurrencies. The report serves as a stark reminder of the persistent cybersecurity challenges facing the cryptocurrency industry and underscores the imperative for continuous improvements in security practices and user education.

