Crypto’s Worst Six Months Yet? North Korea Hacks Lead to $2.1B in Thefts
Cryptocurrency security suffered its worst six-month period on record during the first half of 2025, with losses exceeding $2.1 billion due to hacks and exploits. This represents a significant increase from previous years, surpassing the 2022 H1 high by approximately 10% and nearing the total for the entire year of 2024. A total of 75 incidents were recorded, highlighting a concerning trend in the industry’s vulnerability.
The alarming aspect of this surge in crypto theft is the prominent involvement of nation-state actors. North Korea-linked groups are responsible for a staggering $1.6 billion (70%) of the stolen funds, significantly impacting the overall figures. This is largely attributed to the February 2025 Bybit hack, estimated at $1.5 billion, marking the largest crypto theft in history and dramatically increasing the average hack size to $30 million—double the 2024 average.
The threat, however, extends beyond North Korea. A June 18th incident saw a group potentially linked to Israel, known as Gonjeshke Darande (Predatory Sparrow), steal $90 million from the Iranian exchange Nobitex. This attack is believed to be politically motivated, as the stolen funds were sent to vanity addresses, rendering them essentially unusable, suggesting a retaliatory measure against Nobitex for alleged sanctions evasion.
The methods employed in these attacks are evolving rapidly. Over 80% of the stolen funds resulted from infrastructure-level breaches, including private key thefts and front-end hijacks. These attacks, frequently involving sophisticated social engineering techniques or exploitation of insider access, are proving significantly more profitable than traditional smart contract exploits, yielding ten times the returns.
In contrast, DeFi vulnerabilities like flash loan and reentrancy attacks, prevalent in 2021-2022, accounted for only 12% of the losses in H1 2025. This shift in attack vectors underscores the need for enhanced security measures focused on infrastructure protection and the prevention of social engineering and insider threats. The increasing sophistication and scale of these attacks, particularly those attributed to nation-state actors, necessitates a collaborative response from the cryptocurrency industry and governments to mitigate future risks.

