Introduction
Exchange & private key compromises
Smart contract exploits
Social engineering on the rise
The October 10 crash
Notable mentions of 2025
What we can learn
References
The crypto ecosystem lost $3.4 billion in 2025, roughly flat with 2024’s $3.38 billion. But the numbers hide a shift in how theft happens. North Korean state actors dominated the year, and the gap between the largest exploits and typical incidents hit record extremes.
The pattern is clear. Attacks are getting more concentrated, more sophisticated, and increasingly focused on supply chains and human vulnerabilities rather than brute-forcing smart contracts. Audits and multisig wallets aren’t enough anymore.
In one of 2025’s most significant breaches, Bybit lost between $1.4 and $1.5 billion in February after a targeted supply chain attack. Critically, the breach did not start inside Bybit’s own matching engine or custody stack. North Korea’s TraderTraitor group compromised a Safe wallet system administrator and injected malicious code directly into the UI.
The code spoofed legitimate multisig transactions, swapping the destination address at the final approval moment. During a routine cold-to-warm wallet transfer, the attackers drained 401,000 ETH.
The FBI attributed the breach to DPRK within five days. Funds scattered across thousands of addresses through DEXs, bridges, and no-KYC swaps. The laundering pattern differed from typical operations. 60% of transfers stayed under $500,000, cycling through Chinese-language services on a 45-day rhythm. Most actors move funds in $1 million to $10 million tranches.
Private key compromises drove 88% of Q1 losses despite enterprise security measures. North Korean operatives have been embedding themselves as IT contractors inside crypto companies, gaining privileged access for both immediate theft and long-term reconnaissance.
Trust Wallet’s browser extension became the latest supply chain compromise. The attack affected $7 million in user funds, which Trust Wallet covered in full. Users with version 2.68 were instructed to disable the extension and upgrade to version 2.69. Mobile users and other browser extension versions were not impacted. Trust Wallet is investigating how attackers were able to submit the compromised version.
An integer overflow in Move’s checked_shlw function let an attacker manipulate how Cetus calculated liquidity. Using flash loans and a tight tick range between 300,000 and 300,200, they created fake tokens like BULLA and MOJO that appeared massively over-collateralized from just a single token deposit. The flaw assigned these worthless tokens huge liquidity values, draining 46 pools in under fifteen minutes.
Sui validators froze $162 million through consensus-based transaction censorship, but over $60 million had already moved to Ethereum via cross-chain bridges.
Balancer V2 had two problems. First, weak access control in the manageUserBalance function allowed attackers to spoof op.sender. Second, a rounding bug in _upscaleArray created precision loss during calculations. The attacker chained 65 tiny swaps together, compounding the rounding error to suppress token prices by 10%, then extracted value through arbitrage.
The damage spread across multiple chains. Ethereum took $99 million in losses. Arbitrum, Base, Polygon, Optimism, and Berachain all got hit. More than twenty Balancer forks inherited the same vulnerability.
Both protocols had been audited multiple times. The audits missed novel attack vectors anyway. Balancer’s unified V2 codebase made it worse. One bug spread to every deployment and fork, turning a single oversight into a chain-wide failure.
While attackers exploited protocol-level vulnerabilities, the market’s own infrastructure became the next critical failure point.
North Korean operations moved beyond basic email phishing. Attackers now impersonate executives and investors, embedding fake IT workers inside crypto companies to maintain long-term access. They also compromise legitimate accounts, contacting victims from verified profiles they’ve hijacked. These operatives combine insider knowledge with technical reconnaissance, setting up both immediate theft and future infrastructure compromises.
AI accelerated the problem. Automated systems scan public repositories and codebases to craft targeted phishing campaigns, then replicate exploits across chains within hours. Fake Coinbase support calls alone stole over $100 million. Infrastructure exploits tied to social engineering averaged $30 million each, with 80% gaining entry through compromised hot wallet credentials.
Personal wallets now represent roughly 44% of total crypto theft, up from 7% in 2022. The shift reflects a move toward automation. Instead of hunting whales, attackers run scaled operations hitting smaller amounts across thousands of victims. That said, whales aren’t spared. On December 19th, one whale lost $50 million in an address poisoning scam. What used to require deep technical skill now runs on systematized trust exploitation.
October 10 became the largest liquidation event in crypto history. $19.3 billion vanished in under 14 hours. $3.21 billion disappeared in the first 60 seconds alone. 1.6 million traders got wiped out.
Two triggers hit within sixteen minutes of each other. Trump announced a 100% tariff on Chinese imports. MSCI released a consultation on excluding Digital Asset Treasuries from its global indices. Markets had no time to absorb either shock.
Liquidity collapsed in three dimensions. Order book depth fell 85%.
BTC spreads exploded from 0.02 basis points to 26.43, a 1,321x increase. Exchanges fragmented. Binance quoted 2.50 bps while Arkham showed 13.14 bps. There was no unified market anymore.
The most extreme dislocation concentrated on Binance, where internal order book liquidity for USDe and related collateral vanished. Binance prices crashed while other exchanges traded normally. What started as a Binance-specific problem triggered liquidations across the entire market.
Oracle manipulation turned a $60 million sell-off into a $9.6 billion cascade. Recursive USDe leverage lets traders stack 10x positions on top of manipulatable internal spot prices. The math compounded until it broke. The deleveraging wiped $65 billion in open interest. Market makers lost hundreds of millions. Even well-capitalized firms weren’t immune to the cascade.
Weekend liquidity gaps made it worse. Binance’s API froze for both retail traders and market makers, and parts of the UI stopped working. Traders couldn’t buy the dip or add collateral even if they wanted to. The worst stablecoin depegs happened on Binance, where USDe and wrapped collateral markets crashed below par while trading near peg on other exchanges and on-chain. A Binance-specific problem looked like system-wide failure. Binance ultimately paid $283 million in compensation to stabilize things while other major exchanges kept functioning normally.
While the Bybit breach and the October crash dominated headlines, the following incidents illustrate the technical shift toward infrastructure manipulation and sophisticated social engineering that defined the year.
Phemex (CEX) – $73M (January): A cross-chain hot-wallet compromise affecting 16 different blockchains. Forensic analysis linked this attack to North Korean clusters, suggesting a coordinated campaign of gaining entry through compromised hot wallet credentials.
UPCX (Web3 Payments) – $70M (April 1): Attackers gained access to an owner account via a private key exploit. They then performed a malicious upgrade to the implementation logic, adding a function that allowed them to “sweep” 18.4 million UPC tokens directly from management accounts.
Bitget – $100M (April 20): A market infrastructure failure rather than a direct hack. A malfunctioning automated market-maker bot flooded the market with erratic, predictable orders. Savvy traders identified the pattern and siphoned $100M before the platform could freeze accounts and reverse trades.
The industry solved one problem while another grew worse. Years of work perfecting smart contract audits made code exploits harder, but attackers adapted. Bybit fell to a supply chain compromise. The October crash exposed exchange-level infrastructure gaps, especially where one venue concentrated the bulk of leveraged flow. Meanwhile, Cetus and Balancer proved that novel code exploits still work even after multiple audits.
Safe wallet had no formal relationship with Bybit. It was external infrastructure that became the point of failure. One compromised admin account enabled $1.5 billion in theft. North Korean operatives spend months embedded as IT contractors, gaining access no audit prevents. The October crash exposed similar infrastructure weakness. Binance’s liquidity vanished and its API froze while other exchanges functioned normally. Both Cetus and Balancer passed multiple audits before getting drained through vectors the reviews never considered.
The pattern isn’t that code is secure now. It’s that attackers work wherever defenses are weakest. Sometimes that’s a rounding bug in production code. Sometimes it’s a compromised admin at an open-source project. Sometimes it’s market infrastructure with no failsafes. Static security fails against adaptive threats.
Real security means monitoring transactions as they happen, validating every supply chain link, assuming any human with system access could be compromised, and building market infrastructure that doesn’t collapse under stress. It also means assuming every smart contract has an exploit waiting to be found, regardless of how many audits it passed. Security isn’t choosing the right layer to defend. It’s defending all of them.
While 2025 was a year of evolving threats and infrastructure stress tests, it wasn’t all dark. The ecosystem also saw incredible milestones in adoption and technical breakthroughs. Read our companion piece on the year’s greatest successes and “Crypto at its Best: 2025”.
Inside the $19B Flash CrashHow Crypto Users Get Rekt and How You Can Stay Safe
Balancer hack analysis and guidance for the DeFi ecosystem
The Bybit Hack: Following North Korea’s Largest Exploit
Cetus Protocol hacked for more than $200 million
How $3.21B Vanished in 60 Seconds: October 2025 Crypto Crash Explained Through 7 Charts
North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion
Binance pays $283 million in compensation following Friday’s depegs, covering user losses
Thanks for reading Dewhales Research! Subscribe for free to receive new posts and support our work.
We’d love to hear your thoughts on the article! Your feedback helps us improve and bring you the best content possible—it won’t take more than 2 minutes.
Also, this post is public, so feel free to share it!
Thank you so much! ❤️
Our links:
🔗Website
🐦Twitter
✉️Substack
🔸DeBank
Disclaimer: The content presented in this article, along with others, is based on opinions developed by the analysts at Dewhales and does not constitute sponsored content. At Dewhales, we firmly adhere to a transparency-first philosophy, making our wallets openly available to the public through our website or DeBank, and our articles serve as vehicles for self-expression, education, and contribution to the ecosystem. Dewhales Capital does not provide investment advisory services to the public. Any information should not be taken as investment, accounting, tax or legal advice or as a recommendation to purchase, sell or hold or to pursue any investment style or strategy.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.