Key Takeaways
- Chainalysis logged $3.4B stolen in 2025, with Bybit’s $1.5B hack alone accounting for 44% of that complete.
- H1 2026 set a report 212 incidents per Blockaid, with Lazarus-linked crews behind about 55% of those losses.
- KelpDAO’s $293M April exploit was 2026’s largest single hit.
Six Years, Extra Than $16 Billion Gone
Crypto theft is now not a section that the digital asset business is slowly getting out of however an business unto itself. Up to now, over the previous half a decade alone, onchain sleuths have counted ballooning stolen totals ($3.7 billion in 2022, $1.7 billion in 2023, $2.2 billion in 2024, and $3.4 billion in 2025), figures which have proven no indicators of stopping.
In truth, it bears mentioning that just about half of final 12 months’s complete got here from a single occasion, i.e. the February 2025 Bybit hack, wherein attackers compromised the trade’s cold-wallet signing course of and walked away with $1.5 billion (making it the biggest crypto theft in historical past).

The primary half of this 12 months was eerily comparable, including roughly $1.1 billion throughout a report 212 incidents, per safety agency Blockaid. The biggest single hit was the April 19 exploit of restaking protocol KelpDAO (at $293 million), and TRM Labs counted 207 incidents over these six months, greater than double the identical interval a 12 months earlier.
The 45-Day Playbook
What sometimes occurs after the aforementioned thefts has develop into virtually like a script at this level, with researchers describing a particular laundering cycle that runs roughly 45 days in three waves.
Throughout days zero by means of 5, pace issues most and the stolen tokens are sometimes swapped by means of decentralized finance (DeFi) protocols (exercise spikes as a lot as 370%) and pushed into mixing providers, which pool and shuffle cash to interrupt the hyperlink between supply and vacation spot. Throughout days six by means of ten, the funds hop chains through cross-chain bridges and circulation by means of exchanges with restricted know-your-customer (KYC) checks.
Then, from roughly day 20 to day 45, the cash are cashed out in small tranches (sometimes beneath $500,000 to remain beneath reporting thresholds) by means of no-KYC venues, prompt exchangers, and Chinese language-language over-the-counter (OTC) networks and assure providers such because the sanctioned Huione market.
Consequently, by the top of the cycle, the cash has crossed by means of so many chains, mixers and jurisdictions that though attribution stays potential (since blockchains always remember), restoration hardly ever is. For perspective’s sake, lower than 5% of Bybit’s stolen funds have been ever recovered, though the trade had a few of the most prolific white hat personnel on their aspect.
2026: Extra Hacks, Smaller Hauls
This 12 months, attackers have widened their targets as a result of, alongside protocol exploits like KelpDAO’s, April alone set a month-to-month report with $641.67 million stolen. Lazarus-linked North Korean crews have been behind about 55% of first-half losses, and CertiK’s depend, which incorporates phishing and personal-wallet drains, places the interval’s harm at $1.32 billion throughout 344 incidents.
Most not too long ago, the Coldcard hardware-wallet exploit confirmed how the playbook is adapting to bitcoin as nicely. After draining roughly $116 million from weak-seed wallets, the attacker started consolidating cash whereas onlookers watched each hop. In gentle of the incident, bitcoin’s core USPs, ala transparency and irreversibility, grew to become double-edged swords virtually in a single day as a result of though everybody might see the stolen cash transfer, nobody might transfer them again.
Why Restoration Virtually By no means Occurs
When all of those assaults are happening, the one lever that has repeatedly labored reliably is the centralized stablecoin freeze. Tether and Circle can blacklist addresses on the contract degree, immediately stranding any USDT or USDC that thieves are nonetheless holding, which is exactly why subtle attackers swap stolen stablecoins into ether or bitcoin inside minutes of a breach, accepting worth threat to flee the freeze radius.
It’s a revealing asymmetry, i.e. essentially the most censorship-resistant property are the best to launder, and essentially the most freezable ones are the best to get well. Each laundering playbook is in the end a race to transform the catchable into the uncatchable earlier than anybody with a pause button notices.
The uncomfortable math of crypto theft is that prevention is sort of the entire sport. Exchanges and analytics corporations can freeze funds that contact compliant platforms, which is precisely why launderers front-load DeFi and mixers, the place nobody can freeze something.
Sanctions on mixers and providers like Huione increase prices however merely push flows to successors slightly than stopping them. And the 45-day clock implies that by the point cross-border authorized course of is even underway, the cash have often completed their journey.
For customers and platforms, the lesson is that, as soon as stolen, the overwhelming majority of their funds are by no means coming again. Moreover, the attackers’ cycle is quicker than compliance, and yearly that “crypto theft is declining” seems in a headline, the following billion-dollar counterexample is already in movement. The blockchain information all the things and returns nothing.
