🔐 Crypto Hacks 2025: The Endless War Between Protocols & Attackers
-
Despite billions poured into cybersecurity, the crypto industry remains locked in what experts call an “endless war” against hackers.According to Ronghui Gu (Columbia University professor & CertiK co-founder), protocols can patch vulnerabilities and improve audits, but attackers only need one weak point—often a human mistake—to exploit.
“As long as there’s a weak point out there, sooner or later attackers will find it… I’m afraid next year’s hacks will still be at a billion-dollar level.” — Ronghui Gu
Hack Losses: 2025 by the Numbers
$2.47B lost in H1 2025 (already more than all of 2024’s $2.4B)
Q2 2025: 144 incidents, ~$800M lost (52% less value lost vs Q1)
Largest exploit ever: $1.4B Bybit hack on Feb. 21, 2025
Source: CertiK
The Shift: From Code to People
As Layer 1s and protocols harden security, hackers are increasingly targeting human behavior:
Private key compromises caused ~50% of incidents in 2024
Phishing & social engineering scams are on the rise
Common tactics: malicious links, fake approvals, wallet-drainer contracts
Recent cases:
Aug. 6: Investor lost $3M USDT by signing a malicious transaction (wallet address mismatch hidden in middle characters).
Aug. 3: Another victim lost $900K+, 458 days after unknowingly approving a malicious wallet-drainer.
The Takeaway
Cybersecurity firms can audit millions of lines of code daily, but it takes only one overlooked bug or one careless click to trigger massive losses.
The battlefield is shifting: tech is getting harder to hack, humans aren’t.
As phishing gets more sophisticated, education and behavioral safeguards may become just as critical as protocol-level security.
-