The biggest crypto hack of all time is the Bybit Cold Wallet Compromise, with $1.46 billion stolen on February 21, 2025. Across 23 tracked major exploits and thefts, over $6.1 billion has been lost, ranked here by total USD stolen. The list spans exchange hacks, bridge exploits, DeFi attacks, and governance exploits dating from 2016 to 2026.
While some hacks resulted in full recoveries—such as the Poly Network and Euler Finance incidents—many funds remain lost. The ranking highlights the ongoing security challenges in the crypto space, with bridge exploits and exchange vulnerabilities dominating the top losses. The pattern has continued into 2026: the two largest exploits of the year so far — the Kelp DAO bridge drain ($292M, April 18, 2026) and the Drift Protocol admin takeover ($285M, April 1, 2026), both attributed by investigators to North Korean state-linked actors — already rank among the ten biggest crypto thefts of all time. Notably, both defeated off-chain infrastructure (bridge verifier nodes, pre-signed admin transactions) rather than smart-contract code, echoing the operational-security failures behind Bybit and Ronin.
-
#1
Bybit Cold Wallet Compromise (Feb 21, 2025)
$1.46B
On February 21, 2025, Bybit's Ethereum cold wallet was drained of approximately 401,346 ETH plus staked-ETH derivatives in a single execution — $1.46B, the largest crypto theft ever. Attackers injected malicious JavaScript into the Safe multisig signing interface; the attack is attributed to North Korea's Lazarus Group, and no customer funds were lost.
-
#2
Ronin Bridge Validator Compromise (March 23, 2022)
$620M
On March 23, 2022, the Ronin Bridge — the canonical bridge between Ethereum and the Ronin sidechain hosting Sky Mavis's Axie Infinity ecosystem — was drained of 173,600 ETH and 25.5M USDC ($620M) after a spear-phishing campaign compromised five of the bridge's nine validator keys — enough to meet its 5-of-9 signing threshold.
-
#3
Poly Network Cross-Chain Exploit (August 10, 2021)
$611M
On August 10, 2021, an attacker exploited a flaw in Poly Network's verifyHeaderAndExecuteTx function to overwrite the cross-chain bridge's keeper keys and withdraw $611M across Ethereum, BNB Chain, and Polygon — then returned effectively all of the funds in the weeks that followed.
-
#4
BNB Chain Token Hub IAVL Proof Forgery (Oct 7, 2022)
$568M
On October 6-7, 2022, an attacker forged IAVL Merkle proofs against the BSC Token Hub — BNB Chain's native cross-chain bridge — to mint 2 million BNB (~$568M). Validators halted block production mid-attack, freezing roughly $430M before it could leave the chain.
-
#5
Coincheck NEM Hot-Wallet Theft (Jan 26, 2018)
$530M
On January 26, 2018, Tokyo-based exchange Coincheck reported the unauthorized transfer of 523 million NEM (XEM) tokens (~$530M) from a single hot wallet whose key was compromised via targeted phishing — the tokens had never been moved to cold storage.
-
#6
Wormhole Bridge Signature Bypass (Feb 2, 2022)
$326M
On February 2, 2022, an attacker bypassed the Wormhole Bridge's signature verification using a deprecated Solana function and minted 120,000 unbacked wETH (~$326M). Jump Crypto fully replenished the bridge's locked-ETH reserves via a $326M bailout within 24 hours.
-
#7
KelpDAO rsETH Cross-Chain Bridge Exploit (April 18, 2026)
$292M
Kelp DAO lost ~116,500 rsETH (~$292M) on April 18, 2026 — the biggest exploit of 2026 so far — when an attacker defeated its LayerZero bridge's single one-of-one DVN by compromising RPC nodes and feeding the verifier fabricated burn records, minting unbacked rsETH across destination chains.
-
#8
Drift Protocol DPRK Admin-Access and Fake-Oracle Exploit (April 1, 2026)
$285M
Drift Protocol, then Solana's largest perpetual-futures DEX, lost ~$285M on April 1, 2026 — the second-largest Solana hack after Wormhole (2022). A months-long DPRK social-engineering operation abused Solana durable nonces to obtain pre-signed multisig approvals, seized admin control, whitelisted a fake wash-traded token as collateral, and drained three vaults in about 12 minutes.
-
#9
WazirX Exchange Hack (Jul 18, 2024)
$235M
On July 18, 2024, WazirX, India's largest cryptocurrency exchange by spot trading volume, lost approximately $235M in customer assets when a social-engineering attack attributed to the Lazarus Group compromised its Liminal Custody-managed multisig via manipulated transaction calldata.
-
#10
Cetus Protocol Exploit on Sui (May 22, 2025)
$223M
On May 22, 2025, Cetus Protocol, the dominant concentrated-liquidity DEX on the Sui Network, suffered an exploit driven by an integer-overflow bug in its tick-math library. External coverage (The Block, CoinDesk) puts the loss at ~$223M, while the DeFi Intel post-mortem estimates $230M. Sui validators froze roughly $162M, later returned via a community vote, while ~$60M was bridged out; Cetus restored pools and announced full user reimbursement.
-
#11
Euler Finance donateToReserves Exploit (March 13, 2023)
$197M
On March 13, 2023, an attacker drained approximately $197M from Euler Finance, an Ethereum money market, via a faulty donateToReserves function combined with flash-loan self-liquidation. After public on-chain negotiation the attacker returned all stolen funds, and Euler fully reimbursed users.
-
#12
Beanstalk Flash-Loan Governance Attack (April 17, 2022)
$182M
On April 17, 2022, the Beanstalk Farms stablecoin protocol was drained of approximately $182M in a single atomic transaction: the attacker used a ~$1B flash loan to acquire majority governance power and pass a malicious proposal that transferred protocol funds to their own address.
-
#13
Cream Finance Third Hack of 2021 (Oct 27, 2021)
$130M
On October 27, 2021, Cream Finance, a Compound-fork lending protocol, suffered its third and largest exploit of the year — $130M — via a flash-loan-amplified price-oracle manipulation of its yUSD vault collateral. No recovery was possible.
-
#14
Atomic Wallet Mass Seed-Phrase Compromise (Jun 3, 2023)
$100M+
Beginning June 2-3, 2023, roughly 5,500 users of Atomic Wallet, a non-custodial multi-asset wallet, had funds drained in a mass seed-phrase compromise attributed to the Lazarus Group, with losses exceeding $100M. Most victims recovered nothing.
-
#15
Curve Finance Vyper Reentrancy Compiler Bug (July 30, 2023)
$73M
On July 30, 2023, multiple Curve Finance stable pools were drained via a previously-unknown bug in the Vyper compiler's @nonreentrant decorator (versions 0.2.15-0.3.0), which silently failed to block reentrancy. Whitehat frontruns and negotiated returns brought recovery to roughly 73% of the $73M taken.
-
#16
Bitfinex Multisig Compromise (Aug 2, 2016)
$72M (119,756 BTC)
On August 2, 2016, Hong Kong-based exchange Bitfinex disclosed the theft of 119,756 BTC (~$72M at the time) through its BitGo-integrated multisig hot-wallet architecture. Bitfinex made customers whole via BFX tokens; US authorities later recovered most of the coins and convicted Ilya Lichtenstein of executing the theft.
-
#17
The DAO Reentrancy Exploit (June 17, 2016)
$60M
On June 17, 2016, an attacker exploited a reentrancy vulnerability in The DAO, an Ethereum investment vehicle holding roughly 14% of all ETH, recursively withdrawing ~$60M. Ethereum's July 20, 2016 hard fork returned the ether to holders — and the un-forked chain lives on as Ethereum Classic.
-
#18
Humanity Protocol Bridge Admin-Key Theft (June 9, 2026)
$36M
A June 5, 2026 phishing email impersonating Bithumb planted root-access malware on a Humanity Protocol employee laptop that held seven private keys, letting the attacker push a malicious bridge upgrade, drain ~141M H tokens, and mint 300M more on BNB Chain. Forensics tied the tooling to North Korean groups.
-
#19
Step Finance Treasury Drain and Shutdown (January 31, 2026)
$27M
Step Finance, Solana's longest-running portfolio dashboard, lost 261,854 SOL (~$27M, with ~$40M claimed across all assets) on January 31, 2026 after attackers phished executive-team devices, took over the treasury keys, unstaked the protocol's SOL, and withdrew it. The protocol announced its shutdown.
-
#20
Truebit Legacy-Contract Mint Exploit (January 8, 2026)
$26M
Truebit lost 8,535 ETH (~$26.4M) on January 8, 2026 — 2026's first major crypto exploit — when an attacker triggered an integer overflow in a dormant, unverified, roughly five-year-old bonding-curve contract, minting TRU for zero ETH and looping sells to drain the reserves.
-
#21
Resolv USR Minting-Key Compromise and Depeg (March 22, 2026)
$25M
Resolv's USR stablecoin was exploited on March 22, 2026 after attackers compromised the AWS KMS-hosted SERVICE_ROLE minting key through a supply chain that began with a contractor's stolen GitHub credential. The attacker minted 80 million unbacked USR against under $200,000 of USDC and cashed out roughly 11,409 ETH (~$24.5M) as USR depegged.
-
#22
Grinex Exchange Wallet Drain (April 17, 2026)
$14M
Grinex, the Kyrgyzstan-incorporated successor to the sanctioned Russian exchange Garantex, was drained of ~$13.74M (on-chain ~$15M in USDT) from dozens of hot wallets on TRON and Ethereum, with the proceeds instantly swapped into non-freezable TRX. Attribution remains contested.
-
#23
Matcha Meta / SwapNet Aggregator Arbitrary-Call Exploit (January 25, 2026)
$13M
On January 25, 2026, an arbitrary-call bug in SwapNet, a closed-source DEX aggregator integrated into 0x's Matcha Meta, let an attacker abuse users' standing infinite approvals and sweep ~$13.43M from about 20 wallets across Ethereum, Arbitrum, Base, and BNB Chain.