DeFi Intel

DeFi and Crypto Hacks 2024-2026: Bybit $1.5B and the Complete Recap

TL;DR

  • The largest crypto hack ever is the Bybit exploit of 21 February 2025: approximately $1.5 billion in ETH, stETH, mETH and cmETH drained from Bybit's cold wallet via a Safe{Wallet} supply-chain attack attributed to North Korea's Lazarus Group.
  • DPRK-attributed actors stole over $1.3B in 2024 (per Chainalysis) — roughly half of all stolen-fund volume globally — and another $1.5B+ in H1 2025 from Bybit alone.
  • Major events 2024-2026 include DMM Bitcoin Japan $305M (May 2024), WazirX India $234M (July 2024), Radiant Capital $50M (October 2024), Penpie $27M (September 2024), Phemex $82M (January 2025), Bybit $1.5B (February 2025), and the Mt Gox 140k BTC repayments (July 2024).
  • Legal aftermath: SBF sentenced to 25 years (March 2024); Avi Eisenberg sentenced to 4 years 4 months for the Mango Markets exploit (April 2024); Do Kwon extradited to the US (early 2025); Alex Mashinsky sentenced (2025); Lichtenstein and Morgan sentenced for the 2016 Bitfinex hack (2024); Roman Storm Tornado Cash trial concluded.

Last updated: 2026-04-26 — Educational recap. Not legal advice. Sources cited at end.

Table of contents

Annual numbers

Year Stolen-fund volume Headline event DPRK share
2021 $3.3B Poly Network ($611m), THORChain hacks ~25%
2022 $3.8B (record) Ronin Bridge ($625m), Wormhole ($325m), Nomad ($190m), FTX ($432m drainer), Terra collapse ~45%
2023 $1.7B Mixin ($200m), Euler ($197m), Curve Vyper ($61m), Atomic Wallet ($100m) ~50%
2024 $2.2B DMM Bitcoin ($305m), WazirX ($234m), Radiant ($50m), Penpie ($27m), BingX ($52m) ~50%+
2025 H1 $2.0B+ Bybit ($1.5B record), Phemex ($82m) >75%
2025 H2 $0.7B (estimated) Multiple smaller exploits, no headline n/a
2026 Q1 $0.4B (estimated) n/a n/a

Sources: Chainalysis Crypto Crime Report 2025, TRM Labs, Elliptic, PeckShield, SlowMist, Rekt News leaderboard.

Bybit February 2025

The Bybit hack of 21 February 2025 is the largest single crypto theft in history. Attackers attributed to North Korea's Lazarus Group drained approximately $1.5 billion in ETH, stETH, mETH and cmETH (LST/LRT derivatives) from Bybit's primary multisig cold wallet over a single coordinated transaction series.

The mechanism was not a Bybit-internal failure — it was a supply-chain attack on Safe{Wallet} (Safe is the leading Ethereum smart-account standard, formerly Gnosis Safe). The attack steps, as forensically reconstructed and attributed by Mandiant, Sygnia, Bybit and the FBI:

  1. Attackers compromised a Safe developer's workstation through a malicious npm package install (likely a typosquatted dependency of the Safe front-end build).
  2. The attacker exfiltrated AWS credentials and gained write access to the S3 bucket serving Safe's official front-end.
  3. Malicious JavaScript was injected into the front-end that selectively activated only when the connected wallet matched the Bybit cold-wallet signing addresses.
  4. When Bybit's signers connected to perform a routine cold-wallet operation, the front-end displayed the legitimate transaction details but the underlying wallet-connect payload sent to the hardware wallets was attacker-crafted: a delegatecall to an attacker contract that swapped the cold wallet's logic for attacker-controlled code.
  5. Once the malicious upgrade was signed by the threshold of Bybit signers, the attackers executed the drain.

Bybit replenished customer funds through a combination of internal capital, emergency loans from market makers, and a previously-undisclosed Bybit Recovery Fund. Withdrawals continued throughout the incident; no customer experienced a halt. CEO Ben Zhou published transparency dashboards within hours and gave nightly press briefings. The episode became a textbook case of post-incident communication.

Forensic attribution was rapid: within 48 hours Safe and Bybit jointly attributed to Lazarus Group based on transaction-laundering patterns matching prior DPRK incidents (Ronin, Atomic Wallet, DMM Bitcoin). The FBI confirmed in a public advisory days later. Approximately 80% of stolen funds were laundered through Tornado Cash and THORChain in the subsequent six weeks; recovery has been minimal.

Industry-wide consequences:

DMM Bitcoin Japan — $305M

On 31 May 2024, Japanese exchange DMM Bitcoin lost 4,502.9 BTC (~$305m) in a hot-wallet compromise attributed to Lazarus Group. The attack vector was reportedly a private-key compromise via social-engineering of a multi-signature signer. DMM Bitcoin shut down withdrawals; parent company DMM.com Securities provided emergency capital to make customers whole. The exchange ultimately wound down its crypto operations in late 2024 and transferred customer accounts to SBI VC Trade.

This was the largest Japanese crypto hack since Coincheck (2018, $530m XEM) and the Mt Gox collapse (2014). It catalysed a Japanese FSA review of multi-signature operational standards which later fed into the 2025 stablecoin regulatory updates.

WazirX India — $234M

On 18 July 2024, Indian exchange WazirX suffered a $234m loss through a multisig wallet operated by its custody provider Liminal Custody. The attack involved manipulation of the multisig signing process: attackers obtained signatures from two of three required signers (Liminal-side, with the third being WazirX), substituted the transaction payload at the on-chain submission step, and drained ERC-20 tokens (SHIB, MATIC, USDT and others).

WazirX's response was contentious. Founder Nischal Shetty initially announced a "socialised loss" plan that distributed the haircut across all customer balances at 55% of pre-hack value. Indian customers and regulators pushed back. WazirX entered a moratorium under Singapore's restructuring law in October 2024, and a recovery plan was approved in 2025 with payments staged through 2026-2027.

The Indian Enforcement Directorate launched a parallel investigation into the platform; technical attribution to Lazarus Group came from Elliptic and TRM Labs.

Phemex — $82M

On 23 January 2025, Singapore-incorporated Phemex lost approximately $82m in a hot-wallet compromise. The attack drained tokens across Ethereum, Polygon, Arbitrum, Optimism, Base, BNB Chain and Tron. Phemex paused withdrawals for 48 hours, replenished customer balances from internal funds, and resumed operations. The incident was attributed to Lazarus Group based on laundering patterns and infrastructure overlap with prior DPRK activity.

Radiant Capital — $50M

On 16 October 2024, the cross-chain lending protocol Radiant Capital was drained for ~$50m through a sophisticated DPRK-attributed compromise of its multisig signer set. The attack vector was a PDF malware delivered to multiple signers via spear-phishing — the malware modified the data shown on signers' Ledger displays so that signers believed they were approving a routine smart-contract upgrade when in fact they were granting administrative control of Radiant's lending pools to attacker-controlled logic.

Within minutes of the malicious upgrade, the attackers drained collateral pools across Arbitrum and Binance Smart Chain. Radiant's response was open: the team published full forensic detail within weeks, including the malicious PDF hash, the npm-style targeting of signer devices, and the gas-limit exploitation pattern. The incident became a case study in multisig display-verification weakness — even hardware-wallet signers cannot reliably verify EVM calldata semantics from a Ledger display alone.

Penpie — $27M

On 3 September 2024, the Pendle yield-aggregator protocol Penpie lost approximately $27m through a reentrancy exploit in its registerPenpiePool integration with Pendle. The bug allowed an attacker to register a malicious pool that re-entered Penpie's reward-claiming logic, claiming rewards multiple times against a single deposit. Pendle itself was unaffected — the bug was in Penpie's integration layer, which had been audited but had not undergone formal verification.

Penpie's response: the team coordinated with the attacker via on-chain messages and ultimately recovered approximately $11m of the funds in a partial bug-bounty settlement; the remaining ~$16m was distributed via a token-emission redemption plan.

Mt Gox repayments July 2024

Mt Gox is not a 2024 hack — but it was a 2024 event. On 5 July 2024, the Mt Gox Rehabilitation Trustee Nobuaki Kobayashi began the long-awaited distribution of approximately 140,000 BTC (and 142,000 BCH) to creditors who had filed claims after the February 2014 collapse. Distributions continued through Q4 2024 via Bitstamp, Kraken, BitGo and SBI VC Trade as designated exchanges.

The market had feared a "Mt Gox supply shock" because the distributed bitcoin had been off-market for over 10 years and represented approximately 0.7% of circulating supply. In practice the distributions had limited near-term price impact: most creditors had already pre-sold their claims to distressed-debt funds at deep discounts in 2018-2022 (typical 12-18 cents on the dollar), and the funds spread their selling over many months. Some creditor cohorts (the "early-bird" recipients who took 90% of fiat value with no further BTC exposure) received fiat in 2018; the 2024 cohort received the appreciated BTC.

The total dollar value distributed in 2024 exceeded $9 billion at then-prevailing prices — the largest single-event distribution in crypto history.

Earlier landmarks

A complete recap requires reaching back to set context for the 2024-2026 environment.

Mango Markets — October 2022, $110M

On 11 October 2022, Avi Eisenberg executed an oracle-manipulation attack on Solana-based Mango Markets. He simultaneously took large MNGO-PERP perpetual positions and pumped MNGO spot price across thin venues; the inflated spot price flowed into the Mango oracle; he then borrowed approximately $110m of other assets against the inflated MNGO collateral. Eisenberg argued his trades were a "highly profitable trading strategy" and not a hack. He was arrested in Puerto Rico in December 2022, convicted in April 2024 on commodities-fraud and wire-fraud charges, and sentenced to 4 years 4 months in April 2024.

Curve Finance — July 2023, $61M

On 30 July 2023, several Curve Finance pools were drained for approximately $61m via a reentrancy bug in Vyper compiler versions 0.2.15, 0.2.16, and 0.3.0. The bug was not in Curve's code — it was in the compiler's gas-refund handling, which made any Vyper contract compiled with those versions vulnerable. The episode was the most dramatic compiler-level supply-chain failure in EVM history. White-hat actors and MEV searchers ultimately recovered substantial portions of the funds; Nexus Mutual paid out claims. The lesson — audit your toolchain, not just your code — reshaped the audit industry.

KyberSwap Elastic — November 2023, $54.7M

On 22 November 2023, KyberSwap Elastic was drained for $54.7m via a complex tick-rounding edge case in concentrated-liquidity math. The attacker, who later identified themselves online with a public statement, demanded "complete executive control" of KyberDAO as a ransom for fund return. Negotiations broke down; the attack catalysed Kyber Network to wind down KyberSwap Elastic in 2024.

The 2022 catastrophes

The 2022 collapses deserve a paragraph each because they shaped the regulatory and risk environment of 2024-2026.

Terra/Luna — May 2022, $40B wipeout

The algorithmic stablecoin UST and its sister token LUNA collapsed in a death spiral starting 9 May 2022. UST de-pegged from $1 as Anchor Protocol's 20% yield proved unsustainable; arbitrage redemptions minted billions of LUNA; LUNA's price collapsed from ~$80 to fractions of a cent within 72 hours. Approximately $40 billion in market cap was destroyed. The collapse triggered the cascade that took down Three Arrows Capital, Voyager, Celsius and ultimately Genesis. Do Kwon, Terraform Labs founder, was arrested in Montenegro in March 2023 and extradited to the US in early 2025. SEC settled with Terraform Labs and Kwon for ~$4.5B in June 2024.

Three Arrows Capital (3AC) — June 2022 collapse

Singapore-based hedge fund 3AC defaulted on Voyager and Genesis loans in late June 2022 after losses on Terra/Luna and leveraged GBTC/stETH trades. Liquidators in the British Virgin Islands took control on 27 June 2022. Founders Su Zhu and Kyle Davies were sanctioned by Singapore's MAS for prior breaches; Su Zhu was detained in Singapore in 2023. The 3AC default was the trigger for the cascading 2022 lending failures.

Celsius — June 2022 collapse, Mashinsky charged

Crypto lender Celsius froze withdrawals on 12 June 2022 and filed for Chapter 11 on 13 July 2022. Founder Alex Mashinsky was charged in July 2023 by the SDNY with securities fraud, commodities fraud and conspiracy. He pleaded guilty to two counts in late 2024 and was sentenced in 2025. Customers received partial recoveries through the bankruptcy process.

Genesis — January 2023 bankruptcy

Genesis Global Capital filed for Chapter 11 on 19 January 2023 after the FTX collapse left it unable to meet redemption demands from Gemini Earn and other counterparties. The case was resolved in 2024 with creditors receiving partial recoveries.

FTX — November 2022 collapse

FTX filed for Chapter 11 on 11 November 2022 after a CoinDesk article on 2 November exposed Alameda Research's balance sheet dependence on FTX's exchange token FTT, and a Binance announcement of intended FTT liquidation triggered a customer run. Within hours of the bankruptcy filing, a separate hot-wallet drain of approximately $432m occurred — initially believed to be an exploit but later identified as either an inside job or Bahamian regulator-coordinated transfer (subject to ongoing dispute).

Sam Bankman-Fried was arrested in The Bahamas in December 2022 and extradited to the US. He was convicted on seven federal charges in November 2023 by an SDNY jury. On 28 March 2024 Judge Lewis Kaplan sentenced him to 25 years in federal prison. Caroline Ellison (CEO of Alameda) cooperated and received 24 months; Gary Wang and Nishad Singh received time served. SBF is incarcerated at FCI Terminal Island in California; multiple appeals are pending.

The FTX bankruptcy estate, led by John Ray III, ultimately recovered enough assets — partly through the post-2024 crypto market rally — to make all customer claims whole at petition-date dollar values, with substantial residual recoveries flowing to general unsecured creditors and equity holders.

Lazarus Group cumulative attribution

Lazarus Group, the catch-all name for North Korean state-sponsored cyber actors operating under the Reconnaissance General Bureau, has been the dominant single source of crypto theft since 2018.

Incident Date Amount Source
Atomic Wallet June 2023 $100M Multiple wallets compromised via supply chain
Stake.com Sep 2023 $41M Hot wallet compromise
CoinEx Sep 2023 $54M Private-key extraction
HTX/Heco bridge Nov 2023 $113M Multi-sig compromise
DMM Bitcoin May 2024 $305M Multi-sig social engineering
WazirX Jul 2024 $234M Liminal Custody multi-sig manipulation
Radiant Capital Oct 2024 $50M PDF malware multi-sig display attack
Phemex Jan 2025 $82M Hot wallet compromise
Bybit Feb 2025 $1.5B Safe{Wallet} supply-chain

Cumulative DPRK crypto theft 2018-2026: estimated $5-6 billion. Funds are typically laundered through cross-chain bridges (THORChain, eXch), mixers (Tornado Cash and successors), and OTC desks in jurisdictions with weak AML enforcement, before being converted to USDT and ultimately to fiat for North Korean state use.

Top crypto audit firms

The leading crypto smart-contract security firms as of April 2026:

Firm Founded Notable engagements Strength
Trail of Bits 2012 Curve, Compound, Aave, Uniswap Static analysis, fuzzing
OpenZeppelin 2015 Compound, Aave, Maker, Tether Library standardisation
ConsenSys Diligence 2017 Aave, 0x, mStable, Maker EVM expertise
Halborn 2019 Solana, Avalanche, Polygon, Sui Multi-chain
PeckShield 2018 EOS, BNB Chain, Solana ecosystem Forensics
SlowMist 2018 OKX, Binance, Pancake Asia coverage, forensics
BlockSec 2021 Ankr, Compound, Avalanche bridges Real-time MEV/exploit detection
Spearbit 2021 Lido, MakerDAO, Polygon zkEVM Researcher network
Quantstamp 2017 Ethereum 2.0, Polkadot, Maker Formal methods
Sigma Prime 2016 Ethereum consensus client (Lighthouse) Consensus & cryptography
Zellic 2022 Ondo, Aerodrome, Movement Modern audit boutique
Cyfrin 2022 Aave, Polygon, Maker Codehawks community

Audit competition platforms (multiple researchers, fixed prize pools):

Bug bounty platforms:

For protocol selection, look for:

Person Role Charge / outcome Year
Sam Bankman-Fried FTX / Alameda founder 25 years SDNY March 2024
Caroline Ellison Alameda CEO 24 months, cooperated September 2024
Gary Wang FTX co-founder Time served, cooperated November 2024
Nishad Singh FTX engineer Time served, cooperated October 2024
Avi Eisenberg Mango Markets exploit 4 years 4 months April 2024
Do Kwon Terraform Labs founder Pleaded guilty; sentenced to 15 years 2025
Alex Mashinsky Celsius founder Pleaded guilty, sentenced 2025 2025
Ilya Lichtenstein 2016 Bitfinex hack money laundering 5 years November 2024
Heather Morgan ("Razzlekhan") 2016 Bitfinex hack money laundering 18 months November 2024
Roman Storm Tornado Cash co-developer Trial concluded 2025 2025
Changpeng "CZ" Zhao Binance CEO 4 months, BSA violations April 2024

The Bitfinex 2016 hack is the iconic late-resolution case. Approximately 119,756 BTC were stolen from Bitfinex's hot wallets in August 2016. The funds sat dormant for nearly six years before laundering activity began in early 2022. Ilya Lichtenstein and Heather Morgan were arrested in February 2022; the seized BTC at the time of arrest was worth approximately $3.6B, the largest single financial seizure in DOJ history. They pleaded guilty in 2023 and were sentenced in November 2024.

How to assess DeFi protocol security

Eight checks before depositing significant capital in any DeFi protocol:

  1. Two independent top-tier audits — covering the deployed contract version, by Trail of Bits, OpenZeppelin, ConsenSys Diligence, Halborn or equivalent, within the last 12 months.
  2. Active Immunefi bug bounty — with a maximum payout of at least $1m and clear scope. The bounty must cover deployed contracts, not just testnet.
  3. Time-locked upgrades — minimum 48-hour delay on contract upgrades, with on-chain transparency on the timelock contract. This gives users time to exit if a malicious upgrade is queued.
  4. Multi-signature governance — ideally 3-of-5 or larger with publicly identifiable, reputable signers. Single-signer or 2-of-3 with anonymous signers is a red flag.
  5. Formal verification or extensive fuzz-testing — for critical math (interest accrual, share-token redemption, oracle integrations).
  6. Transparent on-chain treasury — with regular reporting and ideally an independent auditor.
  7. No unaudited new code shipped in the last 30 days — fresh code without re-audit is the most common exploit surface.
  8. Public incident-response plan and track record — how the team has handled prior issues.

Plus: avoid yield that is significantly higher than the prevailing risk-free benchmark unless you can mechanistically explain where the yield comes from.

Risks and criticism

Research and reports

Use cases / examples

FAQ

What was the largest crypto hack ever?

The largest crypto hack on record is the Bybit exploit of 21 February 2025, in which Lazarus Group attackers drained approximately $1.5 billion in ETH, stETH, mETH and cmETH from Bybit's cold wallet through a supply-chain attack on Safe{Wallet}'s deployment infrastructure. The attackers compromised a Safe developer's machine, injected malicious JavaScript into the Safe UI, and tricked Bybit's signers into approving a transaction that delegated control of the cold wallet to attacker-controlled logic. The previous record was Ronin Bridge ($625m March 2022, also Lazarus). Bybit replenished customer balances within 72 hours and continued operating without halting withdrawals.

Who is Lazarus Group and how much have they stolen?

Lazarus Group is the catch-all name for North Korean state-sponsored cyber actors operating under the Reconnaissance General Bureau. According to Chainalysis and TRM Labs, DPRK-attributed actors stole more than $1.3 billion of crypto in 2024 alone — roughly half of all stolen-fund volume globally — and over $1.5B in H1 2025 from the Bybit hack alone. Major historical attributions include Ronin Bridge ($625m, 2022), Atomic Wallet ($100m, 2023), Stake.com ($41m, 2023), DMM Bitcoin ($305m, 2024), WazirX ($234m, 2024), Phemex ($82m, 2025), Radiant Capital ($50m, 2024), and Bybit ($1.5B, 2025).

How was Bybit hacked in 2025?

The 21 February 2025 Bybit hack was a supply-chain attack on Safe{Wallet}'s deployment infrastructure, not on Bybit's internal systems. Attackers compromised a Safe developer's workstation through a malicious npm-package install, injected modified JavaScript into the Safe UI served from the AWS S3-backed front-end, and waited until a Bybit cold wallet signing ceremony. Bybit's signers saw the legitimate Safe interface but were signing attacker-crafted delegate-call transactions that took control of the wallet's logic. The attackers then drained approximately $1.5B in ETH derivatives. Safe and Bybit jointly attributed the attack to Lazarus Group within 48 hours.

What happened to Sam Bankman-Fried (SBF)?

Sam Bankman-Fried, founder of FTX and Alameda Research, was convicted on seven federal charges in November 2023 and sentenced to 25 years in federal prison on 28 March 2024 by Judge Lewis Kaplan in the Southern District of New York. The charges included wire fraud, conspiracy to commit wire fraud, money laundering, and securities fraud. Caroline Ellison, Gary Wang and Nishad Singh pleaded guilty to related charges and cooperated; their sentences were 24 months, time served, and time served respectively. SBF was moved to FCI Terminal Island in California in April 2025; multiple appeals are pending.

What happened to Do Kwon and Terra/Luna?

Do Kwon, the founder of Terraform Labs whose UST stablecoin and LUNA collapse erased approximately $40 billion in value in May 2022, was arrested in Montenegro in March 2023 and extradited to the United States in early 2025 after extensive legal back-and-forth between US and South Korean prosecutors. He pleaded guilty in August 2025 to conspiracy and wire-fraud charges in the Southern District of New York, and was sentenced to 15 years in prison in December 2025. Separately, the SEC settled its civil case against Terraform Labs and Kwon for approximately $4.5B in June 2024.

What is the cumulative amount stolen in DeFi hacks 2024-2026?

Combined: 2024 saw approximately $2.2B in stolen-fund value (per Chainalysis), with over $1.3B attributed to DPRK actors. 2025 H1 alone saw more than $2B in stolen funds — driven primarily by the $1.5B Bybit hack. Including the second half of 2025 and Q1 2026, cumulative crypto stolen-fund volume from January 2024 through April 2026 is approximately $5.0-5.5 billion. Stolen-fund volume in 2022 was the all-time annual record at $3.8B (driven by cross-chain bridge hacks); 2023 fell to $1.7B; 2024 rose to $2.2B; 2025 will likely set a new record because of Bybit alone.

Who are the top crypto audit firms?

The leading code-audit firms are Trail of Bits, OpenZeppelin, ConsenSys Diligence, Halborn, PeckShield, SlowMist, BlockSec, Spearbit, Sigma Prime, Quantstamp and Zellic. Audit competitions are run on Code4rena, Sherlock, and Cantina. Bug bounty programmes are run primarily through Immunefi (the largest, with cumulative payouts over $100m). For protocol selection, look for at least two independent audits from top-tier firms, an active live bug bounty with at least $1m maximum payout, time-locked upgrades, and ideally formal verification of critical components.

What was the Curve Finance hack and how was it different?

On 30 July 2023, several Curve Finance pools using Vyper compiler versions 0.2.15, 0.2.16 and 0.3.0 were drained for approximately $61m via a reentrancy bug in those Vyper versions' gas-refund logic. The bug was not in Curve's code — it was in the smart-contract compiler itself, which made the Curve pools that were compiled with those Vyper versions vulnerable despite Curve's well-audited Solidity-equivalent logic. White-hat attackers and MEV searchers ultimately recovered substantial portions of the funds. The incident reshaped industry attention on compiler-level supply-chain risk and led to broader audit-coverage of toolchain dependencies.

What happened to Mango Markets and Avi Eisenberg?

Avi Eisenberg manipulated the Mango Markets perpetual-futures price oracle on 11 October 2022 by simultaneously taking large MNGO-PERP positions and pumping the spot price across thin liquidity venues, then borrowing approximately $110m of other assets against the inflated MNGO collateral. He left Mango Markets effectively insolvent. Eisenberg argued in interviews that his trades were "highly profitable trading strategy" and not a hack. He was arrested in Puerto Rico in December 2022 and convicted on commodities-fraud, manipulation and wire-fraud charges in April 2024. He was sentenced to 4 years 4 months in April 2024.

How can I assess the security of a DeFi protocol before depositing?

Eight checks: (1) at least two independent audits from top-tier firms (Trail of Bits, OpenZeppelin, ConsenSys Diligence, Halborn) within the last 12 months covering the deployed contract version. (2) Active Immunefi bug bounty with at least $1m maximum payout and clear scope. (3) Time-locked upgrades with a minimum 48-hour delay and on-chain transparency. (4) Multi-signature governance with at least 3-of-5 with reputable signers. (5) Formal verification or fuzz-testing coverage for critical math and accounting logic. (6) Transparent on-chain treasury and reserves with regular reporting. (7) No unaudited new feature shipped in the last 30 days. (8) A public incident-response plan and historical track record on prior incidents.

Glossary

Sources and further reading

About the author

DeFi Intel Research is a specialist crypto and digital-asset research desk. Our security desk monitors on-chain forensic data, audit-firm publications, court filings and regulator advisories. We do not provide legal or investment advice. We publish research, education and data — and we cite our sources.

Last updated: 2026-04-26

Stay current on this topic

Get the weekly DeFi Intel brief — entity-graph intelligence on defi hacks 2024, defi hacks 2025, defi hacks 2026, free to your inbox.

Frequently asked questions

What was the largest crypto hack ever and how much was stolen?

The largest crypto hack ever is the Bybit exploit of 21 February 2025, where approximately $1.5 billion in ETH, stETH, mETH and cmETH was drained from Bybit's cold wallet.

How did the Bybit hack occur?

The Bybit hack was a supply-chain attack on Safe{Wallet} where attackers compromised a Safe developer's workstation through a malicious npm package install, exfiltrated AWS credentials, and gained write access to the S3 bucket serving Safe's official front-end.

Which group was attributed to the Bybit hack?

The Bybit hack was attributed to North Korea's Lazarus Group.