- Crypto industry losses exceeded $3.1 billion in the first half of 2025, surpassing total losses for 2024.
- Access management vulnerabilities accounted for nearly 60% of these losses.
- Phishing attacks are on the rise, with fake calls from Coinbase and malicious dApps being popular methods.
- Significant breaches include Bybit’s $1.46 billion loss and Cetus Protocol’s $223 million hack.
- Social engineering attacks caused approximately $600 million in losses, marking them as a significant threat to Web3 security.
The Rising Tide of Crypto Losses in 2025
In an alarming development reported by Hacken, the cryptocurrency industry witnessed staggering losses exceeding $3.1 billion in just the first half of 2025. This figure already surpasses the total losses incurred throughout all of 2024. The report highlights critical vulnerabilities in access management as a primary cause, with hackers exploiting weaknesses through phishing attacks involving fake calls from well-known entities like Coinbase and deploying malicious decentralized applications (dApps).
Access Management Vulnerabilities: A Major Concern
The most substantial damage came from attacks related to access management vulnerabilities, which accounted for approximately $2 billion out of the total losses. These incidents made up about 59% of overall damages. A major breach involved Bybit, resulting in a massive loss of $1.46 billion, marking it as one of the largest hacks not only during this period but also in crypto history.
Hacken’s research identified similar vulnerabilities across smaller protocols such as UPCX and KiloEx, which suffered significant financial impacts. Despite a reduction in scale during the second quarter—from $1.6 billion to $190.5 million—the threat remains persistent.
DeFi Under Siege: The Smart Contract Problem
Smart contracts have emerged as another area fraught with challenges, causing losses amounting to $263 million during this period. Notably, Cetus Protocol suffered a breach resulting in a loss of $223 million within just 15 minutes.
Additionally, Hacken noted a historical attack on Uniswap V4’s hook mechanics where attackers exploited lack of basic verification checks to steal $12 million from Cork Protocol.
The Pervasiveness of Phishing and Social Engineering
Social engineering has proven to be one of the most dangerous threats in Web3 ecosystems according to experts at Hacken. In just six months, these types of attacks inflicted damages nearing $600 million on the industry.
Methods often involve manipulating user trust via phishing schemes or fake interfaces—leading users into signing dangerous transactions or providing sensitive information under false pretenses.
A case that drew notable attention involved scammers posing as support staff convincing an elderly U.S.-based investor into transferring assets worth $330 million directly into their control—a record-breaking individual theft for this sector.
Moreover, criminals leveraged leaked user data for personalized scams including impersonating Coinbase staff through deceptive phone calls—resulting in additional user losses totaling around $100 million.
Protective Measures Against Threats
To combat these emerging threats effectively requires proactive steps from both organizations within crypto spheres alongside individual users themselves:
– Implement cold storage solutions when possible.
– Employ multi-signature protocols coupled with time-lock mechanisms.
– Ensure private keys are accessed strictly via dedicated devices used solely for securing transactions.
Hacken underscores how digital hygiene plays an essential role—caution should be exercised before clicking suspicious links regardless if received through emails or messaging apps like Telegram/SMS chats while verifying sender authenticity is crucial too!
In conclusion; although technology continues advancing rapidly bringing forth new opportunities within blockchain domains—the human element remains its weakest link rendering robust cybersecurity practices indispensable amidst evolving adversarial tactics targeting unsuspecting stakeholders globally!
