Chainalysis reported approximately 3.4 billion dollars stolen in crypto hacks during 2025. The headline figure is less instructive than its shape. The losses were concentrated, the mix shifted, and the categories that grew are the ones institutions have the least direct control over.
Concentration
A small number of incidents accounted for most of the service-related total. The February exchange breach alone represented a large share of the year's losses. Concentration of that kind changes how a risk function should think about the number: the expected annual loss across the industry is not a useful planning input for a single institution, because the distribution is dominated by rare events at the signing and integration boundaries.
The shift to personal wallet compromise
Losses attributable to individual wallet compromise grew as a share of the total. The relevance to institutions is indirect but real. Personal device and credential compromise is the entry path into privileged workflows: an engineer's laptop, an approver's phone, a treasury operator's browser session. The perimeter that matters is not only the corporate estate but the specific endpoints that participate in signing and administration.
DeFi losses suppressed while value rose
Protocol-level losses did not scale with total value locked. Audit practice, bug bounty coverage, timelocks and battle-tested contract patterns have measurably reduced the frequency of pure contract exploits. This is genuine progress, and it moves the attacker toward the parts of the stack that audits do not cover: front ends, key management, governance processes and the people who approve transactions.
What the pattern means for institutions
The exposure is at the signing boundary and the integration boundary, not primarily in the contract. Controls should follow the exposure. Independent transaction verification, policy engines evaluated before signing, hardened approver endpoints, correlation of privileged actions against change records, and continuous monitoring with named ownership address the categories that are actually growing. An audit report describes a contract at a point in time. Continuous operations describe the system as it runs.
Into 2026
CertiK reported approximately 1.31 billion dollars lost in the first half of 2026 across incident types it tracks. Methodologies differ between publishers and figures are not directly comparable, which is a further argument against managing to an industry aggregate. The stable finding across sources is the location of the failure rather than its size: the human and integration paths around the contract, operated continuously or not at all.