Skip to content
Client Focus

Insights

2025 digital asset losses: what the numbers say about operations

Approximately 3.4 billion dollars was stolen in 2025, concentrated in a small number of large incidents, with DPRK-linked actors responsible for a record share.

Operations notes

Published
August 22, 2026
Covers
Full year 2025
Reading time
6 minutes
By
Client Focus

Chainalysis reported approximately 3.4 billion dollars stolen in crypto hacks during 2025. The headline figure is less instructive than its shape. The losses were concentrated, the mix shifted, and the categories that grew are the ones institutions have the least direct control over.

Concentration

A small number of incidents accounted for most of the service-related total. The February exchange breach alone represented a large share of the year's losses. Concentration of that kind changes how a risk function should think about the number: the expected annual loss across the industry is not a useful planning input for a single institution, because the distribution is dominated by rare events at the signing and integration boundaries.

The shift to personal wallet compromise

Losses attributable to individual wallet compromise grew as a share of the total. The relevance to institutions is indirect but real. Personal device and credential compromise is the entry path into privileged workflows: an engineer's laptop, an approver's phone, a treasury operator's browser session. The perimeter that matters is not only the corporate estate but the specific endpoints that participate in signing and administration.

DeFi losses suppressed while value rose

Protocol-level losses did not scale with total value locked. Audit practice, bug bounty coverage, timelocks and battle-tested contract patterns have measurably reduced the frequency of pure contract exploits. This is genuine progress, and it moves the attacker toward the parts of the stack that audits do not cover: front ends, key management, governance processes and the people who approve transactions.

What the pattern means for institutions

The exposure is at the signing boundary and the integration boundary, not primarily in the contract. Controls should follow the exposure. Independent transaction verification, policy engines evaluated before signing, hardened approver endpoints, correlation of privileged actions against change records, and continuous monitoring with named ownership address the categories that are actually growing. An audit report describes a contract at a point in time. Continuous operations describe the system as it runs.

Into 2026

CertiK reported approximately 1.31 billion dollars lost in the first half of 2026 across incident types it tracks. Methodologies differ between publishers and figures are not directly comparable, which is a further argument against managing to an industry aggregate. The stable finding across sources is the location of the failure rather than its size: the human and integration paths around the contract, operated continuously or not at all.

Printed annual loss analysis on a desk beside a laptop in daylight

Continue reading

Printed annual loss analysis on a desk beside a laptop in daylight

The February 2025 exchange breach: lessons for signing operations

The largest theft in the industry's history to date, approximately 1.5 billion dollars from a single exchange, was executed through the signing workflow, not a smart contract bug.

Printed operational reports and a notebook on a desk in daylight

2025 in review: the year digital assets became an operations problem

Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.

A quiet office corridor with glass-walled meeting rooms in daylight

Privileged actions on-chain: the events a security operations center must treat as critical

Role grants, configuration-flag changes, proxy upgrades and pause-state changes are the highest-signal events in a contract's life.

Apply this to your own operations.

Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.