The cryptocurrency industry’s largest thefts have repeatedly demonstrated that the biggest challenge facing digital assets is not simply market volatility but the security of the infrastructure that holds and moves them. A series of major attacks, including the latest theft involving hundreds of millions of dollars, shows how exchanges, digital wallets and blockchain-based systems remain attractive targets for sophisticated cybercriminals.
The scale of the losses has grown alongside the cryptocurrency market itself. When digital assets were relatively small, individual hacks could cause severe damage to individual users but had limited implications for the broader financial system. As the value and institutional use of cryptocurrency have expanded, the incentives for organised attackers have increased accordingly.
The largest incidents also show that there is no single vulnerability responsible for crypto theft. Attackers have exploited exchanges, wallet systems, software infrastructure and operational weaknesses.
The largest attacks have different causes
The record-setting theft from Bybit in February 2025 involved roughly $1.5 billion worth of Ether. U.S. authorities attributed the attack to North Korea, while investigators said the stolen assets were quickly moved through multiple cryptocurrencies and blockchain addresses.
Other major attacks have involved very different circumstances. The Poly Network theft in 2021 involved around $610 million, much of which was later returned. The Ronin Network attack in 2022 involved roughly $540 million and was associated with the infrastructure supporting a blockchain-based game.
Earlier incidents exposed weaknesses in centralised exchanges and digital wallets. The Coincheck theft in 2018 involved around $530 million in cryptocurrency stored in a hot wallet, while the collapse of Mt. Gox followed a long period of security problems and the theft of hundreds of millions of dollars in Bitcoin.
The different mechanisms matter because they demonstrate that simply moving assets onto a blockchain does not automatically make the surrounding infrastructure secure.
Exchanges remain attractive targets
Cryptocurrency exchanges combine large pools of valuable assets with complex technical systems. That makes them attractive to attackers because a successful breach can potentially produce an enormous payoff.
The latest major theft from Bitget initially involved approximately $350 million in cryptocurrency, with later assessments putting the loss considerably higher. The incident reinforced concerns about the security of the systems that manage digital-asset transactions.
The response to such attacks increasingly involves freezing withdrawals, tracing blockchain transactions and attempting to identify destination addresses. Blockchain transparency can help investigators follow stolen assets, but tracing funds does not guarantee that they can ultimately be recovered.
Attackers can move assets between different blockchains, exchange one cryptocurrency for another and use large numbers of addresses. That makes recovery a race against time.
The threat is becoming more organised
The growth of cryptocurrency theft also reflects a shift in the type of criminals involved. Authorities have warned that organised crime groups can use digital assets to move funds across borders outside conventional financial channels. State-linked actors have also been accused of conducting major cryptocurrency thefts.
Researchers have estimated that cybercriminals stole billions of dollars in cryptocurrency across hundreds of attacks during 2025.
This means that security cannot be treated as an optional feature of digital-asset platforms. It is becoming a core requirement for the industry’s continued development.
The challenge is particularly complicated because cryptocurrency businesses often combine decentralised technologies with centralised operational systems. A blockchain may function according to predetermined rules, but exchanges still have employees, software interfaces, authentication systems, wallets and administrative controls.
Attackers therefore do not necessarily need to defeat the underlying blockchain. They can instead search for weaknesses in the systems surrounding it.
Security is becoming central to crypto’s credibility
Repeated billion-dollar thefts have consequences beyond the immediate victims. Every major breach raises questions about whether cryptocurrency platforms can protect assets at a level expected of established financial institutions.
The industry has responded with stronger custody systems, transaction monitoring, multi-layer authentication and increasingly sophisticated blockchain tracing. But the scale of the attacks demonstrates that security improvements are competing against equally rapid advances in attack techniques.
The history of crypto theft therefore reveals a persistent structural problem. Digital assets may offer transparency and programmability, but those characteristics do not eliminate the need for secure infrastructure.
As cryptocurrency becomes more deeply integrated into financial markets, the industry’s ability to reduce large-scale theft will become increasingly important to its credibility. The record of major hacks suggests that technological innovation alone cannot solve the problem. Security has to be built into exchanges, wallets, software, governance and operational controls at every stage of the digital-asset system.
(Adapted from Reuters.com)









