Study of 372+ ICOs shows that ~$400M of the total $3.7B funds raised to date have been stolen, with phishing as the most widely used hacking technique
Context & Ripple Effects
ICOs went from curiosity to capital machine in under a year: by mid-2017, 65 projects had already pulled in $522M, with the New York Times flagging the unregulated structure as an open invitation for abuse. This study quantifies one half of that warning — of the $3.7B raised across 372+ offerings, roughly $400M never reached the projects because attackers took it first, with phishing as the dominant technique.
The finding lands just before the market's biggest expansion: within months, an analysis found 271 of 1,450 ICOs carried red flags like plagiarized white papers and fake executives, and ICOs went on to raise $13.7B in the first five months of 2018 alone. Theft at the point of contribution was thus compounding with outright fraud at the point of issuance.
First-order effects
- Contributors to token sales are losing funds directly to phishers who impersonate project addresses during fundraising windows, and issuers absorb reputational damage for thefts they did not commit.
Second-order effects
- Projects are pushed toward verified channels and escrow-style contribution processes to distinguish themselves from phishers, while the same trust deficit documented in the red-flag research makes buyers discount unvetted offerings.
Third-order effects
- If the pattern holds, unregulated direct-to-consumer fundraising becomes structurally untenable without intermediated custody and verification layers — a trajectory consistent with later reporting showing hackers stealing ~$2.9B across 37 hacks in 38 weeks by early 2022, on pace with the $3.2B lost in all of 2021.
The trend: Crypto fundraising keeps scaling faster than its security and verification infrastructure, shifting value toward whoever controls trusted contribution channels.