Analysis: 2022 was the biggest year for crypto hacking to date, with $3.8B stolen, mainly from DeFi protocols and by North Korea-tied hackers like Lazarus Group
2022 was the biggest year ever for crypto hacking, with $3.8 billion stolen from cryptocurrency businesses.
Context & Ripple Effects
When Chainalysis published this analysis, the $3.8B lost in 2022 stood as the worst year on record, with DeFi protocols the main targets and TRM Labs later attributing roughly a third of all thefts to North Korea-affiliated groups like Lazarus Group. That followed a pattern already visible in CipherTrace's 2021 data, when DeFi accounted for over 60% of hack volume.
The arc since has validated both findings: after a dip to $1.8B across 282 hacks in 2023, losses climbed back through 2024 and hit $2.7B in 2025, capped by the FBI-attributed $1.5B Bybit breach — meaning the 2022 record for total theft has been broken in severity if not in aggregate, while the North Korean share has grown into a state-scale revenue stream.
First-order effects
- Cryptocurrency businesses and DeFi protocol users absorbed the direct losses, with the concentration in DeFi exposing smart-contract risk as the sector's dominant attack surface rather than exchange custodial failure.
- Lazarus Group emerged from the data as the single most prolific actor, confirming that a sanctioned nation-state had made crypto theft a primary revenue instrument.
Second-order effects
- Blockchain-analytics firms like Chainalysis and TRM Labs turned attribution into a core compliance product, as exchanges and regulators increasingly relied on their data to flag DPRK-linked flows.
- The Bybit breach three years later showed the threat migrating from DeFi code exploits toward the largest centralized venues, forcing custodial operators to treat state-grade attackers as a baseline design assumption.
Third-order effects
- North Korea's cumulative haul — reported at $6.75B by end-2025 — points toward theft becoming an institutionalized pillar of sanctions evasion, backed by dedicated units like the reported Research Center 227 and IT-worker infiltration schemes spanning 40+ countries.
- Sustained state-level extraction feeds the crypto industry's legitimacy gap, giving regulators a concrete national-security rationale for tightening oversight of bridges, DeFi protocols, and cross-chain flows.
The trend: Crypto theft is consolidating around state-sponsored actors — North Korea above all — turning blockchain analytics and attribution from forensic niche into critical financial-crime infrastructure.