/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

In H1 2025, hackers stole $2.17B+ from crypto services, including the DPRK's record $1.5B Bybit hack, surpassing all of 2024 and up 17% on H1 2022

Key findings  —  Stolen funds  — With over $2.17 billion stolen from cryptocurrency services so far in 2025, this year is more devastating than the entirety of 2024.

Chainalysis

Context & Ripple Effects

Crypto theft had already risen to $2.2B across 303 hacks in 2024, after 2022 set an earlier $3.8B high-water mark dominated by DeFi losses and North Korea-linked activity. H1 2025’s reported losses put the market back near an annual-scale loss level within six months.

The Bybit breach concentrates much of the period’s damage in a single DPRK-attributed incident, while later coverage points to a record annual haul by North Korean hackers in 2025. That concentration matters as much as the aggregate total: a small number of attacks can reshape annual risk metrics.

First-order effects

  • Bybit absorbs the immediate consequences of the record $1.5B theft, while the reported H1 total raises the loss exposure facing crypto-service operators and their users.
  • DPRK-linked activity becomes the central driver of the period’s headline risk, rather than a diffuse rise in small-scale incidents.

Second-order effects

  • Exchanges, custodians and DeFi services face stronger pressure to review wallet controls, key-management practices and incident-response arrangements after one breach accounts for a large share of reported losses.
  • A concentrated mega-hack can make customers, counterparties and risk providers judge crypto platforms more by operational security than by market activity or product breadth.

Third-order effects

  • If losses remain concentrated in state-linked actors and major platforms, crypto security may increasingly become a market-structure issue: firms with stronger custody and controls gain trust, while weaker operators face a widening crypto-hacking risk legacy.
  • The pattern reinforces the crypto legitimacy gap: repeated large thefts can keep security, compliance and resilience central to how the sector is assessed, even when overall usage grows.

The trend: Crypto hacking is shifting toward a high-consequence security challenge in which state-linked groups and a few large breaches can determine the industry’s annual loss profile.

Discussion

  • @chainalysis @chainalysis on x
    3/ Geographic Spread: - US, Germany, Russia, Canada, Japan: Highest victim concentrations - Eastern Europe, MENA, CSAO: most rapid H1 2024 to H1 2025 growth in victim totals [image]
  • @chainalysis @chainalysis on x
    4/ Laundering Patterns: - Service hackers show more sophistication than personal wallet attackers - Criminals paying premium fees to move stolen funds (up to 14.5x in 2025) - More stolen funds staying on-chain longer, creating seizure opportunities [image]
  • @chainalysis @chainalysis on x
    1/ 2025 is shaping up to be one of the worst years for crypto crime. Over $2.17B stolen so far, with the DPRK's record $1.5B ByBit hack leading the charge. Let's break down the key trends from our mid-year crime report: https://www.chainalysis.com/ ...