Research: hackers have stolen ~$2.9B worth of crypto across 37 hacks in 38 weeks since August, which is almost on par with the $3.2B stolen in all of 2021
Paul Vigna / Wall Street Journal :
Context & Ripple Effects
2021 was already a record year for crypto theft — more than 20 hacks of at least $10M each, six of them over $100M — so the striking part of this report is the pace: roughly $2.9B taken in just 38 weeks since August puts 2022 nearly level with the full prior year's $3.2B.
The trajectory held after this report: theft climbed to $2.2B across 303 hacks in 2024 and an estimated $2.7B in 2025, when a single $1.4B breach at Bybit became the largest on record — making this April 2022 data point an early reading on an escalation that has not reversed.
First-order effects
- Exchanges and DeFi projects are absorbing losses at a run rate that nearly matches a full record year within eight months, with the 37 hacks since August hitting both centralized platforms and on-chain protocols.
- Users and depositors bear the direct losses, and each large breach converts directly into withdrawal pressure and reputational damage for the hacked platform.
Second-order effects
- Security spending, audits, and insurance become competitive necessities for exchanges and projects, since TRM's later finding that five large attacks accounted for 70% of all crypto stolen in H1 2024 shows a handful of breaches can dominate the loss totals — and the targets that avoid them win trust share.
- Concentration in a few mega-hacks pushes custodians and exchanges toward structural defenses — multi-party custody and tighter key management — rather than incremental patching.
Third-order effects
- If theft keeps scaling from hundreds of millions to multi-billion annual totals, the security record becomes the binding constraint on institutional adoption and a standing argument for regulators to treat crypto platforms like systemically important financial infrastructure — feeding what analysts call the crypto legitimacy gap.
- The industry splits structurally between platforms that can absorb or prevent nine-figure breaches and those that cannot, accelerating consolidation around the largest, best-defended custodians.
The trend: Crypto theft is scaling from episodic incidents to an industrial, multi-billion-dollar annual category concentrated in a few mega-breaches, and that security record now shapes the industry's regulatory and adoption path.