Hacks in August 2025: $163M Drained from Crypto Protocols — Up 15%

“Every hack is not just theft. It’s a lesson in where we dropped our guard. And if we don’t learn, the next hit will be harder.”
— Allison Pearson, Director of Cybersecurity at Europol

August 2025 went down as one of the costliest months in crypto history. According to leading analytics firm PeckShield, the month saw 16 major hacks and exploits, with attackers stealing over $163 million. That’s a 15% increase from July ($142M) and highlights a troubling trend: fewer attacks, but far more destructive.

As the broader market grows and institutional adoption surges, hackers have focused on the weakest links: centralized exchanges, DeFi liquidity pools, and hot wallets. Particularly alarming is the rise of attacks tied to state-backed hacking groups like North Korea’s Lazarus Group.

As Hakan Unal of Cyvers noted: “We’re no longer fighting lone wolves. We’re fighting armies armed with AI and billions.”

💥 Biggest August Hacks: $163M in 16 Attacks

🪙 $91.4M Theft from a Long-Term Bitcoin Holder

A shocking case saw a long-term BTC holder lose assets stored for over a decade. According to Chainalysis, attackers gained access via a malicious VS Code extension called “btc-security-helper” that scanned .env and keys.txt files. Over 1,300 BTC worth $91.4M was stolen.

🏦 BtcTurk Breach: $48–54M Lost

Turkey’s largest exchange BtcTurk suffered its second breach in 14 months. On August 18, 2025, hackers compromised a hot wallet, stealing between $48M and $54M. PeckShield linked the attack to Lazarus Group based on laundering patterns. Combined with the $54M stolen in June 2024, BtcTurk’s total losses now exceed $100M.

🧩 DeFi Exploit on Arbitrum: $12.7M

An unknown DeFi project on Arbitrum lost $12.7M due to a flaw in its liquidity management contract. The attacker conducted an arbitrage exploit, manipulating pool pricing under low activity conditions.

🔗 Bridge Attack: $8.2M

A cross-chain bridge linking Ethereum and Polygon was compromised through a flaw in its oracle system. By falsifying network state data, attackers withdrew $8.2M in USDC. Once again, bridges proved to be a major weak point.

📊 PeckShield Analytics: Why Attacks Are More Destructive

PeckShield’s mid-year report reveals: attack numbers are down, but average damage per incident is climbing fast.

Metric H1 2024 H1 2025
Avg. loss per incident $3.1M $7.18M
Total losses $1.65B $3.1B
Share of key-leak attacks 62% 78%
Share of social engineering 15% 23%

PeckShield forecasts that if this trend continues, 2025 losses could exceed $4B.

🔍 Attack Vectors: How Hackers Bypass Defenses

🔑 Key Theft

78% of losses stemmed from key leaks (hot wallet compromises, malicious extensions). Hackers increasingly target developers and admins, not protocols.

🤖 Social Engineering

23% of attacks involved phishing, fake dashboards, or SMS hijacks. LinkedIn and Telegram were prime targets.

🌐 Oracle & Bridge Exploits

Manipulating trusted oracles and bridges let hackers spoof prices and network states, tricking smart contracts.

🧩 Smart Contract Bugs

Logic flaws in governance, synths, or share-calculations remain a key exploit vector.

As ZachXBT said: “The weakest element isn’t the code — it’s the human behind it.”

🌐 Geography & Actors

🇰🇵 North Korea’s Lazarus Group

Lazarus remains the most active, stealing $620M+ in 2025. Proceeds fund nuclear programs, per UNODC.

🇷🇺 Russia & 🇨🇳 China

Groups from these regions drive phishing and Drainer-as-a-Service schemes (e.g., Vanilla Drainer).

🌍 Global Anonymous Networks

Darknet-coordinated crews launder funds via Tornado Cash and high-risk exchanges.

🛡️ Defense Measures

🔧 For Projects

  • Multi-party audits — use firms like CertiK, OpenZeppelin, Zellic.
  • Multi-sig approvals for critical actions.
  • Bug bounties to incentivize white-hats.
  • Developer isolation — VMs, no keys on personal devices.
  • AI monitoring for real-time anomaly detection.

🔐 For Users

  • Hardware wallets for large holdings.
  • Never enter seed phrases in a browser.
  • Vet extensions before installing.
  • Enable 2FA with apps or hardware keys.
  • Leverage on-chain analytics — tools like Nansen, Arkham.

💸 Can Stolen Funds Be Recovered?

  • Recovery rate — only 7–8% of stolen assets return in 2025.
  • CEX freezes possible when hackers cash out.
  • Recovery firms track flows for legal recourse.
  • Insurance (Nexus Mutual, InsurAce) offers partial coverage.

As Charles Guillemet of Ledger said: “The best insurance is solid defense.”

✅ Conclusions: Security Is Continuous

  • Hackers are professionalizing, leveraging state backing.
  • Main targets: CEXes and weak DeFi protocols.
  • Key leaks and social engineering dominate.
  • Total 2025 damages may top $4B.
  • Prevention beats recovery.

As Vitalik Buterin said: “Security isn’t a checklist item. It’s culture.”

As crypto grows, it remains a prime target. Each hack is not panic fuel, but a call to action. In a world where one click can cost millions, vigilance is the only safe wallet.

01.09.2025, 07:00