“Every hack is not just theft. It’s a lesson in where we dropped our guard. And if we don’t learn, the next hit will be harder.”
— Allison Pearson, Director of Cybersecurity at Europol
August 2025 went down as one of the costliest months in crypto history. According to leading analytics firm PeckShield, the month saw 16 major hacks and exploits, with attackers stealing over $163 million. That’s a 15% increase from July ($142M) and highlights a troubling trend: fewer attacks, but far more destructive.
As the broader market grows and institutional adoption surges, hackers have focused on the weakest links: centralized exchanges, DeFi liquidity pools, and hot wallets. Particularly alarming is the rise of attacks tied to state-backed hacking groups like North Korea’s Lazarus Group.
As Hakan Unal of Cyvers noted: “We’re no longer fighting lone wolves. We’re fighting armies armed with AI and billions.”
A shocking case saw a long-term BTC holder lose assets stored for over a decade. According to Chainalysis, attackers gained access via a malicious VS Code extension called “btc-security-helper” that scanned .env and keys.txt files. Over 1,300 BTC worth $91.4M was stolen.
Turkey’s largest exchange BtcTurk suffered its second breach in 14 months. On August 18, 2025, hackers compromised a hot wallet, stealing between $48M and $54M. PeckShield linked the attack to Lazarus Group based on laundering patterns. Combined with the $54M stolen in June 2024, BtcTurk’s total losses now exceed $100M.
An unknown DeFi project on Arbitrum lost $12.7M due to a flaw in its liquidity management contract. The attacker conducted an arbitrage exploit, manipulating pool pricing under low activity conditions.
A cross-chain bridge linking Ethereum and Polygon was compromised through a flaw in its oracle system. By falsifying network state data, attackers withdrew $8.2M in USDC. Once again, bridges proved to be a major weak point.
PeckShield’s mid-year report reveals: attack numbers are down, but average damage per incident is climbing fast.
| Metric | H1 2024 | H1 2025 |
|---|---|---|
| Avg. loss per incident | $3.1M | $7.18M |
| Total losses | $1.65B | $3.1B |
| Share of key-leak attacks | 62% | 78% |
| Share of social engineering | 15% | 23% |
PeckShield forecasts that if this trend continues, 2025 losses could exceed $4B.
78% of losses stemmed from key leaks (hot wallet compromises, malicious extensions). Hackers increasingly target developers and admins, not protocols.
23% of attacks involved phishing, fake dashboards, or SMS hijacks. LinkedIn and Telegram were prime targets.
Manipulating trusted oracles and bridges let hackers spoof prices and network states, tricking smart contracts.
Logic flaws in governance, synths, or share-calculations remain a key exploit vector.
As ZachXBT said: “The weakest element isn’t the code — it’s the human behind it.”
Lazarus remains the most active, stealing $620M+ in 2025. Proceeds fund nuclear programs, per UNODC.
Groups from these regions drive phishing and Drainer-as-a-Service schemes (e.g., Vanilla Drainer).
Darknet-coordinated crews launder funds via Tornado Cash and high-risk exchanges.
As Charles Guillemet of Ledger said: “The best insurance is solid defense.”
As Vitalik Buterin said: “Security isn’t a checklist item. It’s culture.”
As crypto grows, it remains a prime target. Each hack is not panic fuel, but a call to action. In a world where one click can cost millions, vigilance is the only safe wallet.
