BTC $62,955 -0.04%ETH $1,879 +0.00%XRP $0.99946 -0.25%SOL $75.20 -0.02%DOGE $0.06971 -0.35%USDT USDC BTC $62,955 -0.04%ETH $1,879 +0.00%XRP $0.99946 -0.25%SOL $75.20 -0.02%DOGE $0.06971 -0.35%USDT USDC
24 mins read 1d ago

Crypto Hacks: Wallets, Bridges, and Who Steals at Scale

A crypto hack is usually unauthorized control of keys, signing screens, admins, bridges, or supply-chain updates, not “the blockchain got hacked.” Stolen funds and exploit mechanics differ from insolvency, rugs, and retail scam traps. The durable lesson runs from Bitfinex and Ronin through Bybit and Coldcard: the chain executes whatever authorized control tells it to […]

Crypto wallet drain and bridge exploit security warning graphic
Crypto Hacks: Wallets, Bridges, and Who Steals at Scale Source: Live Bitcoin News
Advertisement

A crypto hack is usually unauthorized control of keys, signing screens, admins, bridges, or supply-chain updates, not “the blockchain got hacked.” Stolen funds and exploit mechanics differ from insolvency, rugs, and retail scam traps. The durable lesson runs from Bitfinex and Ronin through Bybit and Coldcard: the chain executes whatever authorized control tells it to do.

Bitcoin was built so strangers could settle value without banks. Crypto hacks proved you could steal that value without breaking the chain: compromise the keys, the signing screen, the admin, or the bridge verifier, and the blockchain will execute the theft with perfect loyalty.

A cold wallet signs what looks like a routine transfer and a billion dollars leave an exchange. A DeFi admin council approves a message after months of friendly chats, then watches the rules rewrite themselves. A bridge reports “zero bugs found” while hundreds of millions walk out because the off-chain verifier saw a fake world. A hardware wallet that was supposed to be the last fortress ships seeds from weak randomness, and attackers sweep addresses like empty rooms. Retail extension updates drain balances before breakfast. Somewhere in the same news cycle, people still say “the blockchain got hacked,” which is usually the least accurate sentence in the story.

That is the strange thing about crypto hack culture. The ledger keeps producing receipts. The panic words stay the same: drained, got rekt, hot wallet fear, Lazarus talk, bridge-hack lore. The technology was revolutionary. The culture kept trusting whoever controlled the next layer above consensus.

This is the dark evolution of crypto theft through technical compromise: not one bug class, not one villain, but an attack surface that moved up the stack from custody to code to bridges to humans who authorize money. People still search the durable names (the Bitfinex heist, the Ronin hack, the Wormhole exploit) because those cases teach the machines. What follows is the exploit map: wallets, bridges, protocols, and who steals at scale.

Opening the Feed: Bybit, Drift, KelpDAO, and Coldcard

Start in 2025 and 2026, because the year-defining losses no longer look like classic “find a reentrancy and leave.”

On February 21, 2025, Bybit lost roughly $1.46 to $1.5 billion from one Ethereum cold wallet. The FBI attributed the theft to North Korea. Bybit’s own incident timeline describes a routine cold-to-warm transfer in which the signing interface was spoofed, allowing authorized signers to approve a malicious change. Valid signatures. Wrong intent. The chain did its job.

Industry research firm Chainalysis estimated that more than $3.4 billion was stolen through crypto hacks in 2025, with Bybit alone accounting for nearly $1.5 billion and DPRK-linked actors nearly $2.02 billion for the year (Chainalysis 2025 theft overview). One heist can define a year.

Then 2026 refused to quiet down. TRM Labs’ H1 2026 dataset recorded 207 hacks and exploits totaling about $972 million. Smart-contract exploits were the majority of incidents (125), yet infrastructure and operational compromises were only about 15% of incidents while causing roughly 76% of the value stolen (TRM H1 2026).

Name the landmarks:

Drift Protocol on Solana lost about $285 million on April 1, 2026, after privileged signing workflows and admin control were compromised (Chainalysis on Drift).

KelpDAO lost about $292 million in rsETH on April 18, 2026; OpenZeppelin summarized it as “$292 Million Lost, Zero Bugs Found” because the core contracts were not the primary failure (OpenZeppelin KelpDAO lesson).

On July 30, 2026, Coinkite disclosed a Coldcard seed-generation weakness from a 2021 firmware path that used weak randomness (Coinkite advisory);

TRM’s preliminary sweep tally by early August sat near $116 million across thousands of addresses (TRM Coldcard analysis).

Why are the largest crypto hacks increasingly not smart-contract hacks at all? Because attackers learned to steal authority: the private key, the signing context, the admin role, the bridge verifier, the dependency, sometimes the entropy that creates the key.

Key Takeaway: Count incidents if you want frequency. Count control-plane failures if you want the year’s money.

The Pattern Map: Failure Modes Before the Timeline

Before the eras, name the machines. A crypto hack is not one genre. It is a set of ways to seize control of value.

Pattern What breaks What the chain sees Landmark shape
Custody/hot wallet Exchange keys, APIs, online wallets Valid withdrawals Bitfinex, KuCoin
Signing-interface compromise What humans approve Valid signatures on bad intent Bybit 2025
Admin/privilege capture Roles that rewrite rules Protocol acting “as designed” under new owners Drift 2026
Bridge verification failure Cross-chain truth Fake mint/release accepted Wormhole, Ronin, KelpDAO
Smart-contract bug Application logic Unintended state transitions The DAO, Euler
Economic/governance exploit Oracles, votes, liquidity assumptions Functions used against design intent Beanstalk, oracle games
Supply-chain/dependency Shared packages, vendors Users sign drains through trusted UI Ledger Connect Kit
Seed/entropy failure Randomness behind keys Correct crypto on guessable keys Coldcard 2026

Search culture collapses this map into two slogans: “smart contract bug” and “Lazarus did it.” Both appear in the history. Neither is the whole stack.

Key Takeaway: Learn the failure modes first. Then the timeline reads like logistics, not random chaos.

What Counts as a Crypto Hack, Exploit, Heist, or Economic Exploit

A crypto hack, in plain language, is unauthorized compromise of systems, credentials, infrastructure, or accounts that lets someone move crypto out of its intended control.

An exploit is narrower: the attacker uses a vulnerability or unexpected system behavior to extract value. The DAO’s recursive-call drain is the textbook case (Ethereum Foundation DAO update).

An economic exploit uses valid protocol functions while manipulating the assumptions those functions rely on: oracles, thin liquidity, governance capture and flash-loan amplification. The legal line can be messier than pure key theft. The security lesson is still clear: assumptions are part of the attack surface.

A heist is the editorial word for large asset theft regardless of method. Bybit was a heist via signing/control-plane compromise. KelpDAO was a heist via cross-chain verification infrastructure. Coldcard-related sweeps were wallet heists enabled by weakened seed entropy.

Label Core idea Not the same as
Hack Unauthorized system/credential compromise Market crash
Exploit Vulnerability or unexpected behavior used for value Designed-in fraud
Economic exploit Valid functions + broken assumptions Always “illegal by default” (nuance exists)
Heist Large theft event (cultural stamp) One technical root cause
Private-key/wallet compromise Control of signing material or seed Protocol insolvency
Bridge exploit Cross-chain verification fails A rug by the team
Smart-contract exploit On-chain app logic fails Consensus failure

What a crypto hack is not:

  • A platform collapse is insolvency, frozen withdrawals, or founder failure without a clean “attacker stole control” story. Mt. Gox appears here only as an early theft milestone; the platform collapse afterlife is a different mechanism.
  • A rug pull or Ponzi is fraud designed into the product from the start, the yield-machine and exit pattern rather than a stolen key.
  • Broader crypto scams literacy, including fake “recovery expert” pitches after a theft, is covered there. Nothing here sells recovery.

Takeaway: Name the incident type before you treat one headline as a warning about the whole industry.

The Attack Stack in 2026

Early crypto security arguments obsessed over hash functions and consensus. Useful. Incomplete. By 2026, the money sits behind a taller stack:

  1. Cryptographic keys (private keys, seeds, entropy, hardware modules)
  2. Wallet architecture (hot/cold, multisig, MPC, policies)
  3. Human signing (display, blind signing, approval workflow)
  4. Application logic (contracts, access control, accounting)
  5. Economic assumptions (oracles, collateral, liquidity)
  6. Cross-chain verification (validators, proofs, RPC, DVNs)
  7. Software supply chain (packages, SDKs, build systems)
  8. Organization (employees, vendors, identities, admin councils)

The strongest modern line is blunt: the blockchain often works exactly as designed; the attacker steals the authority to tell it what to do.

Who Steals at Scale: Six Actor Types

Scale is not the same as cleverness. Scale is the ability to unlock concentrated custody, admin power, or shared dependencies and then keep operating.

1. Nation-state teams

DPRK-linked actors tracked publicly as Lazarus / APT38 / TraderTraitor show the multi-stage model: long reconnaissance, fake recruitment, malware, vendor compromise, privileged access, transaction manipulation. The FBI attributed Ronin’s bridge theft and Harmony’s Horizon theft to Lazarus-linked actors (FBI Ronin attribution; FBI Harmony attribution), named TraderTraitor in the DMM Bitcoin case (FBI/NPA DMM), and attributed Bybit to North Korea. Tradecraft stays here. Once coins leave, the dark-web cash-out and sanctions rails become the next fight.

2. Professional independent hackers

The Bitfinex heist proved a sophisticated non-state attacker can still move exchange-scale Bitcoin. Nation-state is not required for catastrophe.

3. Opportunistic smart-contract exploiters

They watch new deployments, upgrades, obscure functions, and weak integrations. Many incidents; usually smaller checks than one exchange treasury.

4. Copycat exploiters

Nomad’s 2022 bridge failure became a template once the first successful transaction was public. Immunefi called it a “crowdsourced” hack (Immunefi Nomad analysis). Transparency helps defenders and, for a window, helps imitators.

5. Economic manipulators

They attack price, liquidity, collateral, and governance assumptions rather than “break” a line of code. Beanstalk’s governance path is the cultural landmark for “vote your way into the vault.”

6. Supply-chain attackers

They poison packages, vendor sessions, or shared SDKs so many apps inherit one compromise. The Ledger Connect Kit in 2023 is the clean retail-facing example (per the Ledger security incident report).

Why did it matter? “Who steals at scale?” is an operational question. Teams that can live inside trust relationships for months beat teams that only grep for reentrancy.

Custody Becomes the Vault (2011–2015)

“Who Holds the Keys?”

Era Focus: Early users treated exchange custody as if blockchain security extended to the company. It did not.

Mt. Gox-era thefts taught the first industrial lesson. U.S. prosecutors later alleged attackers gained access beginning in 2011 and stole roughly 647,000 BTC over the following years (DOJ Mt. Gox-related charging). Treat that figure as an early custody-theft milestone. The insolvency and creditor saga is a different article: crypto collapses.

Why did it matter? Crypto became valuable enough to steal at exchange scale. The first security question was custody, and it never left.

Code Becomes the Vault (2016–2017)

“The Contract Can Execute the Disaster Faithfully”

Era Focus: Smart contracts and contract wallets join exchange networks as attack surfaces.

The DAO (2016)

On June 17, 2016, the Ethereum Foundation warned that the DAO was being drained through a recursive-calling vulnerability. The issue lived in the DAO contract, not in Ethereum consensus (EF critical update). The later hard fork response (the EF hard fork, completed) split the culture: recovery power versus immutability. Two security questions arrived together: can the theft happen, and what power exists afterward?

Bitfinex (2016)

Attackers stole 119,754 BTC from Bitfinex through exchange infrastructure compromise. Later DOJ cases made the heist a permanent search landmark (DOJ Bitfinex sentencing). Hot wallet fear became industry language.

Parity (2017)

Parity’s multisig wallet incidents showed that the wallet itself can be a smart contract with upgrade and library risks (OpenZeppelin on Parity). Custody logic moved on-chain and brought new failure modes with it.

Why did it matter? “Code is law” stopped sounding like a slogan and started sounding like an incident report.

Hot Wallets, APIs, and Traditional Cyber at Crypto Scale (2018–2020)

“Steal the Session, Steal the Coins”

Era Focus: Centralized platforms learned that phishing, API keys, 2FA fatigue, and hot-wallet design were the same cybersecurity problems banks already knew, only with irreversible settlement.

Binance’s 2019 breach and KuCoin’s 2020 private-key incident stamped the pattern: if the hot wallet can move funds fast for customers, it can move funds fast for an attacker. KuCoin’s public updates described APT-style compromise of hot-wallet keys (KuCoin CEO updates).

Why did it matter? Crypto security stopped being a niche of cryptography papers and became SOC work with a public mempool.

DeFi Composability and Flash-Loan Amplifiers (2020–2021)

“The Bug Was Small; the Liquidity Was Not”

Era Focus: Permissionless composition created economic attack paths that did not always look like “stolen private key.”

Flash loans often amplify a weakness; they are not always the root bug. Oracle assumptions, collateral factors, and obscure accounting paths became lootable. The industry learnt a vocabulary: got rekt, drained, oracle game. Many of these incidents stay smaller than bridge years, yet they teach the difference between a coding error and an economic design error.

Why did it matter? Auditing source files was no longer enough if the market assumptions were the real vault door.

Bridges Become Billion-Dollar Targets (2022)

“Cross-Chain Truth Is a Security Architecture”

Era Focus: Bridges lock value on one chain and mint or release on another. That verification path became 2022’s industrial honeypot. Chainalysis tallied about $2 billion across bridge incidents that year (Chainalysis bridge hacks 2022).

Five failure models still map the era:

Model Failure Landmark
A. Validator/key compromise Quorum keys stolen Ronin (~173,600 ETH + 25.5M USDC)
B. Signature-verification bug Forged authenticated message Wormhole (~120,000 whETH, >$320M then)
C. Validation/configuration failure Invalid messages treated as valid Nomad (~$190M; copycat wave)
D. Proof-verification bug Forged low-level proof BNB Token Hub (attacker minted ~$570M scale; ~$100M off-chain before pause)
E. Off-chain observation compromise Verifier sees false source-chain world KelpDAO 2026 (preview of the next bridge era)

Wormhole

February 2022: signature-verification failure let the attacker forge a message the bridge trusted (Chainalysis Wormhole). Cross-chain messages are only as strong as authentication.

Ronin

March 2022: enough validator keys compromised to authorize fake withdrawals. The FBI later attributed the attack to Lazarus-linked actors. Multisig count is not independence.

Nomad

August 2022: a bad update made invalid messages acceptable; once demonstrated on-chain, others copied it.

Harmony Horizon and BNB Token Hub

Harmony’s ~$100M Horizon theft reinforced key compromise outside the contract (FBI Harmony). BNB Token Hub showed a bridge can create assets that should never have been minted (BNB Chain updates).

Beanstalk’s governance exploit the same year proved voting mechanisms can become the vault door without a classic reentrancy headline.

Why did it matter? Interoperability became the heist layer. Bridge-hack lore entered permanent search memory.

Supply Chain, Employee Trust, and Custody Interfaces (2023–2024)

“Attack the Dependency and the Workflow”

Era Focus: Attackers shifted toward packages, vendors, employees, and multisig UIs.

Euler’s 2023 exploit showed one missing safety check in complex DeFi logic can still cost on the order of $197–$240 million depending on how you frame gross versus recovered narratives (Euler retrospective). “Audited” never meant “done.”

Ledger Connect Kit (December 14, 2023) showed supply-chain leverage: a compromised NPM publishing path shipped malicious package versions; DApps loading them could present drain transactions. Hardware and Ledger Live were not the compromised layer (Ledger incident report). One dependency, many apps.

DMM Bitcoin (2024) showed the employee/vendor path: fake recruitment into session and transaction manipulation, later attributed by FBI and Japan’s NPA to TraderTraitor (FBI/NPA). WazirX’s July 2024 cyberattack kept multisig and custody-interface risk in the retail news cycle (WazirX update).

Why did it matter? The code you did not write, and the human you did trust, became primary targets.

Blind Signing, Admin Capture, and Weak Entropy (2025–2026)

“A Perfect Signature Can Authorize the Wrong Transaction”

Era Focus: Control-plane compromise at institutional scale, plus self-custody entropy failure.

Bybit reframed cold storage. Cold keys offline are not the whole lifecycle. Transaction construction, display, browser, vendor UI, signing coordinator, and multisig logic all sit in the path. Blind signing (approving opaque hashes or misleading UI) became a systemic problem. The Ethereum Foundation’s 2026 Clear Signing initiative named human-readable intent as a structural fix after major signing failures including Bybit (EF Clear Signing).

Drift showed admin keys are economic keys: once privilege is captured, collateral lists and protocol settings can be rewritten. KelpDAO showed Model E bridges: contracts can be “correct” even while RPC/verifier observation is poisoned, and a 1-of-1 verifier configuration concentrates trust (Chainalysis KelpDAO). Coldcard showed self-custody moves risk; it does not delete the security stack. Weak seed generation can leave cryptography mathematically tidy and keys practically guessable (Coinkite entropy background).

Why did it matter? The modern question is larger than “can someone steal the key?” It is “who or what can convince the system that a theft is authorized?”

Depth: How Wallets Actually Get Hacked

Hot wallets stay online for speed. They are operational necessities for exchanges and some protocols. They are also high-value targets. If a hot wallet can move customer funds in seconds, an attacker with the same keys can do the same.

Cold wallets keep keys offline. They reduce remote key extraction risk. They do not automatically secure the signing ceremony. Bybit proved a cold multisig can authorize disaster if the display lies. Coldcard proved a hardware device can generate a weak seed if entropy fails. The useful mental model is a full lifecycle: construct, display, interpret, approve, collect threshold signatures, execute. Attackers only need the weakest trusted step.

Seed phrases are master secrets. Phishing, malicious overlays, and compromised backups still drain retail users without any DeFi cleverness. Browser-extension and update-path incidents sit in the same family: the user thinks they are using a trusted wallet surface, then signs a drain.

Blind signing is the cultural villain of 2025: cryptography proves who signed; it does not prove the human understood. Clear signing and transaction simulation exist because opaque hashes and misleading UI text keep winning against tired operators.

Multisig Independence Beats the Threshold Number

Ronin, Bybit, and WazirX-era custody fights keep teaching the same lesson in different clothes. A 5-of-9 wallet sounds stronger than a 2-of-3 wallet until you ask harder questions:

  • Are the keys on independent devices?
  • Are they held by independent people and organizations?
  • Do signers share one cloud identity provider or one vendor UI?
  • Can one compromised laptop trick several signers?
  • Is there a delay, a second policy engine, or out-of-band confirmation before large moves?

Five signatures produced through one compromised workflow are not five independent layers of security. Quorum math without independence is theater.

Depth: Bridges After 2022

A bridge is not “a smart contract.” It is a security architecture: lock/mint/burn/release plus verification of foreign-chain events. Large, locked pools, complex code, off-chain infrastructure, and concentrated-trust assumptions explain outsized losses. Wormhole, Ronin, Nomad, and BNB Token Hub remain search landmarks because they teach Models A–D. KelpDAO updates the syllabus with Model E.

Emergency pauses and validator coordination can limit damage (BNB Chain’s response is the textbook trade-off: safety versus decentralization theater). They do not rewrite the lesson. If one verifier or one UI sits in front of a fortune, attackers will study that door.

Depth: Smart-Contract Exploits Beyond Reentrancy

Reentrancy made The DAO famous. It is not the only genre, and treating every crypto exploit as “another DAO” hides the modern map.

  • Accounting bugs mis-track balances, shares, or internal debt.
  • Access control leaves privileged functions open or upgradeable by the wrong party.
  • Oracle and economic paths treat prices, liquidity, or collateral factors as truth.
  • Governance turns votes into admin keys (Beanstalk’s 2022 path remains the cultural landmark).
  • Flash loans amplify thin-market assumptions; they are often amplifiers, not the root bug.
  • Missing safety checks in complex lending logic still matter; Euler’s 2023 incident showed one gap can move nine figures even after audits and bounties.

When headlines say “protocol exploit,” ask which assumption broke: state ordering, privilege, price, vote weight, or integration. Code can execute exactly as written and still produce a catastrophic economic outcome. That is why “the blockchain was hacked” is usually wrong: consensus may be fine while the application layer burns.

Soft Locks: Wallet Drains, Quarterly Tallies, Nation-State Concentration

Wallet and Extension Incidents Drain Users Fast

Non-custodial wallet and extension paths can empty balances quickly after a malicious update or supply-chain style failure. Operator confirmation and compensation promises are incident-response facts; they do not replace update hygiene. Named wallet incidents are why wallet-hack queries land in this story. CZ’s public confirmation that a Trust Wallet hack left about $7 million stolen, with users to be compensated, is the retail-facing shape of the pattern: browser-extension and update-path risk, then a compensation statement that is not the same thing as prevention. Retail wallet UX is itself an attack surface, not just a convenience layer.

Quarterly Hack Tallies Show Social Engineering Beside Code Exploits

Industry loss reports show many incidents per quarter and that social-engineering drains can sit beside (and sometimes outpace) pure smart-contract bugs in the same climate reading. Net loss after partial recoveries is the useful number. Use tallies for threat climate, not for predicting the next bridge name. One labeled industry snapshot: crypto security fails with about $620 million lost in Q2 hacks. Keep firm labels attached. Do not merge Chainalysis and TRM totals into one fake dataset.

Nation-State Actors Concentrate Stolen-Value Totals

Attributed groups such as Lazarus can dominate yearly stolen value even when attack counts fall. Chainalysis-linked industry framing of a record ~$2 billion North Korea crypto theft year inside a ~$3.4 billion stolen total is the concentration story in headline form. Smaller attribution beats still matter for tradecraft literacy, including coverage where Lazarus Group is tied to a $3.2 million crypto hack in reporting citing zachxbt. Attribution stays with heist coverage; deeper crime-network and cash-out framing links to dark web crypto crime.

TRM’s H1 2026 cut attributed roughly $643 million (about 66% of H1 hack losses) to North Korea-linked activity, largely via Drift and KelpDAO shapes (TRM H1 2026). Different techniques. Same operational idea: attack whatever layer controls the money.

Why Most Hacks Are Small but a Few Define the Year

Crypto theft follows a fat-tail distribution. Many small exploits. A few catastrophic control-plane failures set the year’s total. Chainalysis’s 2025 view put the top three service hacks near 69% of service-related stolen value, with Bybit alone near half the year’s emotional memory (Chainalysis). TRM’s H1 2026 split (many code incidents, most dollars in infrastructure/ops) rhymes.

Personal wallet compromises also rose as a share of stolen value in industry research across 2022–2024, even as institutional targets stayed enormous. Attackers hunt both concentrated vaults and dispersed retail keys.

What Security Has Learned (Without the Fantasy of Finished Safety)

  • Key management still matters; entropy matters too.
  • Signer independence beats decorative multisig counts.
  • Clear signing and simulation beat blind approval.
  • Timelocks and circuit breakers buy response time.
  • Cross-chain invariants must include off-chain verifiers and RPC health.
  • Dependency security is product security.
  • Runtime monitoring beats “we audited last year.”
  • Admin privilege should be treated like treasury custody.
  • Defense in depth assumes one trusted UI will lie someday.

Audits are necessary and not sufficient. Ask what changed after the audit, and what exists outside the audited files. Invariants (“what must never become true?”) beat bug tourism.

On-chain visibility can aid freezes and investigations. It does not make an exploit harmless, nor is it a recovery product pitch.

Stolen Control Is Not Insolvency or Designed Fraud

Stolen control is a different failure mode from insolvency and from fraud designed into a product. A venue can get drained and still pay customers, or freeze withdrawals with no classic external heist. A rug can look like a crash and still be an insider exit. Keep the mechanism straight before you inherit the wrong moral.

FAQ

What is a crypto hack?

A crypto hack is unauthorized compromise of systems, credentials, wallets, bridges, or privileged roles that lets an attacker move crypto out of its intended control. The label covers different machines: protocol exploits, bridge heists, wallet drains, and exchange hot-wallet theft. It is not a market crash, a rug, or an insolvency story by default.

What was the Trust Wallet hack?

Public reporting described a Trust Wallet incident with roughly $7 million stolen and a compensation promise from the operator side. It is a retail wallet/extension-path case: update and software-distribution risk, not a lesson about Bitcoin consensus. Compensation talk is response, not hygiene.

What was the Ronin hack?

In March 2022, attackers drained large ETH and USDC balances from the Ronin Bridge after compromising enough validator keys to meet the withdrawal quorum. The FBI later attributed the attack to Lazarus-linked actors. It remains the landmark for bridge validator compromise.

What was the Wormhole exploit?

In February 2022, Wormhole lost on the order of 120,000 wrapped ETH (more than $320 million at the time) after a signature-verification vulnerability allowed a forged message. It is the landmark for Model B bridge failure: authentication logic, not stolen validator laptops.

What was the Bitfinex heist?

In 2016, attackers stole 119,754 BTC from Bitfinex through exchange infrastructure compromise. Later U.S. prosecutions made it a durable search landmark for hot-wallet and custody failure at exchange scale.

Who is the Lazarus Group in crypto hacks?

Lazarus is the public name often used for DPRK-linked cyber actors attributed by U.S. authorities to major thefts including Ronin and Harmony, with North Korea also attributed in the Bybit case. Treat those attributions as attacker-model evidence. When the question shifts to mixers, mules, and sanctioned cash-out networks, you are in dark web crypto crime territory.

Are hacks the same as rug pulls?

No. A hack/exploit involves unauthorized compromise or unexpected system behavior. A rug pull is generally insider or project-exit fraud designed into the venture. Different intent, different failure mode.

Are hacks the same as exchange collapses?

No. A platform can suffer a hack and remain solvent, or collapse without a classic external heist. Insolvency and creditor fights are a different mechanism from stolen keys.

Where do stolen coins go after a hack?

After control is stolen, funds often move through swaps, hops, mixers, brokers, and cash-out venues. For network and laundering depth, see dark web crypto crime. The heist itself is still a question of how control was stolen.

Why did Bybit matter so much?

Because it showed institutional cold-wallet signing can be defeated without extracting every key: manipulate what authorized people believe they are signing, collect valid signatures, and let the chain execute.

Is self-custody immune to hacks?

No. Self-custody removes a custodian and adds responsibility for seeds, firmware, entropy, backups, and signing hygiene. Coldcard’s 2026 disclosure is the hard reminder.

Do audits prevent crypto hacks?

Audits reduce risk. They do not prove absence of exploit paths, especially after upgrades, in configurations, in admin keys, or in off-chain verifiers the audit never saw. Ask what changed after the audit, and what sits outside the files that were reviewed.

How should readers read “crypto hacked” headlines?

Start by naming the machine: wallet drain, bridge verification failure, hot-wallet theft, admin capture, or economic exploit. Then separate attribution claims from mechanism. Then separate insolvency and scam-recovery pitches from the heist itself, instead of treating every loss as the same failure.

Key Takeaways

  • A crypto hack covers protocol exploits, bridge heists, wallet drains, and exchange hot-wallet theft; the machines differ even when the headline uses one word.
  • The largest modern heists often steal authority (signing UI, admin, verifier, dependency, entropy), not “the blockchain.”
  • Wallet and browser extension incidents can drain retail users quickly; compensation promises do not replace update hygiene.
  • Quarterly loss tallies show social engineering beside code exploits; label industry research firms and avoid merged fake totals.
  • Attributed nation-state actors can concentrate a majority of a year’s stolen value even when incident counts look democratic.
  • Named landmarks (Bitfinex, Ronin, Wormhole, Bybit, KelpDAO, Drift, Coldcard) are memory anchors for failure modes, not trivia.
  • Hacks are a different failure mode from collapses and rug pulls; route those beats to their own pages.
  • Multisig strength is independence of signers and workflows, not the marketing threshold alone.
  • Bridges are verification architectures; five failure models still explain most of the lore.
  • Clear signing, monitoring, timelocks, and dependency hygiene are the living defenses; finished safety is a myth.

Timeline Glance

Year Surface Landmark
2011–2014 Exchange custody theft Mt. Gox-era thefts (collapse depth elsewhere)
2016 Contract + exchange The DAO; Bitfinex 119,754 BTC
2017 Contract wallets Parity multisig failures
2019–2020 Hot wallets/APIs Binance breach; KuCoin key compromise
2020–2021 DeFi economics Oracle/composability exploits
2022 Bridges + governance Wormhole; Ronin; Nomad; BNB Token Hub; Beanstalk
2023 Complex DeFi + supply chain Euler; Ledger Connect Kit
2024 Employee/vendor/multisig UI DMM Bitcoin; WazirX
2025 Signing control plane Bybit ~$1.5B; FBI NK attribution
H1 2026 Admin + bridge observation Drift ~$285M; KelpDAO ~$292M
Jul–Aug 2026 Hardware seed entropy Coldcard disclosure; ~$116M preliminary sweeps

Why Crypto Hacks Refuse to Stay in One Genre

New technologies change the surface. The underlying psychology often stays the same: people trust screens, brands, thresholds, and “we are audited” stickers. Collapses stress-test solvency myths. Scams stress-test belief. Hacks stress-test control.

The earliest crypto-security question was whether someone could steal the key. The modern question is larger: who or what can convince the system that a theft is authorized? The blockchain may be the strongest component in the stack. Everything around it is what attackers increasingly target.

That is the real story beneath the chaos. Not that code is doomed. That money at internet speed keeps teaching the same lesson with new doors: authority is the asset, and the chain will faithfully follow whoever holds it.

 

Explore more

Advertisement