The post Record $2.02B stolen in 2025 appeared on BitcoinEthereumNews.com. Rising blockchain adoption and higher digital asset prices have coincided with a sharpThe post Record $2.02B stolen in 2025 appeared on BitcoinEthereumNews.com. Rising blockchain adoption and higher digital asset prices have coincided with a sharp

Record $2.02B stolen in 2025

Rising blockchain adoption and higher digital asset prices have coincided with a sharp escalation in DPRK crypto theft, reshaping global risk across centralized services, DeFi, and personal wallets.

Over $3.4 billion stolen in 2025 as crypto theft shifts

According to a new report by Chainalysis, the crypto sector saw more than $3.4 billion stolen between January and early December 2025, with the Bybit breach in February alone responsible for $1.5 billion. However, behind this headline figure, the structure of crypto crime has changed markedly across just three years.

Moreover, personal wallet compromises have surged as a share of overall theft. They rose from 7.3% of stolen value in 2022 to 44% in 2024. In 2025, they would have accounted for 37% of total losses if the Bybit compromise had not so heavily distorted the data.

Centralized services, despite deep resources and professional security teams, continue to suffer increasingly large losses driven by private key compromises. While such incidents occur infrequently, they remain devastating. In Q1 2025, they represented 88% of all losses, underscoring the systemic risk created by single points of failure.

That said, the persistence of high theft volumes shows that despite better practices in some segments, attackers can still exploit weaknesses across multiple vectors and platforms.

Outlier mega-hacks dominate crypto theft

Crypto theft has always skewed toward a handful of outsized breaches, but 2025 set a new extreme. For the first time, the ratio between the largest hack and the median incident surpassed 1,000x, based on the U.S. dollar value of funds at the time of theft.

As a result, the top three hacks in 2025 accounted for 69% of all service losses. While incident counts and median losses tend to move with asset prices, the scale of individual outliers is rising even faster. This concentration risk means that a single compromise can now reshape annual loss statistics for the entire industry.

North Korea leads global crypto theft landscape

The Democratic People’s Republic of Korea (DPRK) remains the most consequential nation-state actor in digital asset crime. In 2025, North Korean hackers stole at least $2.02 billion worth of cryptocurrency, an increase of $681 million over 2024 and a 51% year-over-year rise in value taken.

These operations made 2025 the worst year on record for DPRK-linked theft by value. Moreover, DPRK attacks represented a record 76% of all service compromises, pushing the lower-bound cumulative total stolen by Pyongyang-linked actors to $6.75 billion. Notably, this record haul came despite an assessed sharp reduction in confirmed incidents.

North Korean operators increasingly exploit one of their core vectors: embedding IT workers inside exchanges, custodians, and web3 companies.

Once inside, these workers can cultivate privileged access, ease lateral movement, and eventually orchestrate large-scale thefts. The Bybit attack in February 2025 likely amplified the impact of this infiltration model.

However, DPRK-linked groups have also adapted their social engineering tactics. Rather than simply applying for jobs, they now frequently impersonate recruiters for prominent web3 and AI firms, staging elaborate fake hiring processes. These often end with “technical screens” that trick targets into handing over credentials, source code, or VPN and SSO access to their current employers.

At the executive level, similar social engineering campaigns feature bogus outreach from supposed strategic investors or acquirers.

Pitch meetings and pseudo–due diligence processes are used to probe for sensitive system details and map access paths into high-value infrastructure. This evolution builds directly on earlier IT worker fraud schemes and highlights a tighter focus on strategically important AI and blockchain businesses.

Throughout 2022–2025, DPRK-attributed hacks consistently occupy the highest value bands, while non–nation-state actors show more normal distributions across incident sizes. That pattern indicates that when North Korea strikes, it prefers large centralized services and aims for maximum financial and political impact.

One striking feature of 2025 is that this record total was achieved with far fewer known operations.

The enormous Bybit breach appears to have allowed DPRK-linked groups to execute a small number of extremely lucrative attacks instead of a larger volume of mid-sized compromises.

Distinctive DPRK cryptocurrency laundering patterns

The unprecedented influx of stolen assets in early 2025 provided unusually clear visibility into how Pyongyang-linked actors move funds at scale. Their cryptocurrency laundering patterns are significantly different from those of other criminal groups and continue to evolve over time.

DPRK outflows show a distinctive bracketing structure. Slightly over 60% of volume travels in transfers below $500,000, whereas other stolen fund actors send more than 60% of their flows on-chain in tranches between $1 million and $10 million+.

Despite typically stealing larger totals, DPRK groups break payments into smaller segments, suggesting a deliberate attempt to evade detection through more sophisticated structuring.

Furthermore, DPRK actors consistently favor specific laundering touchpoints.

They rely heavily on Chinese-language money movement and guarantee services, often operating through loosely connected networks of professional launderers whose compliance standards can be weak. They also make extensive use of cross-chain bridge and mixing services, along with specialized providers such as Huione, to increase obfuscation and jurisdictional complexity.

By contrast, many other criminal groups prefer lending protocols, no-KYC exchanges, P2P platforms, and decentralized exchanges for liquidity and pseudonymity. DPRK entities show limited integration with these areas of DeFi, underlining that their constraints and objectives differ from those of typical financially motivated cybercriminals.

These preferences indicate that DPRK networks are tightly linked with illicit operators across the Asia-Pacific region, especially in China-based channels that provide indirect access to the global financial system. This matches Pyongyang’s wider history of using Chinese intermediaries to sidestep sanctions and move value offshore.

The 45-day laundering cycle after DPRK crypo theft

On-chain analysis of DPRK-linked thefts between 2022 and 2025 reveals a relatively stable, multi-wave laundering cycle lasting around 45 days. While not all operations follow this timeline, it appears repeatedly when stolen funds are actively moved.

Wave 1, spanning days 0 to 5, focuses on immediate layering. DeFi protocols see intense spikes in stolen fund flows as initial entry points, while mixing services record large volume jumps to create the first layer of obfuscation. This flurry of movement is designed to push funds away from easily identified source addresses.

Wave 2, covering days 6 to 10, marks the start of integration into the broader ecosystem. Exchanges with limited KYC controls, some centralized platforms, and secondary mixers begin to receive flows, often facilitated by cross-chain bridges that fragment and complicate transaction trails. This phase is critical, as funds transition toward potential off-ramps.

Wave 3, running from days 20 to 45, features the long tail of integration. No-KYC exchanges, instant swap services, and Chinese-language laundering services emerge as major endpoints. Centralized exchanges also increasingly receive deposits, reflecting efforts to blend illicit proceeds with legitimate trade flows, often through operators in less regulated jurisdictions.

This broad 45-day window provides valuable intelligence for law enforcement and compliance teams seeking to disrupt flows in real time. However, analysts note important blind spots: private key transfers, certain OTC crypto-for-fiat deals, or fully off-chain arrangements can remain invisible unless paired with additional intelligence.

Personal wallet compromises surge in volume

Alongside high-profile service breaches, attacks on individuals have escalated sharply. Lower-bound estimates show that personal wallet compromises represented about 20% of total value stolen in 2025, down from 44% in 2024, yet still reflecting large-scale damage.

Incident counts nearly tripled from 54,000 in 2022 to 158,000 in 2025. Over the same period, the number of unique victims doubled from roughly 40,000 to at least 80,000. These increases likely mirror broader user adoption of self-custodied assets. For example, Solana, one of the chains with the most active personal wallets, recorded about 26,500 affected users, far more than other networks.

However, the total dollar value lost by individuals fell from $1.5 billion in 2024 to $713 million in 2025. This suggests attackers are spreading efforts across many more victims while extracting smaller sums per account, potentially to reduce detection risk and exploit less sophisticated users.

Network-level crime metrics illuminate which chains currently present the greatest user risk. In 2025, when measuring theft per 100,000 wallets, Ethereum and Tron show the highest crime rates. Ethereum’s vast scale combines high incident counts with elevated per-wallet risk, whereas Tron displays a relatively high theft rate despite a smaller active base. By contrast, Base and Solana show lower rates even though their user communities are sizable.

These differences indicate that personal wallet compromises are not evenly distributed across the ecosystem. Factors such as user demographics, dominant application types, local criminal infrastructure, and education levels likely influence where scammers and malware operators focus their efforts.

The decentralized finance sector exhibits a notable divergence between market growth and security outcomes. Data from 2020 through 2025 confirm three clear phases in the relationship between DeFi total value locked (TVL) and hack-related losses.

In Phase 1, from 2020 to 2021, TVL and losses rose in tandem as the early DeFi boom attracted both capital and sophisticated attackers. Phase 2, covering 2022 to 2023, saw both TVL and losses retreat as markets cooled. However, Phase 3, spanning 2024 and 2025, marks a structural break: TVL has recovered from 2023 lows, but hack volumes remain comparatively subdued.

This divergence implies that defi security improvements are starting to have measurable effect. Moreover, the simultaneous rise of personal wallet attacks and centralized exchange hacks hints at target substitution, with threat actors shifting resources toward areas perceived as easier to compromise.

Case study: Venus Protocol highlights defensive progress

The Venus Protocol incident in September 2025 underscores how layered defenses can meaningfully change outcomes. Attackers used a compromised Zoom client to gain a foothold and manipulated a user into granting delegate control over an account holding $13 million in assets.

Under earlier DeFi conditions, such access might have resulted in irreversible losses. However, Venus had integrated a security monitoring platform only a month earlier. That platform flagged suspicious activity roughly 18 hours before the attack and issued another alert when the malicious transaction was submitted.

Within 20 minutes, Venus paused its protocol, halting fund movements. Partial functionality returned after around 5 hours, and within 7 hours the protocol forcibly liquidated the attacker’s wallet. By the 12-hour mark, all stolen funds had been recovered and normal operations resumed.

In a further step, Venus governance approved a proposal to freeze approximately $3 million in assets still under the attacker’s control. The adversary ultimately failed to profit and instead incurred net losses, showcasing the growing power of on-chain governance, monitoring, and incident response frameworks.

That said, this case should not breed complacency. It demonstrates what is possible when protocols invest early in monitoring and rehearsed playbooks, but many DeFi platforms still lack comparable capabilities or clear contingency plans.

Implications for 2026 and the future threat environment

The 2025 data portray a highly adaptive DPRK ecosystem, in which fewer operations can still deliver record outcomes. The Bybit incident, combined with other large-scale compromises, shows how one successful campaign can sustain funding needs for extended periods while groups focus on laundering and operational security.

Moreover, the unique profile of dprk crypto theft relative to other illicit activity offers valuable detection opportunities. Their preference for specific transfer sizes, heavy reliance on certain Chinese-language networks, and characteristic 45-day laundering cycle can help exchanges, analytics firms, and regulators flag suspicious behavior earlier.

As North Korea crypto hackers continue to use digital assets to finance state priorities and circumvent sanctions, the industry must accept that this adversary operates under different incentives than ordinary financially motivated criminals. The regime’s record-breaking 2025 performance, achieved with an estimated 74% fewer known attacks, suggests that many operations may still be going undetected.

Looking ahead to 2026, the central challenge will be to identify and disrupt these high-impact operations before another Bybit-scale breach occurs. Strengthening controls at centralized venues, hardening personal wallets, and deepening cooperation with law enforcement will be critical to containing both nation-state campaigns and the broader wave of crypto crime.

In summary, 2025 confirmed that while defenses are improving in areas like DeFi, sophisticated actors such as DPRK and large-scale wallet thieves continue to exploit structural weaknesses, making coordinated global responses more urgent than ever.

Source: https://en.cryptonomist.ch/2025/12/19/dprk-crypto-theft-2025/

Market Opportunity
DeFi Logo
DeFi Price(DEFI)
$0.000309
$0.000309$0.000309
-0.96%
USD
DeFi (DEFI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

8.18 Million Solana Committed on CME as SOL Options Prepare to Go Live

8.18 Million Solana Committed on CME as SOL Options Prepare to Go Live

Solana open interest rockets 6% on CME
Share
Coinstats2025/09/18 04:05
Lovable AI’s Astonishing Rise: Anton Osika Reveals Startup Secrets at Bitcoin World Disrupt 2025

Lovable AI’s Astonishing Rise: Anton Osika Reveals Startup Secrets at Bitcoin World Disrupt 2025

BitcoinWorld Lovable AI’s Astonishing Rise: Anton Osika Reveals Startup Secrets at Bitcoin World Disrupt 2025 Are you ready to witness a phenomenon? The world of technology is abuzz with the incredible rise of Lovable AI, a startup that’s not just breaking records but rewriting the rulebook for rapid growth. Imagine creating powerful apps and websites just by speaking to an AI – that’s the magic Lovable brings to the masses. This groundbreaking approach has propelled the company into the spotlight, making it one of the fastest-growing software firms in history. And now, the visionary behind this sensation, co-founder and CEO Anton Osika, is set to share his invaluable insights on the Disrupt Stage at the highly anticipated Bitcoin World Disrupt 2025. If you’re a founder, investor, or tech enthusiast eager to understand the future of innovation, this is an event you cannot afford to miss. Lovable AI’s Meteoric Ascent: Redefining Software Creation In an era where digital transformation is paramount, Lovable AI has emerged as a true game-changer. Its core premise is deceptively simple yet profoundly impactful: democratize software creation. By enabling anyone to build applications and websites through intuitive AI conversations, Lovable is empowering the vast majority of individuals who lack coding skills to transform their ideas into tangible digital products. This mission has resonated globally, leading to unprecedented momentum. The numbers speak for themselves: Achieved an astonishing $100 million Annual Recurring Revenue (ARR) in less than a year. Successfully raised a $200 million Series A funding round, valuing the company at $1.8 billion, led by industry giant Accel. Is currently fielding unsolicited investor offers, pushing its valuation towards an incredible $4 billion. As industry reports suggest, investors are unequivocally “loving Lovable,” and it’s clear why. This isn’t just about impressive financial metrics; it’s about a company that has tapped into a fundamental need, offering a solution that is both innovative and accessible. The rapid scaling of Lovable AI provides a compelling case study for any entrepreneur aiming for similar exponential growth. The Visionary Behind the Hype: Anton Osika’s Journey to Innovation Every groundbreaking company has a driving force, and for Lovable, that force is co-founder and CEO Anton Osika. His journey is as fascinating as his company’s success. A physicist by training, Osika previously contributed to the cutting-edge research at CERN, the European Organization for Nuclear Research. This deep technical background, combined with his entrepreneurial spirit, has been instrumental in Lovable’s rapid ascent. Before Lovable, he honed his skills as a co-founder of Depict.ai and a Founding Engineer at Sana. Based in Stockholm, Osika has masterfully steered Lovable from a nascent idea to a global phenomenon in record time. His leadership embodies a unique blend of profound technical understanding and a keen, consumer-first vision. At Bitcoin World Disrupt 2025, attendees will have the rare opportunity to hear directly from Osika about what it truly takes to build a brand that not only scales at an incredible pace in a fiercely competitive market but also adeptly manages the intense cultural conversations that inevitably accompany such swift and significant success. His insights will be crucial for anyone looking to understand the dynamics of high-growth tech leadership. Unpacking Consumer Tech Innovation at Bitcoin World Disrupt 2025 The 20th anniversary of Bitcoin World is set to be marked by a truly special event: Bitcoin World Disrupt 2025. From October 27–29, Moscone West in San Francisco will transform into the epicenter of innovation, gathering over 10,000 founders, investors, and tech leaders. It’s the ideal platform to explore the future of consumer tech innovation, and Anton Osika’s presence on the Disrupt Stage is a highlight. His session will delve into how Lovable is not just participating in but actively shaping the next wave of consumer-facing technologies. Why is this session particularly relevant for those interested in the future of consumer experiences? Osika’s discussion will go beyond the superficial, offering a deep dive into the strategies that have allowed Lovable to carve out a unique category in a market long thought to be saturated. Attendees will gain a front-row seat to understanding how to identify unmet consumer needs, leverage advanced AI to meet those needs, and build a product that captivates users globally. The event itself promises a rich tapestry of ideas and networking opportunities: For Founders: Sharpen your pitch and connect with potential investors. For Investors: Discover the next breakout startup poised for massive growth. For Innovators: Claim your spot at the forefront of technological advancements. The insights shared regarding consumer tech innovation at this event will be invaluable for anyone looking to navigate the complexities and capitalize on the opportunities within this dynamic sector. Mastering Startup Growth Strategies: A Blueprint for the Future Lovable’s journey isn’t just another startup success story; it’s a meticulously crafted blueprint for effective startup growth strategies in the modern era. Anton Osika’s experience offers a rare glimpse into the practicalities of scaling a business at breakneck speed while maintaining product integrity and managing external pressures. For entrepreneurs and aspiring tech leaders, his talk will serve as a masterclass in several critical areas: Strategy Focus Key Takeaways from Lovable’s Journey Rapid Scaling How to build infrastructure and teams that support exponential user and revenue growth without compromising quality. Product-Market Fit Identifying a significant, underserved market (the 99% who can’t code) and developing a truly innovative solution (AI-powered app creation). Investor Relations Balancing intense investor interest and pressure with a steadfast focus on product development and long-term vision. Category Creation Carving out an entirely new niche by democratizing complex technologies, rather than competing in existing crowded markets. Understanding these startup growth strategies is essential for anyone aiming to build a resilient and impactful consumer experience. Osika’s session will provide actionable insights into how to replicate elements of Lovable’s success, offering guidance on navigating challenges from product development to market penetration and investor management. Conclusion: Seize the Future of Tech The story of Lovable, under the astute leadership of Anton Osika, is a testament to the power of innovative ideas meeting flawless execution. Their remarkable journey from concept to a multi-billion-dollar valuation in record time is a compelling narrative for anyone interested in the future of technology. By democratizing software creation through Lovable AI, they are not just building a company; they are fostering a new generation of creators. His appearance at Bitcoin World Disrupt 2025 is an unmissable opportunity to gain direct insights from a leader who is truly shaping the landscape of consumer tech innovation. Don’t miss this chance to learn about cutting-edge startup growth strategies and secure your front-row seat to the future. Register now and save up to $668 before Regular Bird rates end on September 26. To learn more about the latest AI market trends, explore our article on key developments shaping AI features. This post Lovable AI’s Astonishing Rise: Anton Osika Reveals Startup Secrets at Bitcoin World Disrupt 2025 first appeared on BitcoinWorld.
Share
Coinstats2025/09/17 23:40
EIGEN pumps to three-month high with boost from AI agents

EIGEN pumps to three-month high with boost from AI agents

The post EIGEN pumps to three-month high with boost from AI agents appeared on BitcoinEthereumNews.com. Eigen Cloud (EIGEN) pumped to a three-month high, boosted by its role as a data supplier to AI agents. EIGEN rallied by 33% for the past day, logging 67% gains for the past 90 days.  Eigen Cloud (EIGEN) was the latest breakout token during the current altcoin season. It gained 33.8% in the past day, to trade at a three-month peak of $2.03. The token attempted a recovery after its rebranding in June.  EIGEN broke out to a three-month peak, following its addition to Google’s AI agent payment framework. | Source: CoinGecko. EIGEN open interest also jumped to over $130M, the highest level in the past six months. The token still has limited positions on Hyperliquid, with just nine whales betting on its direction. Five of those positions are shorting EIGEN, and are carrying unrealized losses after the recent breakout. Eigen Cloud rallied after becoming part of Google’s AI agent payment initiative. As Cryptopolitan previously reported, Google opened a toolset for safe, verifiable payments coming directly from AI agents.  Google’s AP2 protocol included Eigen as a platform for safe, verified transactions originating with AI agents.  We’re excited to be a launch partner for @GoogleCloud‘s new Agent Payments Protocol (AP2), a standard that gives AI agents the ability to transact with trust and accountability. At EigenCloud, our focus is on verifiability. As our founder @sreeramkannan said: AP2 helps create… https://t.co/Fx90rTJuhm pic.twitter.com/0Vil6yLdkf — EigenCloud (@eigenlayer) September 16, 2025 The new use case for Eigen arrives as older Web3 and DeFi projects seek to pivot to new use cases. Other AP2 partners from the crypto space include Coinbase and the Ethereum Foundation. Most of the payment and e-commerce platforms offer fiat handling, while Eigen’s verifiable transaction data target crypto payments and transfers. The market for AI agent transactions is estimated at over $27B,…
Share
BitcoinEthereumNews2025/09/18 18:29