NextFin News - The largest theft in cryptocurrency history did not break a single line of code. On February 21, 2025, attackers took roughly $1.5 billion in ether from Bybit — more than the entire second-place heist on the all-time leaderboard — by tricking the exchange into signing a malicious transaction during what looked like a routine wallet transfer. The FBI later attributed the operation to North Korea. The message to the industry was blunt: the weakest link is no longer the smart contract. It is the human, and the machine, that signs.
The Paradox: Record Hacks, Falling Losses
Crypto theft has entered a contradiction that defines the current era. In the first half of 2026, attackers carried out 207 hacks — the most in any six-month period on record, more than double the 83 incidents logged in the same stretch of 2025. Yet total losses fell to $972 million, less than half the $2.3 billion stolen in the first half of 2025. The typical hack now yields about $219,000.
The distribution is the story. Two North Korea-linked operations in April 2026 — against Drift Protocol, which lost roughly $285 million, and KelpDAO, which lost roughly $292 million — accounted for about $577 million, or 66% of all value stolen in the half. Infrastructure and operational compromises made up only about 15% of incidents but roughly 76% of losses. More than 100 smaller smart-contract exploits, by contrast, produced only a small share of the money. In the words of blockchain-intelligence firm TRM Labs:
"North Korean hacking groups accounted for 76% of all crypto hack losses in 2026 through April — not because North Korea launched a wave of attacks, but because two attacks totaling USD 577 million dwarfed everything else."
The all-time leaderboard reads like a roll call of the industry's growing pains, valued at incident-date prices:
- Bybit, centralized exchange, Feb. 21, 2025 — ~$1.5 billion
- Ronin Network, Axie Infinity bridge, Mar. 23, 2022 — ~$615 million
- Poly Network, cross-chain protocol, Aug. 10, 2021 — ~$612 million
- Coincheck, exchange hot wallet, January 2018 — ~$534 million
- Mt. Gox, exchange collapse, 2014 — ~$473 million
- KelpDAO, bridge, Apr. 18, 2026 — ~$292 million
- Drift Protocol, Solana DeFi, Apr. 1, 2026 — ~$285 million
- WazirX, Indian exchange, Jul. 18, 2024 — ~$235 million
North Korea is the dominant author. In 2025, DPRK-linked hackers stole $2.02 billion — a 51% year-over-year increase — lifting their cumulative total to roughly $6.75 billion. In the first half of 2026 alone, they captured about $643 million, or 66% of all stolen value, down from roughly $1.7 billion in the first half of 2025 but still far ahead of every other actor. The pattern from the prior years holds: $660.5 million across 20 incidents in 2023, then $1.34 billion across 47 incidents in 2024, a 102.88% increase in value stolen.
The Attack Surface Moved Off-Chain
The defining shift is where the break happens. The Bybit heist — described by blockchain-intelligence analysis as "the largest digital heist in the history of cryptocurrency" — did not exploit a vulnerability in Ethereum or in Bybit's own code. Investigators found that the attackers compromised a machine associated with a third-party service used to move ether from a cold wallet to a hot wallet and injected malicious JavaScript into the transaction-signing workflow. When Bybit's CEO signed what appeared to be a routine transfer of 401,000 ETH, the signed payload had already been swapped, redirecting the funds to addresses under the attackers' control.
That distinction matters. A smart-contract bug can be audited, patched, and eventually priced into a risk model. A signing workflow subverted from inside the operations stack cannot be fixed by an audit firm. The WazirX breach in July 2024 followed the same pattern: a multi-signature wallet managed with third-party custodian Liminal was drained of roughly $235 million after the payload displayed on the verification interface did not match what was actually signed. The Drift Protocol attack in April 2026 was not a code exploit either. It was a six-month intelligence campaign that compromised protocol signers through social engineering, then executed the full $285 million drain in about 12 minutes.
The KelpDAO incident completed the picture. Attackers exploited a single-verifier design flaw in a LayerZero bridge by compromising data-verification nodes and DDoSing others to force a failover to poisoned infrastructure. The result: roughly 116,500 rsETH, about $292 million, gone in one malicious instruction.
This is why the industry's long-held belief that cold wallets and multi-signature setups are "the best crypto wallet" took a hit. As analysts at the Center for Strategic and International Studies noted after the Bybit theft, the attack rattled members of the crypto industry who had treated offline storage and multisig as near-infallible. Bybit had also used a third-party signing solution — and that dependency became the entry point.
Why the Losses Concentrate Instead of Spreading
The concentration is structural, not accidental. North Korean operators — tracked by U.S. authorities as TraderTraitor and Lazarus Group — have turned crypto theft into fiscal policy. The trilateral attribution statement from the United States, Japan, and South Korea in January 2025 tied the WazirX theft to the DPRK and noted that Pyongyang had funded its sanctioned weapons program through a string of operations, including thefts from DMM Bitcoin, Upbit, and Rain Management. When theft is a state revenue line rather than an opportunistic crime, the attacker has patience, capital, and a mandate to keep going.
The economics explain the skew. Chainalysis found that in 2025 the top three hacks accounted for 69% of all losses, with Bybit alone representing $1.5 billion of the more than $3.4 billion stolen for the year. Outliers now reach 1,000 times the median theft. One patient campaign against a large target outweighs a year of smaller, opportunistic exploits.
There is also a selection effect. Smart-contract exploits are numerous — 125 of the 207 incidents in the first half of 2026 — because the attack surface keeps expanding: thousands of DeFi protocols, tokens, and smart contracts ship new code every week. But the money sits in infrastructure: bridges, custodians, signing setups, and centralized exchanges. Attacking the pipe is worth more than attacking the packet.
The operational tradecraft has also evolved. DPRK operators increasingly embed their own IT workers inside crypto services or use sophisticated impersonation tactics targeting executives, achieving larger thefts with fewer incidents. Fewer attacks, bigger paydays: that is the signature of a professionalized, state-directed program rather than a loose criminal network.
The Second-Order Effect: Contagion Travels Through DeFi Plumbing
The first-order loss is the stolen principal. The second-order damage is what the theft does to the rest of the system — and this is the channel the market underprices. The KelpDAO episode showed how a single breach can seize up lending markets far beyond the victim. After the initial $292 million drain, the attackers deposited stolen funds into Aave v3 as collateral and borrowed wrapped ether, creating roughly $195 million in debt. Lending pools raced to full utilization, at one point blocking more than $5.1 billion in stablecoin withdrawals, and Aave's total value locked dropped by nearly $8 billion.
That is the transmission mechanism: a bridge exploit becomes a liquidity shock in an unrelated lending protocol because stolen assets are usable as collateral until they are flagged. The defense — blacklisting addresses, pausing contracts — is reactive and imperfect. KelpDAO did freeze an attempted second drain of another 40,000 rsETH, worth roughly $95 million, but only after the first instruction had cleared.
The Bybit theft produced its own market tremor. Ethereum fell sharply in the days after the breach, briefly trading below $2,700 and pulling its market capitalization to about $283 billion — briefly below the network's realized cap, a condition associated with market-wide distress. The FBI's own alert warned that TraderTraitor actors "are proceeding rapidly" and that the stolen assets "will be further laundered and eventually converted to fiat currency." Bybit CEO Ben Zhou said that by March 20, 2025, the attackers had converted 86.29% of the stolen ETH into bitcoin and had begun using mixers to obscure the trail.
Recovery Has Improved — But Recovery Is Not Safety
The industry's response capacity has genuinely advanced. Within 72 hours of the Bybit theft, the exchange had assembled nearly 447,000 ether through emergency funding from Galaxy Digital, FalconX, and Wintermute, restoring reserves above a 100% collateralization ratio verified by a proof-of-reserves audit. Chainalysis said it helped freeze more than $40 million of the stolen funds, and Bybit offered a bounty of up to 10% of any recovered amount.
But recapitalization is not recovery. The stolen assets were not returned; users were made whole by the company's balance sheet and its backers. Meanwhile, the thieves kept moving. The Ronin case offers the only partial counterexample. After the March 2022 theft of $615 million in ETH and USDC, U.S. authorities seized about $30 million and sanctioned the receiving address. The bridge was recapitalized, but the vast majority of the funds were never recovered. "We are working with law enforcement officials, forensic cryptographers and our investors to make sure all funds are recovered or reimbursed," Ronin said at the time — and reimbursement, not recovery, is what ultimately happened.
Poly Network was an anomaly: roughly $578.6 million of the $612 million taken in August 2021 was returned within days by the attacker — a rare act of conscience, not a repeatable defense. And Mt. Gox, the original cautionary tale, took more than a decade to begin repaying creditors for the roughly 650,000 customer bitcoins and 100,000 of its own lost in 2014, a collapse that at the time represented about 7% of all bitcoins in circulation.
The Counter-Thesis: The Industry Is Actually Getting Safer
The strongest case against alarm is the data itself. Losses in the first half of 2026 fell by more than half year over year, from $2.3 billion to $972 million, even as incident counts doubled. Exchanges recapitalize faster. Law-enforcement cooperation is real: the FBI now publishes wallet addresses and asks node operators, exchanges, and DeFi services to block transactions with or derived from tainted addresses. Proof-of-reserves audits, once rare, are becoming table stakes after a major breach. If the measure is systemic survivability, 2026 looks better than 2025.
But survivability is not the same as security. The decline in losses reflects the absence of another Bybit-scale event, not a reduction in the underlying threat. North Korea's share of stolen value — 66% in the first half of 2026 — shows that the concentration risk has not eased; it has merely migrated to fewer, larger operators. And the attack vector that produced the three largest recent losses — Bybit, Drift, WazirX — is not code that can be patched. It is trust in signing infrastructure, third-party custodians, and bridge verifiers. That is a harder problem to audit away, because no amount of code review can protect against a signing interface that shows one thing and signs another.
What Comes Next
The forward picture splits by horizon. In the short term, incident frequency will keep rising as the DeFi surface expands; the typical $219,000 exploit is a cost of doing business that most protocols can absorb. In the medium term, the concentration will persist: a handful of state-sponsored operators will continue to pursue eight- and nine-figure targets, and the largest losses will keep coming from infrastructure compromise rather than code bugs. In the long term, the structural question is whether signing and verification can be moved to hardware-enforced, multi-party workflows that do not rely on a human reading a screen — because as long as a person or a single machine can be tricked into approving a transaction, the heist playbook will keep working.
Base case: losses remain lumpy, with annual totals driven by whether one or two large infrastructure targets fall. Upside case: hardware-backed signing and mandatory verification-node redundancy push infrastructure-compromise losses below 30% of total value for two consecutive quarters. Downside case: a successful attack on a top-tier bridge or custodian exceeds the Bybit record, and contagion through lending markets proves deeper than Aave's near-miss.
What to watch: the share of stolen value attributable to North Korea each quarter; the ratio of infrastructure-compromise losses to smart-contract-exploit losses; and whether any major platform adopts hardware-enforced, multi-party transaction signing. The falsifying signal for the concentration thesis is specific: if North Korea's share of stolen value falls back toward its incident share — roughly 15% to 20% — for two consecutive quarters while infrastructure losses stay below 30% of total value, the "state-sponsored concentration" read is wrong.
Crypto's heists have stopped being a coding contest and become an intelligence contest. Audits protect the code; they do not protect the signature. Until the industry treats the signing workflow as the asset, the next record theft will look less like a hack and more like a handover.
Explore more exclusive insights at nextfin.ai.
