BTCC / BTCC Square / Blockchainreporter /
$2.1B Crypto Heist in H1 2025: Infrastructure Attacks & State-Sponsored Hackers Fuel Unprecedented Losses

$2.1B Crypto Heist in H1 2025: Infrastructure Attacks & State-Sponsored Hackers Fuel Unprecedented Losses

Published:
2025-06-27 15:00:00
18
1

Crypto’s Wild West just got wilder. The first half of 2025 saw digital asset theft hit a staggering $2.1 billion—and the usual suspects aren’t playing nice.

Infrastructure under siege

Protocols got pummeled. Bridges burned (figuratively, this time). Hackers bypassed layer upon layer of security like it was a game of digital Jenga—except the blocks were your funds.

The state-sponsored elephant in the room

When nation-states enter the chat, the rules change. These aren’t basement-dwelling script kiddies—they’re resource-flush actors treating crypto like an geopolitical ATM. And business is booming.

Meanwhile, traditional finance execs are clutching their pearls—when they’re not quietly funneling VC money into ‘blockchain security’ startups at 100x multiples. The irony’s thicker than a Bitcoin maximalist’s Twitter thread.

hack3 main

  • Crypto theft hits $2.1B in H1 2025, led by infrastructure attacks targeting private keys.
  • North Korea responsible for 70% of losses, using crypto theft for sanctions evasion.
  • Global cooperation and enhanced security needed to combat rising state-sponsored hacks.

Cryptocurrency theft reached a record of $2.1 billion during the first half of 2025, according to data from TRM Labs. The rise in losses stems from network attacks targeting private keys and seed phrases, which accounted for over 80% of all stolen assets. This surge marks one of the highest theft volumes in recent years, propelled by a series of high-profile breaches and the increasing involvement of state-sponsored hacking groups.

The largest single event was the February 2025 hack of the Bybit exchange, where $1.5 billion was stolen. TRM Labs attributes this attack to North Korean state actors. This breach alone represented almost 70% of total crypto theft in the first half of the year and caused the average hack size to jump to nearly $30 million, double the average in H1 2024.

Beyond Bybit, other months such as January, April, May, and June each recorded thefts surpassing $100 million, reflecting a persistent threat environment targeting centralized exchanges.

AD 4nXfGwJoaieHDQTZc2E5GPqtMfbQqdNWBXgauSwGKAqBWKmvyD dAOJrhINSj2rMgEPezvfQ9CaNgdctcmjyri23 I87jwqNXuw5SLSPj9Z N8rrLvclPZp98nvXfz6S6pRWi89SCjA?key=S1TxvEgI19phIvTP IFf Q

Source: TRM Labs

The sheer scale of these incidents pushed 2025’s first half theft totals above the record set in 2022 by roughly 10%, matching the losses recorded for the entirety of 2024. The growing concentration of risk at large exchanges has drawn experienced threat actors seeking significant returns.

North Korea’s Dominant Role in Crypto Theft

TRM Labs identified North Korea as the most active state actor in crypto theft during this period, responsible for approximately $1.6 billion, or 70% of the total stolen assets. These illicit activities align with the country’s broader goals, including sanctions evasion and funding nuclear weapons programs. cryptocurrency theft has become a core component of North Korea’s statecraft, reflecting an institutionalized effort to harness digital asset crime for strategic purposes.

Beyond North Korea, other government-linked hacking groups have also exploited cryptocurrency platforms for political objectives. On June 18, 2025, the Israel-associated group Gonjeshke Darande, also known as Predatory Sparrow, hacked Iran’s largest crypto exchange Nobitex and stole over $90 million. The stolen funds were transferred to vanity addresses lacking private passwords, indicating the theft served symbolic or political purposes rather than financial gain.

Enhanced Security and Global Collaboration Needed

TRM Labs pointed out the urgent need for strengthened defenses against sophisticated state-level threats. Recommendations include enhanced insider threat detection and improved measures against social engineering attacks.

The report also stresses the importance of global cooperation among law enforcement, financial intelligence units, and blockchain analytics firms to track stolen funds and hold perpetrators accountable. The first half of 2025 displays a shift in the cryptocurrency theft landscape, with technical attacks and state-sponsored operations dominating losses.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users