Key Highlights
- The SlowMist 2025 report shows total losses surging to $2.93 billion as cybercriminals shifted from high-frequency attacks to precision-targeted, large-scale attacks.
- Centralized exchanges faced the impact of the financial damage, largely due to the $1.46 billion Bybit breach.
- On-chain monitoring and stablecoin interventions were enhanced, enabling the recovery of over 13% of the year’s stolen capital.
Blockchain security firm SlowMist published its 2025 Annual Report on Tuesday, showing that while the number of crypto-related security breaches decreased from 410 to 200 major incidents this year, the total financial impact rose to $2.935 billion.
The data was gathered through December 2025, showing a shift toward more organized cybercrime, especially from state-sponsored groups, while law enforcement agencies and stablecoin issuers have taken a firmer stance on freezing illegal funds.
The impact of the Bybit breach
The highlight of the year was the Bybit $1.46 billion breach, linked to North Korean hackers. This attack accounted for nearly half of all losses in 2025. Although the DeFi sector remained the most frequent target with 126 incidents, the size of the Bybit hack pushed centralized exchanges to the top of the financial loss list.
Security analysts noted that hackers are moving from opportunistic attacks to systematic, multi-step operations. The report states, “Account compromises remained the most common cause of security incidents,” with hijackings of X accounts making up 24% of the total cases. Smart contract vulnerabilities closely followed, representing 30.5% of the year’s exploits.

The difference between 2024 and 2025
2024 had more than double the number of incidents at 410 cases, but resulted in a lower total loss of about $2 billion. The 2025 data suggests that while the “barrier to entry” for low-level hackers may be increasing due to improved security tools, high-tier criminal groups have become much more skilled at extracting large sums from fewer high-value targets.
Moreover, the rise of AI-powered fraud has complicated the situation. Scammers are now using phishing and deepfake technology to impersonate project founders and exchange executives in “trust-based scams,” which has led to increased user distrust despite better technical audits.
Another major trend noted by SlowMist is the “active intervention” by stablecoin issuers and governments. In 2025, Tether (USDT) and Circle (USDC) became much more proactive, with USDT frozen on 576 separate Ethereum addresses and USDC on 214 addresses. This coordinated action led to roughly $387 million, about 13% of all stolen funds being successfully recovered or neutralized.
Looking ahead to 2026, the report indicates that security compliance is now a requirement for business survival, not just an optional benefit. The industry is set to face stricter regulations worldwide, such as the MiCA framework in Europe and the GENIUS Act in the United States, which focus on stablecoin reserves and anti-money laundering (AML) standards.
Also Read: Chinese Crypto Scammers Build $27B Darknet Market Via Telegram
