More

    Crypto’s biggest hacks drain over $5B – Here’s the major problem they expose – AMBCrypto


    The biggest 10 hacks that have happened since 2022 have drained over $5 billion to date.

    But what is eye-catching here is that these hacks did not happen because they broke ‘a single line of code.’ According to CoinBureau,

    They [the attackers] broke people, passwords and approval systems instead.

    What vulnerabilities led to the biggest hacks?

    Here, the biggest attack was the Bybit’s $1.46 billion hack, which took place in February 2025. In this exploit, the hackers compromised a developer’s computer and manipulated what was displayed on the screens of Bybit employees.

    Though the transaction appeared legitimate on the surface, the underlying transaction redirected roughly 401,000 ETH to the attackers.

    After the investigation, the FBI linked the attack to North Korea’s TraderTraitor group. Well, this was a social-engineering and infrastructure-compromise attack, rather than simply finding a bug in Bybit’s blockchain code.

    Then comes the Ronin Network hack, which followed a similar pattern and drained $625 million. Instead of breaking the blockchain itself, attackers compromised five of nine validator keys. In this, the initial access reportedly came through a fake job offer sent to an employee.

    Other attacks involved genuine technical loopholes. For instance, in the BNB Chain exploit, attackers compromised a flaw in the bridge’s proof-verification system to drain approximately 2 million BNB.

    Meanwhile, in the Wormhole hack, a vulnerability in the code allowed an attacker to mint around 120,000 wrapped ETH without providing the required collateral. These attacks fell into the category of traditional smart-contract vulnerabilities.

    Other compromises and the main culprit

    Then there were attacks that involved multisig systems, centralized exchanges, and third-party providers. The biggest being the the FTX attack, which reportedly lost hundreds of millions after attackers gained control of employee-related authentication.

    Given all these cases, the U.S. authorities and blockchain-analysis firms have already attributed numerous major crypto thefts to North Korean-linked groups such as Lazarus and TraderTraitor.

    These groups are known for commonly using fake employment opportunities, malware, phishing, and social engineering to obtain access before moving stolen cryptocurrency through multiple networks.

    The hacks epidemic

    This comes on the heels of TRM Labs recently reporting a record 207 crypto hacks in H1 2026, more than double the 85 incidents recorded in H1 2025.

    Source: TRM Labs

    While smart contract exploits accounted for 125 cases, three-quarters of stolen funds came from compromised keys, custody systems, and signing infrastructure.

    Lastly, losses reached $972 million, with North Korea-linked actors responsible for 66% of stolen funds.


    Final Summary

    • Bybit hack happened because attackers compromised a developer’s computer. 
    • Meanwhile, in the Ronin Network hack, the attackers compromised five of nine validator keys.



    Source link

    Latest stories

    You might also like...