Biggest Crypto Hacks & Exploits, Ranked by Loss

The biggest crypto hack of all time is the Bybit Cold Wallet Compromise, with $1.46 billion stolen on February 21, 2025. Across 23 tracked major exploits and thefts, over $6.1 billion has been lost, ranked here by total USD stolen. The list spans exchange hacks, bridge exploits, DeFi attacks, and governance exploits dating from 2016 to 2026.

While some hacks resulted in full recoveries—such as the Poly Network and Euler Finance incidents—many funds remain lost. The ranking highlights the ongoing security challenges in the crypto space, with bridge exploits and exchange vulnerabilities dominating the top losses. The pattern has continued into 2026: the two largest exploits of the year so far — the Kelp DAO bridge drain ($292M, April 18, 2026) and the Drift Protocol admin takeover ($285M, April 1, 2026), both attributed by investigators to North Korean state-linked actors — already rank among the ten biggest crypto thefts of all time. Notably, both defeated off-chain infrastructure (bridge verifier nodes, pre-signed admin transactions) rather than smart-contract code, echoing the operational-security failures behind Bybit and Ronin.

  1. #1 Bybit Cold Wallet Compromise (Feb 21, 2025) $1.46B 2025-02-21 · Exchange hack

    On February 21, 2025, Bybit's Ethereum cold wallet was drained of approximately 401,346 ETH plus staked-ETH derivatives in a single execution — $1.46B, the largest crypto theft ever. Attackers injected malicious JavaScript into the Safe multisig signing interface; the attack is attributed to North Korea's Lazarus Group, and no customer funds were lost.

  2. #2 Ronin Bridge Validator Compromise (March 23, 2022) $620M 2022-03-23 · Bridge exploit

    On March 23, 2022, the Ronin Bridge — the canonical bridge between Ethereum and the Ronin sidechain hosting Sky Mavis's Axie Infinity ecosystem — was drained of 173,600 ETH and 25.5M USDC ($620M) after a spear-phishing campaign compromised five of the bridge's nine validator keys — enough to meet its 5-of-9 signing threshold.

  3. #3 Poly Network Cross-Chain Exploit (August 10, 2021) $611M 2021-08-10 · Cross-chain bridge exploit / fully recovered

    On August 10, 2021, an attacker exploited a flaw in Poly Network's verifyHeaderAndExecuteTx function to overwrite the cross-chain bridge's keeper keys and withdraw $611M across Ethereum, BNB Chain, and Polygon — then returned effectively all of the funds in the weeks that followed.

  4. #4 BNB Chain Token Hub IAVL Proof Forgery (Oct 7, 2022) $568M 2022-10-07 · Cross-chain bridge exploit

    On October 6-7, 2022, an attacker forged IAVL Merkle proofs against the BSC Token Hub — BNB Chain's native cross-chain bridge — to mint 2 million BNB (~$568M). Validators halted block production mid-attack, freezing roughly $430M before it could leave the chain.

  5. #5 Coincheck NEM Hot-Wallet Theft (Jan 26, 2018) $530M 2018-01-26 · Exchange hack

    On January 26, 2018, Tokyo-based exchange Coincheck reported the unauthorized transfer of 523 million NEM (XEM) tokens (~$530M) from a single hot wallet whose key was compromised via targeted phishing — the tokens had never been moved to cold storage.

  6. #6 Wormhole Bridge Signature Bypass (Feb 2, 2022) $326M 2022-02-02 · Bridge exploit

    On February 2, 2022, an attacker bypassed the Wormhole Bridge's signature verification using a deprecated Solana function and minted 120,000 unbacked wETH (~$326M). Jump Crypto fully replenished the bridge's locked-ETH reserves via a $326M bailout within 24 hours.

  7. #7 KelpDAO rsETH Cross-Chain Bridge Exploit (April 18, 2026) $292M 2026-04-18 · Bridge / liquid-restaking exploit

    Kelp DAO lost ~116,500 rsETH (~$292M) on April 18, 2026 — the biggest exploit of 2026 so far — when an attacker defeated its LayerZero bridge's single one-of-one DVN by compromising RPC nodes and feeding the verifier fabricated burn records, minting unbacked rsETH across destination chains.

  8. #8 Drift Protocol DPRK Admin-Access and Fake-Oracle Exploit (April 1, 2026) $285M 2026-04-01 · DeFi exploit (social engineering / governance takeover)

    Drift Protocol, then Solana's largest perpetual-futures DEX, lost ~$285M on April 1, 2026 — the second-largest Solana hack after Wormhole (2022). A months-long DPRK social-engineering operation abused Solana durable nonces to obtain pre-signed multisig approvals, seized admin control, whitelisted a fake wash-traded token as collateral, and drained three vaults in about 12 minutes.

  9. #9 WazirX Exchange Hack (Jul 18, 2024) $235M 2024-07-18 · Exchange hack

    On July 18, 2024, WazirX, India's largest cryptocurrency exchange by spot trading volume, lost approximately $235M in customer assets when a social-engineering attack attributed to the Lazarus Group compromised its Liminal Custody-managed multisig via manipulated transaction calldata.

  10. #10 Cetus Protocol Exploit on Sui (May 22, 2025) $223M 2025-05-22 · DEX exploit

    On May 22, 2025, Cetus Protocol, the dominant concentrated-liquidity DEX on the Sui Network, suffered an exploit driven by an integer-overflow bug in its tick-math library. External coverage (The Block, CoinDesk) puts the loss at ~$223M, while the DeFi Intel post-mortem estimates $230M. Sui validators froze roughly $162M, later returned via a community vote, while ~$60M was bridged out; Cetus restored pools and announced full user reimbursement.

  11. #11 Euler Finance donateToReserves Exploit (March 13, 2023) $197M 2023-03-13 · DeFi lending exploit / fully recovered

    On March 13, 2023, an attacker drained approximately $197M from Euler Finance, an Ethereum money market, via a faulty donateToReserves function combined with flash-loan self-liquidation. After public on-chain negotiation the attacker returned all stolen funds, and Euler fully reimbursed users.

  12. #12 Beanstalk Flash-Loan Governance Attack (April 17, 2022) $182M 2022-04-17 · Governance exploit

    On April 17, 2022, the Beanstalk Farms stablecoin protocol was drained of approximately $182M in a single atomic transaction: the attacker used a ~$1B flash loan to acquire majority governance power and pass a malicious proposal that transferred protocol funds to their own address.

  13. #13 Cream Finance Third Hack of 2021 (Oct 27, 2021) $130M 2021-10-27 · DeFi exploit

    On October 27, 2021, Cream Finance, a Compound-fork lending protocol, suffered its third and largest exploit of the year — $130M — via a flash-loan-amplified price-oracle manipulation of its yUSD vault collateral. No recovery was possible.

  14. #14 Atomic Wallet Mass Seed-Phrase Compromise (Jun 3, 2023) $100M+ 2023-06-03 · Non-custodial wallet mass compromise

    Beginning June 2-3, 2023, roughly 5,500 users of Atomic Wallet, a non-custodial multi-asset wallet, had funds drained in a mass seed-phrase compromise attributed to the Lazarus Group, with losses exceeding $100M. Most victims recovered nothing.

  15. #15 Curve Finance Vyper Reentrancy Compiler Bug (July 30, 2023) $73M 2023-07-30 · Compiler vulnerability

    On July 30, 2023, multiple Curve Finance stable pools were drained via a previously-unknown bug in the Vyper compiler's @nonreentrant decorator (versions 0.2.15-0.3.0), which silently failed to block reentrancy. Whitehat frontruns and negotiated returns brought recovery to roughly 73% of the $73M taken.

  16. #16 Bitfinex Multisig Compromise (Aug 2, 2016) $72M (119,756 BTC) 2016-08-02 · Exchange hack

    On August 2, 2016, Hong Kong-based exchange Bitfinex disclosed the theft of 119,756 BTC (~$72M at the time) through its BitGo-integrated multisig hot-wallet architecture. Bitfinex made customers whole via BFX tokens; US authorities later recovered most of the coins and convicted Ilya Lichtenstein of executing the theft.

  17. #17 The DAO Reentrancy Exploit (June 17, 2016) $60M 2016-06-17 · Smart-contract exploit / governance crisis

    On June 17, 2016, an attacker exploited a reentrancy vulnerability in The DAO, an Ethereum investment vehicle holding roughly 14% of all ETH, recursively withdrawing ~$60M. Ethereum's July 20, 2016 hard fork returned the ether to holders — and the un-forked chain lives on as Ethereum Classic.

  18. #18 Humanity Protocol Bridge Admin-Key Theft (June 9, 2026) $36M 2026-06-09 · Bridge / private-key compromise

    A June 5, 2026 phishing email impersonating Bithumb planted root-access malware on a Humanity Protocol employee laptop that held seven private keys, letting the attacker push a malicious bridge upgrade, drain ~141M H tokens, and mint 300M more on BNB Chain. Forensics tied the tooling to North Korean groups.

  19. #19 Step Finance Treasury Drain and Shutdown (January 31, 2026) $27M 2026-01-31 · Treasury key compromise / protocol shutdown

    Step Finance, Solana's longest-running portfolio dashboard, lost 261,854 SOL (~$27M, with ~$40M claimed across all assets) on January 31, 2026 after attackers phished executive-team devices, took over the treasury keys, unstaked the protocol's SOL, and withdrew it. The protocol announced its shutdown.

  20. #20 Truebit Legacy-Contract Mint Exploit (January 8, 2026) $26M 2026-01-08 · Legacy smart-contract exploit

    Truebit lost 8,535 ETH (~$26.4M) on January 8, 2026 — 2026's first major crypto exploit — when an attacker triggered an integer overflow in a dormant, unverified, roughly five-year-old bonding-curve contract, minting TRU for zero ETH and looping sells to drain the reserves.

  21. #21 Resolv USR Minting-Key Compromise and Depeg (March 22, 2026) $25M 2026-03-22 · Stablecoin minting-key compromise

    Resolv's USR stablecoin was exploited on March 22, 2026 after attackers compromised the AWS KMS-hosted SERVICE_ROLE minting key through a supply chain that began with a contractor's stolen GitHub credential. The attacker minted 80 million unbacked USR against under $200,000 of USDC and cashed out roughly 11,409 ETH (~$24.5M) as USR depegged.

  22. #22 Grinex Exchange Wallet Drain (April 17, 2026) $14M 2026-04-17 · Exchange hack

    Grinex, the Kyrgyzstan-incorporated successor to the sanctioned Russian exchange Garantex, was drained of ~$13.74M (on-chain ~$15M in USDT) from dozens of hot wallets on TRON and Ethereum, with the proceeds instantly swapped into non-freezable TRX. Attribution remains contested.

  23. #23 Matcha Meta / SwapNet Aggregator Arbitrary-Call Exploit (January 25, 2026) $13M 2026-01-25 · DeFi aggregator exploit (approval abuse / arbitrary call)

    On January 25, 2026, an arbitrary-call bug in SwapNet, a closed-source DEX aggregator integrated into 0x's Matcha Meta, let an attacker abuse users' standing infinite approvals and sweep ~$13.43M from about 20 wallets across Ethereum, Arbitrum, Base, and BNB Chain.

Frequently asked questions

What is the biggest crypto hack ever?

The biggest crypto hack ever is the Bybit Cold Wallet Compromise on February 21, 2025, with a loss of $1.46 billion. It is an exchange hack where a cold wallet was compromised.

How much has been stolen in crypto hacks?

According to this list of 23 tracked hacks and exploits, over $6.1 billion has been stolen. This includes both recovered and unrecovered funds.

What types of crypto hacks are most common among the largest losses?

Bridge exploits and exchange hacks dominate the list. Examples include Ronin Bridge ($620M), Poly Network ($611M), BNB Chain Token Hub ($568M), and Coincheck ($530M). DeFi and governance exploits also appear.

Have all the biggest crypto hacks been recovered?

No. While some funds were fully recovered, such as the Poly Network ($611M) and Euler Finance ($197M) exploits, most losses remain unrecovered, including the $1.46B Bybit hack.