Home › Cyber News › Crypto hacks explained
CYBER NEWS · CRYPTO

Crypto hacks explained: the biggest thefts and who is behind them

Billions of dollars of cryptocurrency are stolen every year, and a large share goes to a handful of state-backed hackers. Here is what the biggest cases show, in plain English.

Published October 9, 2026 · Written and maintained by the cyberhygiene.tools team

In this article

  • The short version
  • Bybit, February 2025: about US$1.5 billion
  • Ronin, March 2022: about US$620 million
  • The 2025 numbers at a glance
  • What this means for you
  • Sources

The short version

Dollar figures are in US dollars, as reported.

Bybit, February 2025: about US$1.5 billion

On or about February 21, 2025 attackers stole about US$1.5 billion from the exchange Bybit. It was described as the largest crypto theft recorded at that time.

Security reviews by Sygnia and Verichains, reported by BleepingComputer, found the attackers did not break Bybit's own systems directly. They first compromised a developer's computer at Safe{Wallet}, a wallet service Bybit used. That gave them access to Bybit's wallet account. They intercepted a routine transfer from its offline storage and redirected the money to wallets they controlled.

On February 26, 2025 the FBI issued a public notice naming North Korea, specifically the groups known as TraderTraitor, Lazarus Group and APT38. The FBI said the stolen funds were being converted to bitcoin and other assets and spread across thousands of addresses, and it shared a list of 51 Ethereum addresses holding stolen funds.

Ronin, March 2022: about US$620 million

On March 23, 2022 attackers stole about US$620 million from the Ronin Network. The loss was 173,600 Ether plus 25.5 million USDC. By one report the company took six days to notice. On April 14, 2022 the FBI said the Lazarus Group and APT38, which it describes as North Korean state-sponsored hackers, were responsible. The company said it later reimbursed affected users.

Some reports say part of the money was laundered through a mixing service called Tornado Cash. We have not independently verified that.

The 2025 numbers at a glance

Figures are from Chainalysis as reported by Payment Expert on December 19, 2025. Attribution to North Korea comes from the FBI and from blockchain analysts, not from a court ruling.

What this means for you

What this means for you
  • Never share your recovery phrase. Nobody legitimate will ever ask for it, including “support staff”.
  • Use a hardware wallet for any amount you cannot afford to lose, and keep the recovery phrase offline.
  • Do not leave everything on one exchange. The biggest thefts have hit exchanges and bridges, not just individuals.
  • Use an authenticator app, not text messages, for two-factor sign-in. See our two-factor guide.
  • Treat unexpected job offers, investment “opportunities” and urgent support messages as scams until proven otherwise. Check them with our phishing checker.
  • Double-check wallet addresses before sending. A single wrong character sends your money to someone else, and it cannot be reversed.

This page is general safety information, not financial advice, and we are not licensed financial advisers.

Sources

Published October 9, 2026. We only include facts we could confirm in the sources above, and we say clearly where something is reported but not confirmed.


Frequently asked questions

What was the biggest crypto hack ever?

The Bybit theft of about US$1.5 billion on or about February 21, 2025, which the FBI attributed to North Korea.

Who is behind the biggest crypto thefts?

The FBI has attributed both the Bybit and Ronin thefts to North Korean state-sponsored groups known as Lazarus Group, TraderTraitor and APT38.

How do hackers steal from crypto exchanges?

Often by compromising a person or a supplier first. In the Bybit case, attackers compromised a developer's computer at a wallet service and used it to slip in a disguised transaction.

How can I keep my crypto safe?

Never share your recovery phrase, use a hardware wallet, use an authenticator app for sign-in, avoid keeping everything on one exchange and check wallet addresses carefully.