Institutions came back to crypto in 2025. But the year also revealed just how fragile the underlying infrastructure remains. Illicit actors stole $3.4 billion, according to Chainalysis data. This isn’t just financial damage, it is a signal that the criminal playbook has changed.

The industry has moved beyond simple, opportunistic code exploits. Instead, we are seeing industrial-scale theft. Sophisticated groups have turned to “big game hunting,” targeting centralized platforms and high-net-worth individuals with a level of coordination typically reserved for nation-state espionage.

2025 Crypto Losses Hit $3.4 Billion

The aggregate loss figure, hovering near $3.4 billion and $4 billion depending on the forensic methodology applied by Chainalysis and Hacken, was driven largely by a few catastrophic events rather than a high volume of smaller hacks.

Image Credit: Binance 

The scales tipped in February. The Bybit hack alone wiped out nearly $1.5 billion in Ethereum and accounted for roughly 44% of the year’s stolen funds. This proves the threat has moved. Hackers aren’t just looking at DeFi protocols anymore; they are hunting centralized infrastructure.

Image Credit: Binance 

This shift aligns perfectly with the methods of advanced persistent threats. TRM Labs and Elliptic data suggest that North Korean-linked actors, including the Lazarus Group, stole an estimated $2-$2.7 billion, 52% of the year’s total. Hackers stopped trying to break the code and started targeting the people. Today’s groups favor social engineering, often infiltrating IT teams directly to seize signing keys. These infrastructure attacks prove a hard truth: the human element is still the most fragile point in the security stack.

Yet, amid this turbulence, internal data from major infrastructure providers suggests that security at the top tier is hardening, creating a divergence in the market. Binance’s 2025 Year In Review report offers a counter-narrative to the industry-wide losses. The exchange cut its direct exposure to illicit fund categories by 96% from 2023 to 2025. Beyond that, its risk systems blocked an estimated $6.69 billion in potential fraud, keeping 5.4 million users safe throughout the year.

Image Credit: Binance 

The takeaway is clear: even as global theft numbers remain high, the largest platforms are successfully turning their ecosystems into hostile territory for illicit activity. Noah Perlman, Chief Compliance Officer at Binance, points to this decoupling of volume and risk as a critical metric for the industry’s maturity.

“Analysis of independent industry data shows a steep reduction in our direct illicit exposure between early 2023 and mid-2025,” Perlman stated, emphasizing that security protocols are holding up under stress. “Even as Binance handled growing volumes comparable to the next six largest exchanges combined,” he noted, the platform processed more legitimate activity while effectively filtering out bad actors.

The Rising Rate of Attacks Serves as a Lesson for Industry Players

If 2025 proved anything, it is that reactive security is dead. The threat market has moved on, weaponizing artificial intelligence to devastating effect.

AI has made crime more efficient. Chainalysis found that AI-enabled scams were 4.5 times more profitable than standard variations last year. These tools allow criminals to scale deepfakes and phishing attacks that fool even savvy users, leaving exchanges with no choice but to change tactics. The industry’s answer is defense-in-depth.

The industry has realized that waiting for cold storage is often too slow. Specialists emphasize real-time analytics to spot drains the moment they happen. Parallel to this, we are seeing a structural upgrade across exchanges and custodians, with Multi-Party Computation (MPC) and Hardware Security Modules (HSM) becoming standard to ensure no single point of failure remains exposed.

This hardening of infrastructure often tracks with stricter regulations. Frameworks like the Abu Dhabi Global Market (ADGM), which Binance recently secured, demand rigorous standards for custody, governance, and risk management. It effectively compels platforms to bring their defensive architecture up to institutional grade.

But the only way to fight AI is with AI. Platforms are deploying machine learning to catch what human analysts miss. Binance provides a clear example. The exchange now relies on over 100 AI models to police fraud, a network that supported more than 71,000 law enforcement requests just last year. However, capability brings responsibility. This means strict oversight is non-negotiable to ensure these safety measures don’t erode user privacy.

Resilience as the New Standard

The year 2025 demonstrated that while big game hunters have industrialized theft, top-tier infrastructure providers have successfully decoupled user growth from crime rates. The dichotomy of the year, record losses driven by a few massive breaches alongside record fraud prevention stats, suggests the industry is bifurcating into secure, regulated zones and vulnerable targets.

As the global crypto population surpasses 560 million users, the stability of the crypto market will rely on this convergence of strict regulatory frameworks, advanced AI defense systems, and the relentless hardening of custodial infrastructure. The lesson of 2025 is clear: security must evolve from a feature into the very foundation of the ecosystem.

Disclaimer: GeekWire newsroom and editorial staff were not involved in the creation of this content..