According to a recent blockchain security report, May 2025 saw a notable decrease in total losses from cryptocurrency hacking incidents compared to April, with one major event accounting for nearly 90% of the month’s losses.
This decline coincides with the crypto industry’s intensified efforts to strengthen defenses against malicious actors. Blockchain security firm PeckShield reported approximately 20 significant crypto hacking incidents in May, resulting in a total loss of $244.1 million—a 39.29% decrease from the previous month.
Largest May Hack Sees Majority of Funds Frozen
The most severe incident occurred on May 22, when the decentralized exchange Cetus was exploited, leading to user losses of up to $223 million within 24 hours.
Security analysts at Dedaub identified that the attacker exploited a vulnerability in the most significant bit (MSB) checking mechanism. By manipulating liquidity parameter values and changing their order of magnitude, the hacker was able to establish large positions with minimal operations.
PeckShield’s data also indicated that Cetus and the Sui network successfully froze $157 million of the stolen funds, recovering approximately 71% of the total amount stolen.
The second-largest attack in May targeted the DeFi platform Cork Protocol, resulting in a loss of $12 million. Cybersecurity firm Cyvers reported that the attacker exploited a vulnerability to steal around 3,761 wstETH tokens, which were later converted into Ethereum (ETH).
The remaining three of the top five hacks in May included:
- A suspected North Korea-linked exploit resulting in $5.2 million in losses
- A $2.2 million attack targeting the MBU token
- A $1.2 million loss due to an exploit in MapleStory Universe
Crypto Industry Strengthens Anti-Hacking Measures
These incidents come at a time when the cryptocurrency sector is actively enhancing its security infrastructure to defend against cybercriminals.
On May 31, BitMEX’s security team launched a counter-reconnaissance operation against the North Korean state-sponsored hacking group Lazarus. The operation successfully identified weaknesses in the group’s operational security, exposing critical information such as IP addresses, database structures, and tracking algorithms.
In the first quarter of 2025, hackers stole more than $1.63 billion in cryptocurrency. PeckShield highlighted that the attack on the Bybit platform accounted for over 92% of these losses.
The security firm also reported that January 2025 saw cryptocurrency hacking losses exceeding $87 million, while February experienced a dramatic surge to $1.53 billion, largely due to the major attack on Bybit—one of the largest crypto thefts recorded to date.
👉 Explore real-time security tools and strategies
Frequently Asked Questions
What caused the decrease in crypto hacking losses in May 2025?
The decline is attributed to improved security protocols across exchanges and DeFi platforms, as well as faster response times in freezing stolen assets. Industry-wide collaboration and enhanced monitoring tools also played a significant role.
How are stolen cryptocurrencies recovered?
Recovery often involves coordination between security firms, blockchain networks, and exchanges to trace and freeze stolen funds. In many cases, rapid response allows authorities to prevent hackers from cashing out stolen assets.
What are common vulnerabilities exploited in crypto hacks?
Frequent targets include smart contract flaws, governance mechanisms, liquidity parameter manipulations, and private key compromises. Regular audits and real-time monitoring are essential to mitigate these risks.
Is the crypto industry becoming more secure?
Yes. The increasing implementation of advanced security measures, industry-wide information sharing, and regulatory compliance efforts are contributing to a more resilient ecosystem against attacks.
What should users do to protect their crypto assets?
Users should enable two-factor authentication, use hardware wallets for large holdings, avoid sharing private keys, and only interact with audited and reputable platforms.
Are decentralized exchanges more vulnerable than centralized ones?
Both face unique risks. While centralized exchanges are targets for large-scale breaches, decentralized platforms are often exposed to smart contract exploits. Users should research platforms thoroughly and prioritize those with strong security records.