One year ago this week, North Korea's Lazarus Group executed the largest digital heist in history — $1.5 billion stolen from Bybit through a compromised developer laptop, not a smart contract exploit. That single incident reshaped the threat model for the entire industry. Twelve months later, the...
"Despite 2025 being the worst year for hacks on record, those hacks stem from Web2 operational failures, not onchain code. The human factor is now the weak link." — Mitchell Amador, CEO, Immunefi
One year ago this week, North Korea's Lazarus Group executed the largest digital heist in history — $1.5 billion stolen from Bybit through a compromised developer laptop, not a smart contract exploit. That single incident reshaped the threat model for the entire industry. Twelve months later, the data confirms a structural shift: crypto's security crisis is no longer about code. It's about people.
The numbers are staggering. In 2025, total crypto theft reached $3.4 billion across hacking alone, while broader illicit flows hit $154–158 billion according to Chainalysis and TRM Labs. North Korean hackers stole $2 billion, a 51% year-over-year increase. But the most alarming signal arrived in January 2026: $370 million stolen in a single month, with $311 million — 84% — coming from phishing attacks, not protocol exploits. The attack surface has moved from Solidity code to human psychology, and the industry's defenses haven't caught up.
The institutional response is accelerating. TRM Labs closed a $70 million Series C at a $1 billion valuation in February 2026, backed by Goldman Sachs and Citi. CertiK now secures over $600 billion in digital assets. But the fundamental asymmetry persists: attackers need to find one human weakness; defenders must secure every endpoint, every signer, every developer laptop in the chain. This report examines where the threat landscape stands, why the shift from code to people changes everything, and what the industry's response means for the economic architecture of Web3.
On February 21, 2025, hackers compromised a single developer's laptop at Safe{Wallet}, the multi-signature wallet provider used by Bybit for institutional custody. They didn't exploit a smart contract vulnerability. They didn't find an on-chain logic error. Instead, they injected malicious JavaScript into Safe's frontend code, making a fraudulent transaction appear legitimate to Bybit's multi-signature signers. The result: 401,347 ETH — approximately $1.5 billion — redirected to attacker-controlled addresses.
The FBI attributed the attack to North Korea's Lazarus Group (also known as TraderTraitor, APT38, and BlueNoroff) within five days. By March 20, 2025, CEO Ben Zhou reported that 86.29% of the stolen ETH had already been converted to Bitcoin through decentralized exchanges, cross-chain bridges, and thousands of intermediary wallets. As of the most recent updates, 27.6% of the stolen funds remain untraceable.
What made Bybit architecturally significant wasn't the dollar amount — it was the attack vector. Multi-signature wallets were supposed to be the gold standard of institutional security. The Bybit hack proved that when the UI layer between humans and the blockchain can be compromised, even a 3-of-5 multisig offers no protection. The signers approved exactly what they saw on screen. What they saw was a lie.
Bybit's response was remarkable — the exchange fully restored liquidity within 72 hours without halting withdrawals, implemented 50 security upgrades, and maintained operations through what would have been an extinction event for most platforms. But the lesson was already written: the weakest link in crypto security isn't the chain. It's the human at the keyboard.
The Chainalysis 2026 Crypto Crime Report, released in January, paints a sobering picture of 2025. Illicit cryptocurrency addresses received at least $154 billion, a 162% increase year-over-year. TRM Labs independently estimated $158 billion, confirming the order of magnitude. While much of this surge was driven by a 694% increase in sanctioned entity transactions (overwhelmingly Russia-linked flows through the ruble-backed stablecoin A7A5), the hacking and scam vectors tell their own story.
Key 2025 statistics:
| Category | Value | YoY Change | |----------|-------|------------| | Total illicit crypto flows | $154–158B | +145–162% | | Hacking losses | $3.4B | Significant increase | | DPRK-linked theft | $2.0B | +51% | | Scams and fraud | $17B | — | | Impersonation scam growth | — | +1,400% | | Stablecoin share of illicit volume | 84% | — |
Two structural shifts stand out. First, scams and social engineering now generate more illicit revenue than protocol exploits. Impersonation scams surged 1,400% year-over-year, with AI-enabled schemes proving 4.5 times more profitable than traditional methods. Second, Chinese-language money laundering networks processed $16.1 billion in illicit crypto — approximately $44 million per day across 1,799+ active wallets — functioning as what TRM Labs calls global "illicit settlement infrastructure."
The professionalization is the point. Crypto crime is no longer the domain of lone hackers. It's an industry with specialized service providers: phishing-as-a-service toolkits, professional money laundering networks, AI-generated deepfakes for impersonation, and nation-state operators with military-grade capabilities.
If the Bybit hack was the wake-up call, January 2026 was the alarm that wouldn't stop ringing. CertiK reported $370.3 million in total cryptocurrency losses — the highest monthly total in 11 months, representing a 214% increase from December 2025.
The composition of those losses tells the story:
This ratio represents a fundamental inversion. Through 2023–2024, DeFi protocol exploits dominated the loss landscape — re-entrancy attacks, flash loan manipulations, oracle price manipulation. Security firms built their entire business models around smart contract auditing. But the attackers pivoted faster than the defenders.
The shift makes economic sense from an attacker's perspective. Exploiting a smart contract requires deep technical expertise, custom tooling for each target protocol, and operates in an environment where code is public and audited. Phishing a wallet signer requires a convincing email, a spoofed URL, and patience. The skill-to-reward ratio favors social engineering by an order of magnitude.
February 2026 has continued the pattern. The Flow blockchain suffered a $3.9 million exploit that led to a controversial six-hour transaction rollback. CrossCurve lost $3 million to a bridge vulnerability. And Safe{Wallet} flagged and removed approximately 5,000 malicious addresses in a large-scale address poisoning campaign targeting multisig users — the same infrastructure category that enabled the Bybit breach.
The geopolitical dimension of crypto security cannot be overstated. North Korean hackers stole $2.02 billion in cryptocurrency in 2025 alone, pushing their cumulative all-time total to approximately $6.75 billion. The Bybit hack — a single incident — exceeded the approximately $800 million attributed to North Korea across all of 2024.
US and UN officials now openly state that crypto theft has become a primary funding mechanism for North Korea's weapons of mass destruction programs. The CSIS and Wilson Center have both published detailed analyses of how stolen crypto flows into Pyongyang's missile and nuclear programs through a sophisticated chain of decentralized exchanges, cross-chain bridges, and "Chinese laundromats" — contracted money laundering networks that use chain-hopping and wallet fragmentation to obscure the trail.
In February 2026, Lazarus Group launched "XPACK ATTACK" — a campaign embedding malicious packages in npm and PyPI repositories, targeting developers through fake recruitment schemes. Fireblocks CEO flagged a parallel operation targeting LinkedIn profiles with fraudulent crypto job offers. The attack surface has expanded from exchange infrastructure to the developer supply chain itself.
The 38 North research institute characterized this evolution bluntly: North Korea has transformed from a "digital kleptocracy" to a "rogue crypto-superpower." The distinction matters. This isn't opportunistic theft. It's a systematic, state-directed extraction of economic value from the crypto ecosystem to fund geopolitical objectives.
The market's response to escalating threats has been a dramatic capital inflow into blockchain security and intelligence infrastructure.
TRM Labs closed a $70 million Series C on February 4, 2026, at a $1 billion valuation — achieving unicorn status. The round was led by Blockchain Capital with participation from Goldman Sachs, Citi Ventures, Bessemer Venture Partners, Thoma Bravo, and Brevan Howard. TRM now covers 150 blockchains with 350 employees and total funding of $220 million. The participation of Goldman Sachs and Citi signals that traditional finance views blockchain forensics as critical infrastructure, not a niche service.
CertiK has grown to serve over 5,000 enterprise clients with more than 5,900 smart contract audits, securing over $600 billion in digital assets. Hacken has conducted over 2,300 audits and verified $430 billion through Proof of Reserves. The audit sector has expanded from a pre-launch checkbox to a continuous compliance requirement.
On the custody side, the market is maturing rapidly. Coinbase Prime now safeguards more than 70% of US-based crypto ETFs. Fidelity Digital Assets offers a 0.39% probability-of-default rating with OCC federal charter status. Crypto.com maintains approximately $750 million in cold-storage insurance plus $120 million for institutional custody. Agio Ratings has introduced formal default risk assessment models — the kind of infrastructure that signals an industry moving from "move fast and break things" to "measure, price, and mitigate risk."
The security industry's growth is itself an economic value signal. When Goldman Sachs backs a blockchain forensics startup at a $1 billion valuation, it's pricing the expected growth of illicit flows alongside legitimate adoption. The security layer is becoming a permanent tax on the crypto ecosystem — necessary, but value-extractive.
Viewed through the economic value distribution lens, the security crisis represents a massive, underappreciated friction cost in the Web3 ecosystem. The $3.4 billion stolen through hacking in 2025 is the visible number. The invisible costs — insurance premiums, audit fees, custody overhead, user friction from security measures, lost institutional confidence, regulatory burden triggered by high-profile breaches — likely exceed the direct losses by a factor of 5–10x.
Consider the full cost stack of a single institutional custody arrangement in 2026: multi-signature wallet infrastructure, hardware security modules, transaction simulation and verification layers, ongoing smart contract audits, blockchain monitoring subscriptions, insurance coverage (BitGo at $250M, Gemini at $125M, Crypto.com at $750M+), and compliance personnel. These costs are real economic value extracted from every transaction, every fund, every protocol that touches institutional capital.
The Bybit hack alone triggered an industry-wide reassessment of multisig security, with protocols and exchanges spending millions on upgraded signing infrastructure, UI verification layers, and supply-chain security for wallet providers. That's economic value that could have gone into protocol development, user acquisition, or yield generation — redirected instead into defensive infrastructure because of a single compromised laptop.
For the economic architecture of Web3 to mature, the security cost curve must bend downward relative to the value secured. Currently, it's bending the wrong way.
The attack surface has migrated from code to people. In January 2026, 84% of crypto losses ($311M of $370M) came from phishing, not protocol exploits. The industry's audit-centric security model was built for a threat that is rapidly becoming secondary.
North Korea has industrialized crypto theft. With $6.75 billion stolen cumulatively and $2 billion in 2025 alone, DPRK-linked groups operate at nation-state scale with military-grade sophistication, now targeting the developer supply chain through npm/PyPI poisoning campaigns.
The security industry is scaling fast but remains asymmetric. TRM Labs' $1 billion valuation and Goldman Sachs backing signal institutional commitment, but the defender's burden (secure everything) vs. the attacker's advantage (find one weakness) remains structurally unfavorable.
Illicit flows hit $154–158 billion in 2025, with stablecoins accounting for 84% of illicit volume and Chinese-language laundering networks processing $16.1 billion — functioning as crypto crime's "clearing house."
Security costs are a growing tax on the ecosystem's economic value, redirecting capital from productive use to defensive infrastructure. The cost curve is moving in the wrong direction.
The Bybit hack's one-year anniversary arrives at a moment when the data makes one thing unambiguously clear: the crypto industry's security problem has been redefined. The smart contract exploits that dominated 2021–2024 are being eclipsed by social engineering, supply-chain attacks, and state-sponsored operations that target the humans operating the infrastructure rather than the infrastructure itself.
This is simultaneously bad news and, paradoxically, a sign of progress. On-chain code is getting harder to exploit — Immunefi's Amador projects 2026 as "the best year yet for on-chain security." The code is winning. But the victory is hollow if the people deploying, signing, and administering that code remain the path of least resistance.
The industry's response — billion-dollar security firms, institutional-grade custody, formal risk assessment models — is real and accelerating. But it's a response built for the last war as much as the next one. The next frontier is AI-enabled attacks, autonomous agent exploitation, and deepfake-powered social engineering at a scale that manual security processes cannot match.
For Web3 to fulfill its promise as an open, permissionless financial system, the security layer must achieve the same level of decentralized resilience as the consensus layer. Right now, it hasn't. And at $370 million per month, the clock is running.