According to recent data from CryptoComLearn, crypto hackers have stolen a total of $17.1 billion across 518 incidents over the past decade (2016–2026). The overwhelming majority of losses occurred in the latter half of the period, signaling an escalating security crisis.
Over $15.2B Lost Since 2021
Between 2021 and 2026, more than 450 hacking incidents drained approximately $15.2 billion—representing over 88% of the decade's total. In the most recent 12-month span (April 2025 to April 2026), 140 attacks resulted in $2.5 billion in losses. The frequency and severity of attacks continue to rise.
Attack Vector Shift: Private Keys & Access Control
Researchers observed a clear shift in tactics: from exploiting smart contract vulnerabilities to targeting private key exposures and access control breaches. This means even well-audited projects are vulnerable if key management or permission settings are weak. Recent incidents illustrate this trend, including the Inertia exploit (ERC4626 flaw, $152K), the Squid cross-chain protocol hack ($3M), and the WUSD/GLOVE pair exploit on Ethereum ($207K).
Growing Security Challenges
Beyond code-level attacks, physical coercion (e.g., the rise of "wrench attacks" in France) and social engineering are also on the rise. Verus Bridge recovered $8.5M via negotiation, but many funds remain untraceable. Exchanges and projects are urged to adopt multi-signature wallets, hardware security modules, and rigorous access audits. Users should avoid relying on single authentication methods and securely back up private keys.
CryptoComLearn analysts note that as the crypto market cap expands, the incentives for hackers grow. The industry must collaboratively establish stricter security standards, enhance insurance mechanisms, and strengthen anti-money laundering protocols to counter these evolving threats.

