Highlights:
- Crypto hacks caused $2.87B in losses across nearly 150 incidents during 2025.
- Bybit’s $1.46B breach accounted for 51% of all crypto hack losses in 2025.
- DeFi median losses fell 75%, from $6M in 2022 to $1.5M in 2025.
The crypto insurance problem remains a concern as major security breaches continue to test the financial protection available across digital assets. Hackers stole $2.87 billion across nearly 150 incidents in 2025, according to TRM Labs. The total included smart-contract exploits, infrastructure breaches, and compromises involving wallets and operational systems.
The February 2025 Bybit breach accounted for $1.46 billion of those losses, representing 51% of all crypto funds stolen through hacks during the year. TRM also found that the ten largest incidents produced 81% of total annual losses, while five incidents alone accounted for 70% of the stolen value.
Crypto Insurance Problem Changes as Attack Methods Shift
TRM reported that institutional attacks accounted for most crypto hack losses in 2025. These incidents targeted private keys, wallets, access controls, and other operational systems. As a result, institutional breaches overtook smart-contract exploits as the leading source of losses in TRM’s dataset.
Separate research from Immunefi showed a different trend across decentralized finance protocols. DeFi protocol losses declined from $2.62 billion in 2022 to $534 million in 2024 before rising to $680 million in 2025. Several large incidents accounted for a significant portion of that increase.
The median loss per DeFi incident also declined over the period. Immunefi recorded a median loss of $6 million in 2022. By 2025, that figure had fallen to $1.5 million, a 75% decrease.
Several established attack categories also represented a smaller share of DeFi losses. Flash-loan oracle manipulation and reentrancy attacks accounted for nearly 19% of losses in 2022, but their combined share fell below 1% by 2025.
Bridge incidents followed a similar pattern. They accounted for 73% of DeFi losses in 2022 but only 3% in 2025. Meanwhile, private-key compromises represented 8.1% of DeFi protocol losses in 2025.
Outside DeFi protocols, however, infrastructure-related losses remained substantial. Immunefi said centralized exchanges suffered more than $1.6 billion in infrastructure-class losses during 2025, with the Bybit breach accounting for most of that amount.
Billion-Dollar Hacks Test Available Insurance Capacity
The changing loss profile also highlights the limits of insurance capacity available to digital-asset businesses. Aon reports that it has secured $4 billion in digital-asset insurance limits across its work in the sector. The broker also reports more than $1.2 billion in available capacity for an individual client.
These figures refer to insurance limits that have been secured or capacity that is available, rather than blanket coverage across the crypto market. Policies remain specific to individual clients, insured risks, exclusions, and agreed limits. A company’s total digital-asset holdings can therefore exceed the amount protected by its insurance arrangements.
Aon has previously highlighted this capacity gap in its research on cryptocurrency custody. The company noted that some custodians hold tens of billions of dollars in digital assets while the insurance market cannot provide equivalent coverage at those levels.
Coverage Depends on the Risk and Policy Limits
The crypto insurance problem therefore extends beyond the number of hacks recorded each year. Whether a loss is covered depends on the nature of the incident and the terms of the relevant policy, including insured events, exclusions, deductibles, and maximum limits.
Security data from TRM and Immunefi shows why that distinction has become increasingly important. Several traditional DeFi attack categories declined between 2022 and 2025, while infrastructure-related incidents accounted for a larger share of major losses across the broader crypto sector.
The concentration of losses adds another challenge. Bybit alone accounted for more than half of all hack-related losses recorded by TRM during 2025, while the ten largest attacks generated more than four-fifths of the annual total.








