Finder makes money from featured partners, but editorial opinions are our own. Advertiser disclosure

List of the biggest crypto hacks

We took a look at 8 major crypto hacks and offer a tip to help you avoid becoming a victim of one.

Crypto is still very much the Wild West of finance. Hacks and exploits still plague the space, with the most recent one being a $70 million exploit at Curve Finance. And 2022 being the biggest year ever for crypto hacking.

In this report, we look at some of the biggest crypto hacks of all time and offer a tip on what you can do to avoid becoming a victim of a crypto hack.

8 of the biggest crypto hacks in history

1. Ronin network
2. Bitfinex
3. MyEtherWallet
4. Tesla
5. Solana
6. Harmony network
7. Bancor
8. FTX

Crypto hacks at a glance

  • Crypto hacks remain a notable roadblock to broader blockchain adoption.
  • Hacks can occur on multiple levels in the crypto space — from blockchain bridges to centralized exchanges to hot wallets.
  • Use a hardware wallet to store the private keys to your crypto offline to mitigate the risk of being hacked.

1. Ronin network

On March 23, 2022, hackers stole approximately $625 million in Ethereum (ETH) and USD Coin (USDC) from Ronin, the Ethereum-linked sidechain connected to the popular Axie Infinity online game. The hackers — who were part of the North Korean state-backed hacking collective Lazarus Group — exploited a blockchain bridge, which enables users to transfer assets from one blockchain to another.

The hack remains the largest in the history of crypto. While the US Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned the Ethereum wallet associated with the hack, and while Binance recovered $5.8 million of the stolen funds, the vast majority was never recovered.

2. Bitfinex

In August 2016, 119,754 Bitcoin (BTC) were stolen from the crypto exchange Bitfinex after a hacker breached the exchange’s security system and made more than 2,000 unauthorized transactions. At the time of the hack, the amount of BTC stolen was worth about $72 million, while that value is currently well over $3 billion.

In February 2022, the US Department of Justice arrested the two people behind the hack and stated that it had recovered over 75% of the stolen funds. In a press release, the agency noted that blockchain technology helped law enforcement to follow the money and bring those using cryptocurrency for illicit purposes to justice.

3. MyEtherWallet

In April 2018, MyEtherWallet (MEW) — an app for storing, sending and receiving Ethereum (ETH) and Ethereum-based tokens — was compromised by a phishing attack. Hackers stole just over 216 ETH — worth approximately $150,000 at the time — by hijacking a Google Domain Name System (DNS) server the Ethereum network employed.

MyEtherWallet’s CEO and team responded swiftly, remedying the issue and sharing information to help users secure their funds and mitigate losses. MEW’s CEO added that Ethereum users should use a hardware wallet to safely store and manage their assets.

4. Tesla

In February 2018, Tesla fell victim to a “cryptojacking”. A cryptojacking is a cybercrime in which hackers take over people’s computers or servers and use them to mine cryptocurrency. Hackers infiltrated Tesla’s Kubernetes administration console — an open-sourced, Google-designed system for cloud applications — which wasn’t password protected at the time.

The hackers used this system to illegally mine cryptocurrency in a way that made their IP addresses difficult to detect. The issue was rectified, and no consumer data or information regarding the safety and security of Tesla vehicles was stolen.

5. Solana

In August 2022, over 9,000 wallets on the Solana network were hacked, with approximately $4 million worth of SOL — the native asset of the Solana blockchain — and USD Coin (USDC) being stolen. Hackers exploited the private keys for the Slope wallet, a software wallet for assets on the Solana blockchain.

Some users of Phantom — one of the most popular Solana wallets — also had their funds drained. However, only those who imported their accounts to and from Slope were affected. Days after the hack, Solana issued a statement telling users to create new wallets and transfer their assets out of their old, potentially compromised wallets to mitigate further damage.

6. Harmony network

In June 2022, hackers from the North Korean state-backed hacking collective Lazarus Group exploited the Horizon bridge — a bridge that connects the Harmony blockchain to Ethereum, BNB Chain and Bitcoin — stealing $100 million worth of digital assets. This attack brought the total amount stolen from blockchain bridges in 2022 to over $1 billion, all before the year’s halfway point.

The hackers executed the attack by using compromised private keys to drain assets, including Binance USD (BUSD), USD Coin (USDC), Ethereum (ETH) and Wrapped Bitcoin (WBTC). The hackers swapped the non-ETH assets for ETH and then put the ETH through the Tornado Cash mixer to launder the funds. The Tornado Cash mixer is a privacy service that removes any connection to the address from which wallet funds were sent and is now outlawed by the US government.

7. Bancor

In July 2018, hackers stole $23.5 million in digital assets from a compromised wallet tied to the decentralized exchange (DEX) Bancor, which exists on Ethereum. The hackers made off with 3.2 million Bancor Network tokens (BNT), 25,000 Ethereum (ETH) and 230 million Pundi X tokens (NPXS).

To mitigate the damage, the DEX froze the stolen BNT funds — which called into question just how “decentralized” the network really is. However, it didn’t have the power to free the stolen ETH or NPXS.

No user funds were stolen in this hack.

8. FTX

Hours after FTX declared bankruptcy on November 11, 2022, more than $600 million worth of digital assets was extracted from FTX crypto wallets. Some speculated that members of disgraced former FTX CEO Sam Bankman-Fried’s inner circle siphoned the funds through a back door, though this has yet to be confirmed.

The day after the hack, Nick Percoco, chief security officer at the crypto exchange Kraken, claimed that he knew the identity of the hacker because of a mistake the hacker made in sending Tron (TRX) tokens from Kraken to the same crypto wallet address to which some of the hacked funds were sent. The hacker’s identity has yet to be made public, though, and US authorities are still investigating the case and pursuing the hacker.

How to keep your cryptocurrency safe from hackers

One of the most tried and true ways to keep your crypto safe from hackers is to keep your private keys stored offline in a crypto hardware wallet.

When you leave your crypto assets in the custody of either a centralized crypto exchange like Bitfinex or a hot wallet like Slope, you increase your risk of losing access to your digital assets due to a hack.

Bottom line

Over the years, billions of dollars worth of digital assets have been stolen in crypto hacks, and crypto hacks still pose notable danger to crypto investors and blockchain users.

To mitigate the risks of becoming a victim of a crypto hack, consider using a crypto hardware wallet to store the private keys to your digital assets offline.

Frequently asked questions

  • Disclaimer: This page is not financial advice or an endorsement of digital assets, providers or services. Digital assets are volatile and risky, and past performance is no guarantee of future results. Potential regulations or policies can affect their availability and services provided. Talk with a financial professional before making a decision. Finder or the author may own cryptocurrency discussed on this page.

Frank Corva is a cryptocurrency writer and analyst for digital assets at Finder. Frank has turned his hobby of studying and writing about crypto into a career with a mission of educating the world about this burgeoning sector of finance.

More guides on Finder

Ask a question

Finder.com provides guides and information on a range of products and services. Because our content is not financial advice, we suggest talking with a professional before you make any decision.

By submitting your comment or question, you agree to our Privacy and Cookies Policy and finder.com Terms of Use.

Questions and responses on finder.com are not provided, paid for or otherwise endorsed by any bank or brand. These banks and brands are not responsible for ensuring that comments are answered or accurate.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Go to site