Skip to content
← Back to newsWeb3 Suffers Record Losses: North Korean Hackers and Weak Key Security Blamed
Security

Web3 Suffers Record Losses: North Korean Hackers and Weak Key Security Blamed

By dAppConNewcomer20 rep· 12/29/2025

Web3 platforms experienced a staggering $3.95 billion in losses in 2025, a significant increase from the previous year. A new report from Hacken highlights that over half of these losses are directly linked to North Korean threat actors, with poor key management and operational security failures being the primary drivers, rather than simple coding errors.

 

Key Takeaways

  • Total Web3 losses reached approximately $3.95 billion in 2025, an increase of $1.1 billion from 2024.

  • North Korean-linked threat actors are responsible for over half of the total stolen funds.

  • Access control failures and operational security breakdowns accounted for $2.12 billion, significantly more than smart contract vulnerabilities.

  • The Bybit breach, a single theft of nearly $1.5 billion, is the largest on record and a major contributor to the overall losses.

 

Access Control Over Code

The Hacken 2025 Yearly Security Report reveals a concerning trend: access control failures and broader operational security breakdowns were responsible for approximately $2.12 billion, or nearly 54% of all losses. This starkly contrasts with the $512 million attributed to smart contract vulnerabilities. The report emphasizes that systemic operational risks, such as weak keys, compromised signers, and inadequate off-boarding procedures, are the leading causes of the most significant and unrecoverable losses.

 

Regulatory Lag and Industry Practices

Despite regulators in major jurisdictions outlining clear security requirements like role-based access control, secure onboarding, and institutional-grade custody solutions, many Web3 companies continue to employ insecure practices. Yehor Rudystia, Head of Forensic at Hacken Extractor, noted that common issues include failing to revoke developer access upon off-boarding, using single private keys for protocol management, and lacking robust Endpoint Detection and Response systems. Rudystia stressed the importance of regular penetration tests, incident simulations, custody control reviews, and independent audits, especially for large exchanges and custodians.

 

Moving Towards Hard Requirements

Hacken anticipates a further tightening of security standards as supervisors transition from soft guidance to mandatory requirements. Yevheniia Broshevan, Hacken's Co-founder and CEO, highlighted the opportunity for the industry to elevate its security baseline by adopting clear protocols for dedicated signing hardware and implementing essential monitoring tools. The report also calls for regulators and law enforcement to treat North Korean threat actor playbooks as a specific supervisory concern, advocating for real-time threat intelligence sharing and threat-specific risk assessments focused on phishing-led access attacks.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Web3 Suffers Record Losses: North Korean Hackers and Weak Key Security Blamed | BlockzHub