Web3 security failures worsened in 2025, not because of novel smart contract bugs, but due to persistent weaknesses in operational security. According to Hacken’s 2025 Yearly Security Report, total losses across the crypto sector reached approximately $3.95 billion, up by more than $1 billion from the previous year. Just over half of that damage was attributed to threat groups linked to North Korea.

While the scale of losses has drawn attention, Hacken says the more important takeaway is structural. The bulk of the damage came from compromised access controls, poorly managed private keys and human operational failures, rather than flaws in protocol code.

Losses surged early, then eased — but risks remain

Hacken’s data shows that Web3 losses peaked in the first quarter of 2025 at more than $2 billion, before declining steadily to roughly $350 million by the fourth quarter. The drop suggests that some defensive measures improved over time, but the firm cautions against interpreting the trend as a resolution.

Instead, the pattern reflects recurring weaknesses in how Web3 organizations manage access, custody and internal controls. These failures, Hacken argues, create conditions where large, irreversible losses remain possible even without sophisticated technical exploits.

Operational security failures dominate damage

Access control failures accounted for the majority of losses in 2025. Hacken estimates that compromised keys, signer abuse and broader operational security breakdowns led to about $2.12 billion in stolen funds, representing nearly 54% of total losses. By comparison, smart contract vulnerabilities contributed roughly $512 million.

The largest single incident, the $1.5 billion Bybit breach, played a major role in skewing the data. Hacken attributes the attack to North Korea-linked actors and describes it as the biggest crypto theft on record. As a result, North Korean clusters were responsible for roughly 52% of all stolen funds tracked in the report.

The findings reinforce a long-standing concern within the security community: while smart contract audits have improved, internal security practices have not kept pace.

Source: Mike Pompeo

Regulatory expectations are clear — enforcement is not

Yehor Rudystia, head of forensic analysis at Hacken Extractor, said regulators in the United States, European Union and other major jurisdictions have increasingly outlined what acceptable security looks like. These frameworks commonly include role-based access controls, detailed logging, secure onboarding and off-boarding processes, institutional-grade custody models such as hardware security modules, multi-party computation and multisignature wallets, as well as continuous monitoring systems.

However, Rudystia said many Web3 firms continued to operate below those standards throughout 2025.

Common failures included developers retaining access long after leaving a project, protocols controlled by a single private key, and the absence of endpoint detection and response systems. These weaknesses, he said, left platforms exposed to both insider threats and phishing-driven external attacks.

From guidelines to enforceable standards

Hacken expects regulators to take a firmer stance in 2026, moving from nonbinding guidance to enforceable requirements. Yevheniia Broshevan, Hacken’s co-founder and CEO, said the industry now has an opportunity to raise its security baseline by standardizing practices around signing hardware, monitoring tools and custody controls.

She added that clearer regulatory mandates could help normalize stronger security practices across exchanges, custodians and infrastructure providers.

Given the scale of North Korea-linked activity, Rudystia also called for more targeted regulatory responses. He argued that supervisors should mandate real-time threat intelligence sharing, require risk assessments focused specifically on phishing-led access attacks, and introduce penalties for platforms that fail to implement basic defenses. At the same time, he suggested offering safe-harbor protections to firms that fully comply and actively participate in coordinated defense efforts.