Published analysis puts 2025 losses across cryptocurrency platforms at approximately $3.4 billion over more than 300 incidents, with social engineering and access-control failures identified as the dominant causes.
The Mathematics Was Never The Weak Part
The signature schemes held. The hash functions held. In the largest incident of the year, at 25-0221, and in the largest data incident, at 25-0514, the failures were in signing workflows and in outsourced customer support respectively.
This is the general finding of the corpus, stated in the sector that should be most resistant to it: cryptographic strength is not the binding constraint anywhere. The organisation still has employees, suppliers, support functions and administrators, and those are where the losses come from.
Irreversibility Converts Every Failure Into A Final One
What distinguishes this sector is not the frequency of failure but the absence of a correction mechanism. Conventional payment systems are built with reversal in mind — chargebacks, clawbacks, holds, an issuing bank with authority to unwind.
Settlement finality is presented as a feature and it genuinely is one. It also means an error, a deception or an unauthorised transfer produces the same outcome as a legitimate transaction, and the human processes that authorise transfers are the same fallible processes as everywhere else in this database.
On The Total
A $3.4 billion figure aggregates incidents valued at wildly different moments — some at time of theft, some at time of reporting, in assets whose price moved substantially across the year.
It is not a stable quantity in the way a count of affected people is, and the corpus records it as an order of magnitude rather than a measurement. Graded medium accordingly; the composition finding is firmer than the total.
Built on published sector analysis, listed below. Loss totals aggregate incidents valued at different dates in volatile assets and are not directly comparable. Corrections: corrections@forensicpost.com.