
If you only read the headlines, it’s easy to think crypto security is a lost cause. It isn’t—but the stakes are higher. Independent researchers estimate more than $2.17 billion in crypto was stolen in just the first half of 2025, driven by a handful of massive incidents and a steady drumbeat of wallet-drainer scams. The year’s largest heist alone (the Bybit breach) accounts for roughly $1.5 billion, and analysts warn stolen funds from services could surpass $4 billion by year-end if trends persist.
Meanwhile, classic investment scams are still roaring. The FBI’s latest Internet Crime Report shows crypto investment fraud as the costliest category of online crime in 2024—over $6.5 billion in losses—while the U.S. Federal Trade Commission tallied $12.5 billion in overall fraud losses last year across all categories. Those numbers explain why basic operational security is no longer optional.
1) Use phishing-resistant 2FA (passkeys or security keys)
SMS codes and push approvals can be phished or proxied in “adversary-in-the-middle” (AiTM) attacks. When your exchange or wallet supports it, switch to FIDO2/WebAuthn passkeys or a hardware security key—they cryptographically bind your login to the real site, so cloned pages can’t steal your second factor. CISA calls phishing-resistant MFA the “gold standard” and provides a short fact sheet to help you evaluate options.
2) Separate hot and cold money
Keep trading funds in a “hot” wallet; park long-term holdings in cold storage (hardware wallet or an offline signer). That way, a bad signature or compromised device can’t jeopardize your entire stack. Security auditors tracking incidents across chains found over $2.28 billion in losses in H1 2025 alone; minimizing your exposed balance limits the blast radius if something goes wrong.
3) Sign safely—or don’t sign at all
Most retail losses now start with a malicious signature on a website that looks legitimate. Before you approve anything:
- Read the permission scope (is the dapp asking for “unlimited spend” on a token it shouldn’t touch?).
- Prefer wallets that humanize signatures (showing a clear summary of what will happen).
- After you’re done with a dapp, revoke approvals for the tokens you no longer need. This is the single best antidote to wallet drainers, which rely on evergreen allowances. Group-IB and other threat teams continue to document drainer-as-a-service kits that mass-phish users into bad approvals.
4) Assume every DM is a trap—and verify “support”
The biggest dollar losses aren’t always from code exploits; they’re from social engineering. Attackers now mix deepfaked voices, LinkedIn personas, and fake “security teams” to push you into installing a plugin or signing a “verification” transaction. The FBI links most of the costliest online fraud to crypto investment schemes, and the FTC’s consumer alerts show how convincingly scammers imitate jobs, grants, or “task” platforms to coax initial deposits. Build a habit: never trust inbound outreach; you initiate contact using official channels.
5) Watch the macro threat: state-linked hacking
It’s not just retail. State-linked actors are still draining exchanges and protocols, and their laundering playbooks get more sophisticated each year. Elliptic’s new analysis attributes over $2 billion in stolen crypto to North Korea-linked groups in 2025 alone, bringing the regime’s cumulative total above $6 billion. When these campaigns run, phishing and malware activity aimed at individual traders tends to spike too—because laundering starts with fresh liquidity. Stay skeptical of surprise “opportunities,” especially during newsy weeks.
6) Prefer smart accounts and spending limits when possible
Account abstraction (ERC-4337) and newer wallet standards allow session keys, spending limits, and even transaction whitelists—all of which reduce the damage from a single bad click. If your chain and wallet support smart accounts, enable per-dapp limits or daily caps for valuable tokens; it’s the closest thing crypto has to “credit card limits.” Good primers on ERC-4337 spell out why these features change the risk model for everyday users.
7) Have a recovery plan you can practice
Back up your seed/Secret Recovery Phrase offline (paper + metal), and consider a passphrase or a multi-part scheme only if you can maintain it reliably. Do a dry-run restore on a spare device before you need it. Cointelegraph’s checklist covers the essentials; the bigger point is operational: a plan you’ve tested is the difference between an inconvenience and a disaster.
What’s new in 2025
Wallet drainers are industrialized. Threat intel teams track kits that impersonate tax agencies, DeFi dashboards, or launchpads and walk victims through a scripted “verify and claim” flow. The goal is the same: secure a broad token approval and drain it later. Treat any site that asks for full-balance access as hostile until proven otherwise.
Losses are concentrated, but retail keeps getting hit. Chainalysis’ mid-year update shows 2025 already outpacing 2024 for stolen funds, with service hacks dominating the pie—but the share of personal-wallet thefts is rising, too. That’s what all those drainer kits accomplish: they scale retail theft.
Deepfakes are now part of the scam stack. Banks and government agencies are publishing public guidance on spotting AI-generated audio/video used in social-engineering plays. If someone “from support” calls you about an urgent wallet issue, hang up and go through official channels you find yourself.
Why these habits matter
Security reports vary on totals, but they all agree on the direction: losses are rising—and most are preventable with better hygiene. Whether you look at Chainalysis’ mid-year crime update or auditor rollups for H1 2025, the trend is the same: more value is at risk, and attackers are getting faster at weaponizing social engineering plus weak 2FA. The good news is that the same 3–4 habits—phishing-resistant MFA, safe signing/approval hygiene, hot–cold separation, and tested recovery—neutralize the majority of consumer-grade attacks. Make those muscle memories, and you’ve already done more for your stack than any headline tool can.