Four trackers, one year, and a $1.1 billion gap: nobody in crypto security agrees on how much was actually stolen in 2025.
Start with the number that isn't in dispute. In February 2025, North Korea's Lazarus Group breached Bybit's cold wallet infrastructure and moved out roughly $1.5 billion in ETH — the largest crypto theft in history. The FBI's IC3 advisory confirms $1.5 billion as the official figure. Chainalysis, in its own year-end report, cites the same number for the same incident. On this one fact, every serious tracker lines up.
Then the agreement stops. Ask "how much crypto was stolen across all of 2025" and you get four different answers from four trackers the industry treats as interchangeable:
Chainalysis: $3.4 billion
CertiK: $3.35 billion
PeckShield: $4.04 billion
SlowMist: $2.935 billion
That's a spread of roughly $1.1 billion — about 37% of the smallest figure — between organizations whose entire job is counting this precisely. None of them has published a correction against the others. None has reconciled the gap. Press coverage, exchange risk disclosures, and even policy testimony cite whichever number happens to be on hand, as if $2.9 billion and $4 billion were the same fact stated two ways.
They aren't. They're four different measurements of four different things, wearing the same headline.
Why the numbers diverge
The gap isn't sloppiness — it's scope, and each tracker draws the line somewhere different.
Hacks versus scams. Chainalysis and CertiK lean toward counting technical exploits and breaches — code vulnerabilities, private key compromises, bridge attacks. PeckShield's wider $4.04 billion figure folds in a broader category that includes scams and rug pulls alongside hacks, which mechanically produces a bigger number without necessarily meaning more theft occurred by any narrower definition.
CEX versus DeFi coverage. Some trackers weight centralized-exchange incidents (like Bybit) heavily because they're large, discrete, and easy to verify. Others build up their totals more from the long tail of smaller DeFi protocol exploits, which are numerous but individually harder to confirm and value precisely at the moment of the exploit.
Gross loss versus net-of-recovered. A theft followed by a partial white-hat recovery, a negotiated return, or a law-enforcement clawback can get counted at the original gross figure by one tracker and at the net remaining loss by another. Same incident, two legitimate-looking numbers.
Estimation methodology for the long tail. The handful of nine-figure incidents like Bybit are easy to nail down. The hundreds of smaller five- and six-figure DeFi exploits that make up the rest of the total are where trackers genuinely have to estimate, sample, and extrapolate — and small methodological choices compound across hundreds of incidents into a real aggregate difference.
None of these choices is dishonest. Each is a defensible way to define "theft." The problem is that nobody discloses which definition they're using when the number gets forwarded, and by the time a figure reaches a press release or a Senate hearing, it's just "crypto theft in 2025: $X billion" — full stop, no methodology attached.
Why it actually matters
This isn't pedantry. These figures get used as inputs to real decisions.
Institutional risk models cite whichever total makes crypto custody look safer or riskier depending on which side of a deal is doing the citing. Insurance underwriters pricing crypto-custody coverage need a real loss-rate denominator, and a 37% swing in the numerator changes the math on what a policy should cost. Regulatory testimony treats "crypto lost $X billion to theft this year" as a settled fact justifying a specific policy response, without anyone asking the questioner which tracker's methodology they're citing — or whether "worse than last year" and "better than last year" are both true depending on which one you pick.
The framing effect is real too. A reporter or a policy staffer reaching for the biggest available number gets a "worst year on record" story; reaching for the smallest gets "crypto security is improving." Both headlines can run in the same week, sourced to different trackers, describing the same year.
The falsifiable test
Here's a way to watch whether this actually gets fixed rather than staying a permanent asterisk: has any tracker published a reconciliation methodology — a public breakdown of what they include and exclude, cross-walked against a competitor's figure, so a reader could convert between them? As of this writing, no. If one appears, that's a real sign the industry is treating this number as infrastructure rather than a headline generator. If the same four incompatible totals get recycled into next year's "state of crypto security" report with no cross-walk, that's the tell that nobody who cites these numbers actually needs them to be precise — just big.
The Bybit number holds up because it's one incident, independently confirmed by a federal agency, with a clean chain of custody on the facts. The annual aggregate doesn't hold up the same way, because it was never one measurement to begin with — it's four different ones, laundered through a shared headline until they look like consensus.
Which of these four numbers have you seen cited as "the" 2025 total — and did the source say which tracker it came from?
Not financial advice. DYOR.
$ETH #CryptoSecurity #DataIntegrity #Chainalysis #CryptoHacks