$20.65B Stolen in Crypto Hacks. Only 2% Ever Saw a Refund.

Every large crypto hack comes with the same reassuring noises: negotiations, white-hat bounties, funds being traced. We checked what actually happens across the full record. Of $20.65 billion stolen in 1,215 tracked incidents, only 2% of hacks ever saw any money returned.

The money does not come back

Across every incident in DefiLlama’s hack database with a recorded loss, $20.65 billion was taken and $2.36 billion came back, or 11.4%. That headline share is flattered by a handful of negotiated returns. Count by incident instead and the picture is starker: 24 hacks out of 1,215 saw any recovery at all.

Of 20.65 billion dollars stolen, only 2.36 billion was returned

So the base rate for a victim protocol is simple. In 98 out of 100 hacks, nothing comes back.

Five incidents are a third of all losses

Crypto losses are not spread across a long tail of small failures. They are dominated by a few enormous events. The largest single incident, the 2020 breach of the LuBian mining pool, accounts for 17% of every dollar ever stolen. The top five together account for 32.5%.

Largest crypto hacks by amount stolen

This concentration matters for any claim about causes, which is where most coverage goes wrong.

The cause of the biggest losses flips on one event

Group the 80 recorded attack techniques into three families: stolen keys and access, contract and protocol logic, and social engineering. Run the numbers on all 1,215 incidents and stolen keys lead with 46.6% of the money, against 39.2% for contract bugs. That would support a tidy headline about operational security mattering more than code.

Remove the single largest incident and the ranking reverses: contract and protocol logic moves to 47.2% and stolen keys fall to 35.6%.

Share of losses by cause, with and without the largest incident

In other words, the popular claim that crypto mostly loses money to stolen keys rather than clever exploits rests on one 2020 mining-pool breach. We are publishing both cuts rather than the convenient one.

One thing does not flip. Contract and protocol bugs are by far the most common failure, 951 of 1,215 incidents, yet they never exceed roughly half the money. Key and social failures are rarer but far more expensive per event.

Bridges stay disproportionately costly

Bridge hacks are 90 incidents, about 7% of the record, but 17.8% of all money lost, or $3.68 billion. Per incident, a bridge failure is an order of magnitude more expensive than the median hack.

Why this matters

Two practical conclusions. First, recovery is not a plan: at a 2% incident-level return rate, treating negotiation as a fallback is wishful. Second, any confident statement about the leading cause of crypto losses should be tested against outlier removal, because at this level of concentration a single event decides the answer.

Methodology

Source is the DefiLlama hacks database, all incidents with a recorded loss amount, retrieved 11 September 2026. Note the scope: the database covers crypto broadly, including exchanges, mining pools and bridges, not only DeFi protocols. Recovery uses the database’s returned-funds field, so off-record or partial recoveries not logged there are not counted.

Attack techniques were grouped by keyword into three families. Phishing terms are matched before key terms, so signer phishing is counted as social engineering rather than a key compromise. The sensitivity check removes only the single largest incident and recomputes shares.

Yearly totals are included in the underlying data but 2026 is a partial year, so we make no claim about a trend. Figures, charts and methodology are free to cite with attribution to BullpenBrief.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free Calculators & Tools