Can Cryptocurrency Be Hacked? Risks, Protection, and Recovery

Cryptocurrency can be hacked, but not usually where people picture it. The blockchain ledgers behind Bitcoin and Ethereum have never been successfully breached at the protocol level. What gets hacked are the exchanges that hold your coins, the wallet software that stores your keys, the smart contracts that run decentralized finance, and, most often, the people using all of the above. The FBI’s Internet Crime Complaint Center logged $9.3 billion in cryptocurrency-related losses in 2024, a 66% jump from the year before.1FBI Internet Crime Complaint Center (IC3). 2024 IC3 Annual Report Almost none of that came from breaking the cryptography.

Why the Blockchain Itself Rarely Fails

A blockchain distributes its transaction records across thousands of independent computers. Rewriting confirmed history would require controlling more than half of the network’s computing power, a scenario called a 51% attack. On Bitcoin, sustaining that dominance long enough to matter would cost roughly $1.8 million per hour, which makes the attack economically irrational.

Smaller networks are a different story. Ethereum Classic lost over $1 million to a 51% attack in early 2019, and Bitcoin Gold and several other low-hash-rate coins have been hit the same way. If you hold a lesser-known coin, the ledger protecting it is genuinely more vulnerable than Bitcoin’s or Ethereum’s.

Where Crypto Actually Gets Stolen

Exchange Breaches

Centralized exchanges are the biggest single target because they hold private keys for millions of users in one place. When your crypto sits on an exchange, that company’s servers, employees, and internal controls are what stand between your balance and an attacker. In February 2025, North Korean state-sponsored hackers stole approximately $1.5 billion from Bybit, the largest known theft of any kind in history.2FBI Internet Crime Complaint Center (IC3). North Korea Responsible for 1.5 Billion Bybit Hack Japanese exchange DMM Bitcoin lost $305 million in a separate 2024 breach.

Attackers usually go after the “hot wallets” that exchanges keep online to process withdrawals, either by exploiting server vulnerabilities or by tricking employees into handing over credentials. Once inside, they move funds faster than monitoring systems can flag the activity. The FBI attributed the Bybit theft to a North Korean operation it calls TraderTraitor.2FBI Internet Crime Complaint Center (IC3). North Korea Responsible for 1.5 Billion Bybit Hack

Smart Contract Exploits

Decentralized finance protocols replace human intermediaries with self-executing code. Because that code is public, attackers can study it for flaws before exploiting them. Roughly 80% of hacked DeFi protocols had never been formally audited, but even audited contracts accounted for about 11% of value lost. An audit reduces risk; it doesn’t eliminate it.

The legal status of these exploits is unsettled among the people who commit them, but not among federal prosecutors. Draining a smart contract can be charged as wire fraud, which carries up to 20 years in prison.3Office of the Law Revision Counsel. 18 USC 1343 Fraud by Wire, Radio, or Television It can also be charged under the Computer Fraud and Abuse Act, with up to five years for a first offense and ten for a repeat.4Office of the Law Revision Counsel. 18 US Code 1030 – Fraud and Related Activity in Connection with Computers

Wallet Software Flaws

Your wallet generates and stores the private keys that prove you own your crypto. If the software has a defect in how it generates random numbers for seed phrases, an attacker can predict keys through computational brute force. Wallets that store keys in unencrypted files, or use outdated encryption, leave them exposed to malware that scans device storage. Courts have generally been reluctant to hold wallet developers liable for these failures, and free software is especially difficult to sue over because consumer protection statutes usually require a commercial transaction.

Social Engineering

The cryptography can be flawless and still lose to a convincing phishing page. Attackers build pixel-perfect replicas of exchange logins and drive traffic through fake support accounts, search ads, and targeted emails. Enter your recovery phrase once, and the funds are gone. Blockchain transactions are irreversible, so there is no chargeback.

SIM swapping is particularly destructive. An attacker convinces your mobile carrier to move your number to their device, then intercepts SMS-based two-factor authentication codes and resets your exchange passwords. Most people’s security fails here, at the phone company’s customer service desk, not at the cryptographic layer.

Clipboard malware sits silently on a device, watching for the format of a wallet address. When you copy an address to send funds, the malware swaps in one controlled by the attacker. Unless you check every character of the destination before confirming, the money goes to the wrong place permanently.

How to Protect Your Holdings

Move anything you’re not actively trading off exchanges and into cold storage. A hardware wallet keeps your private keys on a physical device that never exposes them to the internet. Even a computer riddled with malware cannot pull the keys off the device, because the wallet signs transactions internally and only outputs the signed result. No hardware wallet has been successfully hacked remotely.

For any exchange account you keep, replace SMS-based two-factor authentication with a FIDO2 hardware security key. SMS codes can be intercepted through SIM swapping; a hardware key uses public-key cryptography bound to the legitimate website’s domain. Click a perfect phishing link and the key will refuse to authenticate, because the domain does not match. That single change neutralizes the two most common ways individual accounts get drained.

Other measures that meaningfully reduce risk:

  • Turn on withdrawal whitelisting. Most major exchanges let you lock withdrawals to pre-approved addresses, with a 24-hour delay before any newly added address activates. An attacker inside your account cannot immediately send funds elsewhere.
  • Use a multi-signature wallet for larger holdings. A 2-of-3 setup means three keys exist but any two must sign, so no single compromised device can authorize a transfer.
  • Verify recipient addresses character by character. Comparing only the first and last few characters is exactly what clipboard malware is designed to defeat.
  • Stick to audited DeFi protocols. Audits are not a guarantee, but unaudited protocols account for the majority of exploits.

Crypto Has No Federal Insurance Safety Net

Cryptocurrency held on an exchange has none of the protections that apply to bank deposits or brokerage accounts. The FDIC does not insure crypto. The Securities Investor Protection Corporation does not cover digital assets on crypto exchanges. If the platform is hacked or goes bankrupt, you become an unsecured creditor in line with everyone else.

The GENIUS Act, signed into law in July 2025, made this explicit for stablecoins. Issuers must maintain 100% reserve backing with liquid assets like U.S. dollars or short-term Treasuries, but the law specifically prohibits them from claiming their products are federally insured or backed by the U.S. government. Stablecoin holders’ claims are prioritized over other creditors if an issuer becomes insolvent, but that is a recovery mechanism, not insurance.5The White House. Fact Sheet – President Donald J. Trump Signs GENIUS Act into Law

Some exchanges carry private crime insurance or maintain reserve funds, but the limits typically cover a fraction of total customer deposits. Read the fine print. “Assets are insured” on an exchange’s marketing page almost never means what a banking customer would assume.

What to Do If Your Crypto Is Stolen

Report the Theft Immediately

File a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov. Include every piece of transaction information you have: wallet addresses involved, the type and amount of cryptocurrency, dates, times, and transaction hashes. Document how you encountered the scammer, any communications, which exchanges or applications were involved, and a timeline. File even if pieces are missing. Partial reports still help investigators trace funds.6FBI Internet Crime Complaint Center (IC3). FBI Guidance for Cryptocurrency Scam Victims

Contact the exchange where the theft occurred. Some platforms can freeze accounts if they act quickly. Also file a report with local law enforcement, which may matter for both criminal prosecution and the tax documentation below.

Claim a Tax Deduction for the Loss

If your cryptocurrency was held as an investment and stolen through hacking or fraud, you can likely claim a theft loss deduction on your federal return. Since 2018, personal casualty and theft losses have been deductible only when caused by a federally declared disaster, but that restriction does not apply to losses from income-producing property.7Internal Revenue Service. Publication 547 Casualties, Disasters, and Thefts Crypto held for investment qualifies. Three conditions must be met:

  • The loss resulted from conduct that qualifies as theft, fraud, larceny, or embezzlement under applicable law.
  • By the end of the tax year, it is clear you will not get the funds back.
  • You held or transferred the crypto with the primary intention of making a profit.

Report the loss on Form 4684 (Section B), attached to your return. You will need to provide the name and any identifying information you have for the person or entity that took the funds. The deduction is limited to your cost basis in the stolen crypto, not its market value or any unrealized gains.8Internal Revenue Service. Instructions for Form 4684 The loss is deductible in the year you discovered the theft, provided recovery already looked unlikely at that point. If you later recover some of the funds, you’ll account for that on a future return.