The first half of 2025 was the most expensive six months in the history of crypto theft: over $2.1 billion taken across at least 75 incidents, per TRM Labs — roughly 10% above the previous first-half record set in 2022.
Headline numbers make poor underwriting, though. The distribution matters more than the total.
One event dominates
Approximately $1.5 billion of that total is a single incident: the February 2025 attack on Bybit, which the FBI publicly attributed to North Korean state actors. It is the largest crypto theft on record — and it is the shape of the event, not just the size, that the London market noticed.
Bybit's stolen Ether did not leave a hot wallet. The attackers compromised the process around a cold wallet — manipulating what signers believed they were approving during a routine transfer. The assets were offline; the ceremony that moved them was not.
What the pattern says
Read closely, the half tells three things:
Theft concentrates at the transfer boundary. The costliest failures in H1 2025 were not smart-contract exploits but compromises of keys, signing interfaces and front-ends — the seam where offline assets meet online instructions. That seam is exactly where the boundary between two insurance markets runs: specie responds to theft of keys in storage or transit; crime responds to fraudulent transfer and insider dishonesty. Which side of that line a loss falls on decides which policy — if either — answers.
State-level adversaries change the threat model. A meaningful share of the half's losses is attributed to DPRK-linked groups. Underwriters price for the adversary a risk actually faces; a nation-state operating patiently against your signing path is a different proposition from an opportunistic drainer, and control expectations move accordingly.
Aggregation is the quiet worry. Seventy-five incidents in six months, with one event at $1.5 billion, is precisely the profile that makes capacity providers cautious about how much exposure they hold to any one custodian, technology stack or jurisdiction. This is why large limits in this class are built across multiple syndicates rather than written by one hand.
The practical reading
For a firm buying cover, the half's lesson is uncomfortable but useful: cold storage is only as cold as its signing path. Expect underwriters to walk the full ceremony — who can initiate, who verifies what on which device, how a transaction's true destination is confirmed — and to price the answers. The vault is table stakes; the process is the risk.
Sources
- TRM Labs, H1 2025 crypto losses: over $2.1bn across 75+ incidents.
- FBI public service announcement I-022625-PSA (February 2025): DPRK responsibility for the ~$1.5bn Bybit theft.
- CSIS analysis, "The ByBit Heist and the Future of U.S. Crypto Regulation" (2025).
Where znobia sits in this. znobia is a specialist introducer — a trading name of BLD PROTECTION LTD (England & Wales, no. 13422142). We are not authorised by the FCA, and we do not arrange, advise on or underwrite insurance. What we do is connect digital-asset firms with the FCA-authorised brokers and the regulated insurers and Lloyd's syndicates who actually write this class — prepared, and in front of the right desk. Nothing in this primer is advice. Terms are set by underwriters, and the policy wording governs.
