The losses you can see.
Nothing was broken.
Crypto is where the money moves on-chain, so you can watch it happen - and in 2025 the biggest losses did not turn on a bug. In each one the attacker ended up holding authority they should not have had, and every action after that was valid. The same failure reaches every bank and fintech - in traditional finance that path is fragmented across identity, software, approval and account systems, and rarely proven end to end. Below: what happened - and where MoveProof would have flagged the path first, before the money moved.
Kiln
A stolen infra-engineer GitHub token triggered CI/CD and injected a payload into Kiln's API. On an unstake it quietly reassigned Solana withdrawal authority to the attacker.
MoveProof would have flagged the moment an external address gained withdrawal authority over the stake accounts - a new path to the money that sat there 8 days before $41M moved.
Drift Protocol
Two governance signatures, collected months earlier, never expired. The 2-of-5 council threshold had no timelock, so the quorum was already met.
MoveProof would have flagged that two non-expiring signatures already satisfied the quorum - the path to the money existed long before it was drained.
StablR
The mint was protected by a 1-of-3 multisig. One key out of three could mint unbacked tokens without limit.
MoveProof would have flagged that a single key held unlimited mint authority - one identity, one path to unbacked issuance. A MiCA-licensed issuer.
Mechanisms and amounts as publicly reported. Kiln: Kiln incident report, SwissBorg, Chainalysis. Drift: BlockSec, Chainalysis. StablR: Blockaid and issuer disclosure.
$3.4B was stolen in 2025 alone.
Chainalysis, 2025. Figures as publicly reported.
The clock already started.
Two dates made authority a supervised question. The attackers had already moved to it.
DORA applies
Every EU financial firm - banks, payments, insurers, crypto alike - now sits under harmonised ICT-risk, resilience and testing rules; 22,000+ entities in scope.
MiCA - the crypto trigger
EU crypto operators now licensed and supervised. Crypto only - DORA is the cross-sector rule that reaches all of regulated finance.
The attack moved
Not code exploits. Not malware. Stolen access, used exactly as configured - 32% of breaches.