Research

The losses you can see.
Nothing was broken.

Crypto is where the money moves on-chain, so you can watch it happen - and in 2025 the biggest losses did not turn on a bug. In each one the attacker ended up holding authority they should not have had, and every action after that was valid. The same failure reaches every bank and fintech - in traditional finance that path is fragmented across identity, software, approval and account systems, and rarely proven end to end. Below: what happened - and where MoveProof would have flagged the path first, before the money moved.

Sep 2025

Kiln

A stolen infra-engineer GitHub token triggered CI/CD and injected a payload into Kiln's API. On an unstake it quietly reassigned Solana withdrawal authority to the attacker.

MoveProof would have flagged the moment an external address gained withdrawal authority over the stake accounts - a new path to the money that sat there 8 days before $41M moved.

$41M
Apr 2026

Drift Protocol

Two governance signatures, collected months earlier, never expired. The 2-of-5 council threshold had no timelock, so the quorum was already met.

MoveProof would have flagged that two non-expiring signatures already satisfied the quorum - the path to the money existed long before it was drained.

$285M
May 2026

StablR

The mint was protected by a 1-of-3 multisig. One key out of three could mint unbacked tokens without limit.

MoveProof would have flagged that a single key held unlimited mint authority - one identity, one path to unbacked issuance. A MiCA-licensed issuer.

$10.4M
Three different stacks. One shape: authority reached, then used exactly as configured. In every case the path existed - and was visible - before the money moved.

Mechanisms and amounts as publicly reported. Kiln: Kiln incident report, SwissBorg, Chainalysis. Drift: BlockSec, Chainalysis. StablR: Blockaid and issuer disclosure.

The wider number

$3.4B was stolen in 2025 alone.

76%of 2025's losses came through infrastructure: compromised keys, social engineering and supply chain - not broken cryptography.
$2.02Ba single DPRK-linked theft - about 60% of the year's total. Infrastructure compromise, not a protocol bug.
0of the events above needed to break a control. Every action after the authority was reached was valid.

Chainalysis, 2025. Figures as publicly reported.

Why now

The clock already started.

Two dates made authority a supervised question. The attackers had already moved to it.

17 JAN 2025

DORA applies

Every EU financial firm - banks, payments, insurers, crypto alike - now sits under harmonised ICT-risk, resilience and testing rules; 22,000+ entities in scope.

Regulation (EU) 2022/2554
1 JUL 2026

MiCA - the crypto trigger

EU crypto operators now licensed and supervised. Crypto only - DORA is the cross-sector rule that reaches all of regulated finance.

Regulation (EU) 2023/1114
SINCE 2025

The attack moved

Not code exploits. Not malware. Stolen access, used exactly as configured - 32% of breaches.

Verizon DBIR 2025
22,000+ EU financial firms carry more than €34 trillion on their balance sheets, under one ICT-resilience standard - and few can prove, end to end, who can actually move it. No product answers that. Today it is a spreadsheet and a consultant, once a year.

Find out how many humans stand between one account and your treasury.