Preparing transaction

Reading wallet balances…

Did crypto hacks really drop 40% in May 2025?

Behind the Numbers: What the Latest Decline in Crypto Attacks Tells Us

Marko Jurina's avatar
Marko Jurina
Did crypto hacks really drop 40% in May 2025?

The month of May 2025 has brought a glimmer of relief to the blockchain security world. According to a recent report from Cointelegraph (

see article here

), data from blockchain security firm PeckShield reveals that major crypto hacks fell by 39.3% from the previous month. With only 20 high-profile exploits recorded—totaling $244.1 million in losses—this marked a notable decline from April's figure of approximately $400 million. But does this downward trend signify a turning point, or are hackers simply regrouping?

Understanding the nuance behind these numbers requires looking beyond the surface. From improved smart contract auditing to deeper chain monitoring and incident response improvements, the ecosystem has been shifting—gradually but effectively—toward a more hardened security posture.

The Major Exploits: Cetus and Cork Protocol Lead the Charts

May’s figures were significantly influenced by two headline-grabbing incidents. The largest was the $223 million breach on Cetus DEX, which occurred within a single 24-hour period. According to on-chain data and analysis by

Dedaub

, a vulnerability in the swap pool logic allowed a malicious actor to drain funds rapidly. While roughly $157 million of that was subsequently frozen across exchanges, the initial shock still registered heavily.

Meanwhile, Cork Protocol suffered a $12 million attack that exploited a flawed wrapped staked ETH (wstETH) conversion function. This vulnerability allowed unauthorized asset redemptions by bypassing normal collateral checks. Protocol-specific issues like these are often the result of overly complex codebases, which make automated auditing more difficult—a challenge still being addressed by platforms like

Code4rena

and

Immunefi

.

For users trading and bridging assets across ecosystems like Sui or Ethereum, platforms like

Jumper Exchange

can offer added transparency. Tools such as

Jumper Scan

help monitor transactional health and contract integrity across supported chains—critical during periods of network instability following an exploit.

How This Month’s Numbers Compare to Previous Quarters

Although $244.1 million is still a hefty loss, it’s a step down from April’s roughly $400 million. According to

Beosin

and

SlowMist

, March alone saw over $580 million stolen in coordinated attacks, including bridge exploits and MEV manipulation. So far, 2025's first quarter losses exceed $1.6 billion, with February’s Bybit hack accounting for over 90% of that quarter’s toll.

This month’s lower numbers suggest that platforms and protocols may finally be learning from past mistakes. There has been a visible uptick in protocol upgrades, off-chain bug bounties, and a shift toward modular architecture—which limits the blast radius of smart contract failures. Community-driven auditing and whitehat feedback loops are also becoming more common, especially among smaller projects with limited security budgets.

The Role of AI and Surveillance in Reducing Attack Surface

Security innovation in Web3 is increasingly driven by real-time surveillance and artificial intelligence. Blockchain intelligence tools like

Chainalysis Reactor

and

TRM Labs

have enabled investigators to trace stolen assets within minutes of an exploit. More importantly, proactive monitoring through anomaly detection—leveraged by teams such as

PeckShield

—has helped flag protocol vulnerabilities before they can be weaponized.

AI is also being deployed to enhance risk scoring of new contracts and wallets. Platforms like

Forta Network

monitor on-chain activity in real time, flagging suspicious patterns that indicate pending flash loan attacks, phishing schemes, or mint logic exploits.

For users wanting to protect themselves, bridges like

Jumper Exchange

simplify and verify cross-chain swaps, while

Jumper Learn

and

Jumper Academy

offer foundational cybersecurity education focused on wallet safety, contract analysis, and the use of watchlist tools.

Attribution: North Korea, Black Hats, and Rug Pulls

Several of May's smaller exploits have been attributed to persistent threat actors. A $5.2 million exploit involving a token spoofing vulnerability on Solana has been linked to the Lazarus Group—North Korea’s notorious state-sponsored hacking unit—according to analysts from

Elliptic

. The group has also been tied to this year's earlier attacks on DeFi platforms and infrastructure layers.

Rug pulls and inside jobs remain the most common exploit category by count, though they often cause smaller financial losses than technical hacks. These scams prey on uninformed users and unvetted liquidity pools. As a result, security researchers and analytics firms are urging users to stick with audited projects, verified DEXs, and multichain tools like

Jumper Exchange

that only route assets through known and verified liquidity sources.

Is the Decline Sustainable?

Whether May's numbers are an anomaly or the start of a positive trend remains to be seen. Many experts caution that exploiters often work in cycles, with periods of dormancy followed by major coordinated waves. But the recent decline is nonetheless a positive signal. It reflects increased cooperation between analytics firms, whitehat communities, and exchanges who now freeze funds faster and enforce compliance more rigorously.

Education continues to be a major barrier to security adoption. The more users understand things like front-running, reentrancy, and rug mechanics, the more difficult it becomes for malicious actors to succeed. This is why educational hubs like

Jumper Learn

are so crucial—they help demystify technical concepts and empower users to protect their capital.

Final Thoughts

Crypto security will always be a game of cat and mouse. But what May 2025 proves is that progress is possible. While hackers continue to evolve, so do the tools and communities working to stop them. DeFi protocols, centralized exchanges, and even DAOs are becoming more proactive with security budgeting and incident disclosure.

That’s not to say the battle is over. New threats—from AI-powered phishing to novel flash loan strategies—are constantly emerging. But the infrastructure supporting protocol safety is stronger than ever. Platforms like Jumper Exchange and analytics tools like Forta, TRM Labs, and Chainalysis are reshaping what it means to defend a decentralized network.

Bridge on Jumper today!

Further Reading


Marko Jurina's avatar
Marko JurinaCEO Jumper Exchange
Get the latest JetSwap updates

Subscribe to the JetSwap Newsletter to get the latest updates from JetSwap delivered to your inbox.

By signing up to our newsletter you are implicitly agreeing to JetSwap's terms of service and privacy policy. You can unsubscribe at any time from the link in the email footer.

Did crypto hacks really drop 40% in May 2025? | JetSwap Learn