Trusted

Cetus Breach and North Korea Theft Led to $244 Million Crypto Losses in May

2 mins
Updated by Mohammad Shahid
Join our Trading Community on Telegram

In Brief

  • Malicious actors stole over $244 million from the cryptocurrency industry in May 2025, according to Peckshield.
  • Sui-based DeFi protocol Cetus accounted for the bulk of the damage, with North Korean attackers also re-sufacing.
  • Meanwhile, security experts now warn that hackers are increasingly trying to frame victims to mislead investigators.
  • promo

The crypto industry lost over $244 million to hacks and scams in May 2025, according to blockchain security firm PeckShield.

While the figure remains substantial, it marks a 39% decline compared to April’s $402 million loss, signaling a temporary slowdown in malicious activity.

Crypto Hackers are Now Trying to Frame Victims

PeckShield’s data shows the attacks spanned various protocols, with some incidents resulting in minor breaches and others involving catastrophic losses.

The largest exploit involved Cetus Protocol, a decentralized exchange operating on the Sui blockchain, which lost roughly $223 million in a single attack.

Top Crypto Hacks and Exploits in May.
Top Crypto Hacks and Exploits in May. Source: Peckshield

Following the breach, Cetus engaged with Sui validators to freeze some stolen assets, which amounted to roughly $162 million or about 71% of the stolen funds.

Cetus recently saw its proposal to reclaim the frozen funds approved by Sui validators. This marks the beginning of a broader recovery process that includes upgrading smart contracts, restoring liquidity, and preparing the platform for relaunch.

Meanwhile, another platform that saw a significant attack was the Ethereum-based Cork Protocol.

Attackers exploited the platform’s Wrapped Staked Ethereum (wstETH) and Wrapped Ethereum (weETH) markets, stealing around 3,761.8 wstETH, valued at nearly $12 million. Although other markets were not affected, Cork paused all operations to allow for a full audit.

The PeckShield’s report raised new concerns about the return of North Korea-linked hackers. According to the firm, these malicious actors allegedly stole $5.2 million from a single crypto trader.

The incident has reignited fears of state-sponsored attacks, following a lull after February’s $1.5 billion Bybit exploit.

Other incidents included a $2.2 million exploit on Mobius Token contracts on the BNB Chain. In this case, the attacker used a single smart contract to drain 28.5 million MBU tokens.

Amid the growing threats, Tornado Cash, an Ethereum-based crypto mixing tool, remains the preferred tool for laundering stolen funds.

Crypto Attackers' Laundering Method.
Crypto Attackers’ Laundering Method. Source: Peckshield

Considering this, Yu Xian, co-founder of blockchain security firm SlowMist, urged victims to share their wallet addresses after an exploit. He suggested making them public or partially censored to support investigations and avoid being mistakenly identified as suspects.

According to him, hackers increasingly use different tactics to shift suspicion onto innocent users to complicate law enforcement agencies’ investigations.

“Some hackers nowadays like to frame others. You will not only suffer the pain of having your funds stolen, but also the subsequent cooperation with law enforcement investigations… It is not pleasant to be treated as a suspect,” he added.

Top crypto platforms in the US
Figure Markets Figure Markets Explore
Coinbase Coinbase Explore
COCA wallet COCA wallet Explore
Arkham Arkham Explore
Moonacy Moonacy Explore
Top crypto platforms in the US
Figure Markets Figure Markets Explore
Coinbase Coinbase Explore
COCA wallet COCA wallet Explore
Arkham Arkham Explore
Moonacy Moonacy Explore

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

Oluwapelumi-Adejumo.png
Oluwapelumi Adejumo
Oluwapelumi Adejumo is a journalist at BeInCrypto, where he reports on a broad range of topics including Bitcoin, crypto exchange-traded funds (ETFs), market trends, regulatory shifts, technological advancements in digital assets, decentralized finance (DeFi), blockchain scalability, and the tokenomics of emerging altcoins. With over three years of experience in the industry, his works have been featured in major crypto media outlets such as CryptoSlate, Coinspeaker, FXEmpire, and Bitcoin...
READ FULL BIO
Sponsored
Sponsored