Cointime

Download App
iOS & Android

I Analyzed 120 Crypto Hacks. Here Is What I Learned

Validated Individual Expert

For this article, I analyzed 120 crypto hacks to see how they impacted the price performance of the cryptocurrencies affected. Some of the answers might surprise you.

The results of this research are relevant for investors who hold a cryptocurrency that was affected by a hack or who are considering buying a cryptocurrency after a hack has happened.

Please note that this is not an academic study.

The Dataset

All data used about the hacks come from this dataset from DefiLlama. Historical price data is from Coingecko.

At the time of my analysis, DefiLlama’s dataset contained data on 124 crypto hacks in the period from January 2020 to October 2022.

Crypto Hack Classifications & Techniques

In the period under review, the crypto hacks caused the loss of $5176,05 million.

In their dataset, DefiLlama classified whether the hack targeted a weakness in infrastructure, smart contract language, protocol logic, or the interaction between multiple protocols (ecosystem). The results are visualized in the following chart.

  • As the data shows, faults in the protocol logic offer the greatest attack surface for potential attackers, 37 protocol logic hacks resulted in more than $2 billion in loss.
  • Likewise, the infrastructure and the ecosystem of crypto platforms often offer gaps that hackers can penetrate.
  • On the other hand, rug pulls, i.e. project developers giving up a project and running away with the investors’ money, are relatively rare. 

The next chart shows a selection of the techniques most commonly used by the attackers and how much money was stolen with them.

  • What is striking is how often hackers succeeded by compromising the private keys of project members and investors.
  • Access control exploits allowed attackers to access certain features and perform actions they shouldn’t have had access to.
  • Price oracle manipulation means that hackers found a way to manipulate data provided to a smart contract by third parties in order to make the smart contract perform a specific action.

The Impact of Hacks on Cryptocurrency Prices

Unsurprisingly, the news of a hack has a disastrous impact on the price of the affected cryptocurrencies. On average, hacked crypto projects lost around 50% of their value in the first few days after the hack became public.

The following chart visualizes when the prices reached a local bottom a few days after the hacks using a selection of representative projects. The amount of lost funds does not seem to correlate with the price decreases.

To get a better understanding of how hacked cryptocurrency prices behave over a longer period of time, let’s now look at the timeline below. It shows the percentage change in value at different time stamps.

  • As the previous chart showed, the affected cryptocurrencies lost massively in value in the first few days after the hack.
  • What is surprising is that a hack does not automatically mean the immediate total collapse of a project. A large part of the analyzed cases saw a relative price recovery after the hack — shown as ‘peak after hack’ in the above chart. It is not possible to generalize the time took to reach the peak and how much these price increases were. In some cases, it was the well-known ‘dead cat bounce’, in other cases the underlying bull market seemed to be an important driver.
  • However, a large majority of projects never reached the same or higher price level compared to the price before the hack (blue colored lines). This means that once the trust is gone, in most cases it will never come back.
  • For the few cryptocurrencies, where a higher price was achieved after the hack (yellow lines), this happened during the 2021 bull market. However, none of these projects could sustain profits in the long term.
  • In the long term, hacked projects massively lose value — on average they saw a loss of 80% compared to the price levels just before the hack happened.
  • The main conclusion I draw from this analysis is the following: if you own a cryptocurrency that just got hacked — sell it. With the exception of a bull market, you should NOT expect a long-lasting positive price development in the future. If you are considering buying a cryptocurrency after it got hacked, you should probably look for a better alternative.
  • The data on hack classifications and techniques discussed above shows that many crypto projects have serious vulnerabilities. As a retail investor, it is difficult to review and evaluate crypto projects in this regard. For me, this underlines the importance of audits of reliable 3rd parties.
  • You should also carefully examine potential investments and look for information on how the respective projects are arming themselves against the challenges described above.
Comments

All Comments

Recommended for you

  • Norway’s Wealth Fund Watchdog to Review Cryptocurrencies by 2025

    According to market news reported by , the supervisory authority of Norway's wealth fund will conduct reviews on shoe manufacturers, cryptocurrency, and gambling companies in 2025, which may lead to divestment.

  • SlowMist publishes over 4,000 DEXX victim addresses and corresponding attacker addresses on the EVM chain

    Yu Xian disclosed that SlowMist has published the addresses of more than 4000 victims and corresponding attacker addresses on the EVM (ETH/BSC/BASE) chain's DEXX. Last week, more than 8600 Solana addresses related to attackers were announced. The data comes from the official DEXX and submissions from thousands of victims.

  • OpenAI responds to Musk's lawsuit: The application is repeated and still unfounded

    recently Musk requested a US court to block OpenAI, an artificial intelligence research center, from illegally transforming into a for-profit enterprise. A spokesperson for OpenAI said that Musk's application is repetitive and still baseless.

  • Musk says SpaceX could be worth more than $1 trillion

    a netizen posted on social media platform X claiming that there are 9 companies in the world with a market value exceeding one trillion US dollars, of which 8 are American companies. In response, Musk replied that SpaceX may one day become one of them.

  • South Korea postpones cryptocurrency tax again until 2027

    at today's press conference, Park Chan-dae, the leader of the largest opposition party in South Korea, the Democratic Party of Korea, announced that they will abandon their plan to implement a cryptocurrency capital gains tax in 2025 and agree to postpone it for another two years until 2027. The proposal to "delay the cryptocurrency capital gains tax" was put forward by the South Korean government and the ruling party, the People Power Party. The Democratic Party of Korea previously stated that delaying taxation was a political trick of the ruling party.

  • Community feedback: On-chain AI agent Spectral interaction contract was hacked

    On December 1st, X user @RuslanMoody warned: "Do not interact with the on-chain AI agent Spectral website, as its interaction contract has been hacked. Note: this does not apply to tokens whose liquidity is locked on Uniswap." Additionally, X user @0xYong_W stated that the Spectral exchange has been "emptied" by someone else.

  • Japan's Financial Services Agency proposes relaxing reserve requirements for trust banks to issue stablecoins and implementing travel rules

    the Japanese Financial Services Agency (FSA) recently presented some ideas regarding cryptocurrencies and stablecoins to the Financial System Committee's Payment Services Working Group. It was mentioned that the FSA is unwilling to allow banks outside of trust banks to issue stablecoins. As for stablecoins issued by trust banks, the FSA hopes to relax the reserve requirements that currently mandate all assets be held in the form of bank deposits. However, the FSA also hopes to implement travel rules that require KYC for transfers of stablecoins issued by trust banks.

  • Security agency: Clipper lost more than $500,000 in attack, $6.5 million in funds at risk

    security organization fuzzland's co-founder shoucccc stated in a post on X that "DEX Clipper was attacked by hackers due to API vulnerabilities (such as private key leaks). Currently, the losses exceed 500,000 US dollars, and 6.5 million US dollars of funds are at risk. Users are advised to withdraw immediately."

  • Japan’s Financial Services Agency proposes lightweight legislation for non-exchange crypto intermediaries

    Japan is considering new lightweight legislation for cryptocurrency intermediaries that are not cryptocurrency exchanges. Recently, the Japanese Financial Services Agency (FSA) presented its own ideas to the Payment Service Working Group of the Financial System Committee.

  • DeFi TVL exceeds $95 billion again

    According to defillama data, as of May 18, 2024, the total value locked (TVL) in DeFi has once again surpassed $95 billion. It is currently reported at $95.069 billion, an increase of nearly $12 billion from the low point of $83.04 billion 35 days ago. Among the top five protocols in terms of TVL, Eigenlayer has the highest 30-day increase, with TVL rising by 19.67% to a total of $15.455 billion.