The Nine Largest Crypto Hacks in 2022

Already nearly $2 billion, the value of cryptoassets lost to software exploits this year is likely to exceed 2021

article-image

Blockworks exclusive art by axel Rangel

share

key takeaways

  • Single lines of ill-conceived code gave hackers access to cryptoassets worth hundreds of millions of dollars
  • Most of the hacked companies are continuing operations after undergoing audits or upgrading their security

Hackers exploited a software bug in the Web3 music platform Audius to make off with $1.1 million on Saturday, but the funds are a drop in the nearly-$2 billion dollar bucket of funds lost to hacks through the first half of 2022, according to Blockchain security firm Beosin.

The fiat value of hacked assets are on pace to top the $3.2 billion lost in 2021, according to crypto security firm Chainalysis, even amid a drastic slide in cryptocurrency valuations. Blockworks compiled some of the year’s largest crypto hacks to see what went wrong and how protocols fared after being hacked.



  • Crypto.com, January 17, $35 million
    • In late January, a hacker managed to disable two-factor authentication on the crypto exchange Crypto.com and extract bitcoin and ether from customer accounts. CEO Kris Marszalek initially denied customer funds were lost before acknowledging the hack days later. The company said it is transitioning to “multi-factor authentication” in response to the exploit.
  • Qubit QBridge Hack, January 27, $80 million
  • Wormhole, February 2, $325 million
    • A hacker exploited smart contracts on the Solana-to-Ethereum bridge to mint and cash out on wrapped ether without depositing collateral. Jump Crypto, the venture capital firm behind Wormhole, replenished the stolen funds to keep Solana-based platforms affected by the hack solvent. Wormhole renamed its bridge Portal and currently holds over $480 million, according to crypto data firm DeFi Llama. 
  • IRA Financial Trust, February 8, $37 million
    • The crypto-focused retirement and pension platform was pilfered when hackers accessed a “master key” that bypassed all security measures to customer accounts. IRA Financial Trust has since sued Gemini, the crypto exchange where customer funds were stored, for alleged negligence leading to the hack.
  • Cashio, March 22, $52 million
    • A string of fake accounts used an “infinite mint glitch” to put up worthless collateral for Cashio’s CASH stablecoin. The coin’s peg cratered to zero and has not recovered, according to data from CoinGecko.
  • Axie Infinity Ronin Bridge, March 28, $625 million
  • Beanstalk, April 17, $182 million
    • A hacker used a “flash loan,” where funds are borrowed and repaid in the same transaction, to accumulate enough assets to control the stablecoin’s governance protocol. The hacker passed a proposal donating funds to Ukraine before making off with the collateral. Developers paused the protocol while undergoing audits and raising funds, but plan to reopen deposits in early August.
  • Fei Protocol, April 30, $80 million
    • A “reentrancy” bug in the lending protocol’s code allowed a hacker to take out a loan while also withdrawing the collateral put up on the loan. Fei users passed a proposal to make investors whole through “the DAO repaying the bad debt on behalf of the hacker.” The Fei stablecoin remains at its dollar peg, per CoinGecko.
  • Harmony Bridge, June 23, $100 million

Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates (19).png

Research

Suilend has grown into the top money market and liquid staking provider on Sui. STEAMM, Suilend’s Superfluid AMM, presents a compelling avenue for growing market share within Sui’s DEX landscape and revenue generation for the protocol. Suilend’s multi-product suite position it well for owning market share across key verticals. While current metrics across the Sui ecosystem are likely inflated due to Sui Foundation incentive programs, SEND trades at amongst the lowest multiples in the lend/borrow sector, suggesting that a bull case for continued growth in the ecosystem may be mispriced.

article-image

Silk Road founder Ulbricht made a triumphant return to the Bitcoin Conference, 10 years on from sentencing

article-image

A Blockworks Research report looked at who could take up some of the marketshare in the launchpad space

article-image

Business-to-business stablecoin payments are on the rise, per a report from Artemis, Dragonfly and Castle Island

article-image

Crypto continues to do its thing: incentivizing behavior

article-image

Kraken will soon offer Backed ‘xStocks’ as Solana tokens

article-image

In a unanimous decision, the US Court of International Trade has ruled that Trump’s IEEPA tariffs are unlawful