h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

After the Hack: Why Some Crypto Protocols Survive and Others Die

The post-mortem is where a hacked crypto protocol's story seems to end. It is really the start of a harder one: survival, which some projects win and many lose.

The most honest thing crypto does is also its most misunderstood ritual. When a protocol is drained, the team publishes a post-mortem: a timeline, a root cause, an accounting of what went wrong and who, if anyone, is being made whole. Readers treat that document as an ending, the last page of the story. It almost never is. The post-mortem is act one. Act two, the part that actually decides whether a project matters a year later, is survival, and survival is a variable, not a guarantee.

The starkest illustration is happening in real time. Since late July 2026, thieves have been draining Bitcoin from Coldcard hardware wallets carrying a firmware bug that quietly weakened key generation back in 2021. TRM Labs put the running tally near 116 million dollars, roughly 1,816 BTC across more than 5,200 addresses, spread over several waves; TechCrunch, citing Elliptic, reported the total had passed 130 million dollars. Here is what makes Coldcard the outer edge of this whole subject: there is nothing to survive. No DAO, no treasury, no token, no governance forum, no single attacker to negotiate with. Just individual holders who followed self-custody best practice and lost their coins anyway. We covered the mechanics in our Coldcard post-mortem; this piece is about the question that case answers most brutally, which every other hacked project also faces. Does anyone come back from the autopsy?

The post-mortem is the beginning, not the end

Crypto has built an elaborate culture around dissecting its own failures. There is the blameless technical writeup borrowed from Google’s site-reliability engineers, the on-chain negotiation where teams message the attacker directly, the transparency dashboard, the bug-bounty offer that turns a thief into a paid finder. All of it is genuinely useful, and all of it is prologue. The interesting data is not in the writeup; it is in what the protocol looks like six, twelve, twenty-four months later.

Over the past few years the industry has assembled a fairly standard response toolkit. Message the attacker on-chain and offer a whitehat bounty, in the hope a thief becomes a paid finder. Freeze whatever centralized stablecoins and exchange deposits can still be frozen. Stand up a public status page, commission an outside forensic report, and put a reimbursement plan to a governance vote. Adopt one of the pre-signed legal frameworks that promise an attacker safe harbor if the funds come back inside a set window. All of it is genuinely useful, and all of it is front-loaded into the first hours and days. None of it answers the slower question of whether the protocol still exists, and still matters, once the dashboard goes quiet.

The macro picture in 2026 sets the odds. TRM Labs counted a record 207 hacking incidents in the first half of the year, but total losses fell below one billion dollars to about 972 million dollars, down sharply from 2.3 billion in the same period of 2025. Buried in that report is the number that should reframe how you read every post-mortem this year: smart-contract exploits made up 125 of the 207 incidents, a clear majority by count, yet accounted for only a small share of the value. Roughly 76 percent of the money was lost to compromises of keys, custody systems and signing infrastructure, incidents that were about 15 percent of the count. North Korea linked groups took an estimated 643 million dollars, about two thirds of the total, led by the 292 million dollar KelpDAO exploit and the 285 million dollar Drift Protocol breach. The pattern matters because the code bugs, the survivable ones, are getting more common while the value keeps flowing through the failure modes that are hardest to walk away from.

What survival actually means

Part of why people argue past each other about hacked protocols is that survival is not one thing. It is at least four, and they do not move together. A project can nail one and fail the rest.

DimensionWhat it measuresHeld even when others failed
Users made wholeDid depositors get their funds or an equivalent backWormhole covered losses; users kept the money even as the project stayed niche
Protocol continuityDoes the code keep running and attract deposits againCurve kept operating and processing volume years later, below its old peak
Token and market valueDid the native token and market position recoverMango kept a shell running while its token was wound down to nothing
Trust and reputationDo serious users and integrators come backNomad reimbursed and relaunched, yet almost nobody returned

Keep those four apart and the case histories stop looking random. Some teams buy back the first dimension with a checkbook and never recover the fourth. Others limp along on continuity with a dead token. The projects we call survivors tend to land three or four of the four; the casualties usually manage one or none.

The order in which those dimensions fail also tells you something. A protocol that loses trust first, before it loses solvency, is usually finished even if the balance sheet still looks fine, because DeFi runs on the willingness of other people to route liquidity and integrations through your contracts. A protocol that loses solvency but keeps trust, the Wormhole case, can be rescued with a check. The worst position is the one where continuity and trust collapse together, which is what happens when the team itself vanishes or is implicated, because then there is no one left to run the recovery and no one the market is willing to believe. Reading a post-mortem well means asking which of the four is actually gone, not just how big the hole is.

Euler: the gold-standard comeback

In March 2023, the lending protocol Euler Finance was hit by a flash-loan attack that drained about 197 million dollars, one of the largest DeFi exploits of that year. What followed became the template teams still copy. Instead of vanishing, Euler negotiated on-chain, and the attacker, over a series of transfers, returned essentially all of the recoverable funds, leaving an on-chain message that read, in part, “No intention of keeping what is not ours.” Depositors were made whole. That alone would have been a clean ending.

The team went further and rebuilt. Euler v2 launched on Ethereum in September 2024, a modular redesign that shipped only after an exhaustive round of independent audits, and it climbed back to hundreds of millions of dollars in deposits. Michael Bentley, chief executive of Euler Labs, described the psychological hurdle bluntly to CoinDesk: “A lot of people wrote us off and said it would have been totally normal for us to end the project right there.” He credited the comeback mostly to product-market fit rather than incentives. Euler hit the survivor jackpot on all four dimensions at once: funds returned, protocol relaunched, token and standing rebuilt, and a flaw that was isolated rather than baked into the design. It is the exception, not the rule, and it is worth studying precisely because so little of it can be reproduced on demand.

Wormhole: survival bought with a balance sheet

Not every rescue depends on a repentant attacker. In February 2022, the cross-chain bridge Wormhole lost about 320 million dollars to a signature-verification flaw that let the attacker mint wrapped ether out of nothing. The bridge was suddenly insolvent, which for a bridge is close to a death sentence: the whole point is that the assets on one side are backed on the other. Within roughly a day, Jump Crypto, the trading firm behind Wormhole, replaced the entire 320 million dollars from its own funds to keep the peg intact. A year later, in February 2023, Jump and the DeFi platform Oasis used a court order to claw back about 225 million dollars from the attacker’s leveraged position, recovering a large chunk of the bailout.

Wormhole survived, and it survived because someone with a very large balance sheet chose to absorb the loss. That is a real strategy, and it is also the one that raises the most uncomfortable questions. A backer willing to eat a nine-figure hole buys user trust instantly, but it does nothing to fix the underlying incentive: if losses are always socialized by a benefactor, the pressure to write flawless bridge code eases rather than tightens. Wormhole earned three of the four survival dimensions, but it earned them with capital, not with a cure.

Ronin: reimburse, rebuild, and still be here in 2026

The Ronin bridge hack remains one of the defining case studies in surviving a catastrophe. In March 2022, attackers later tied to North Korea’s Lazarus group compromised validator keys and drained about 625 million dollars from the network behind the game Axie Infinity. The theft went undetected for six days. What saved Ronin was a combination of capital and a product people still wanted to use. Sky Mavis, the studio behind it, raised 150 million dollars in a round led by Binance and combined it with its own balance sheet to reimburse users, then relaunched the bridge on June 28, 2022. Aleksander Larsen, the company’s chief operating officer, kept the messaging concrete: “The bridge will be refilled with the outstanding user-owned ETH and USDC. Everything is on schedule and the validators are ready.”

More than four years later, Ronin is still a live gaming layer, not a memory. The lesson is not that a 625 million dollar hole is survivable in the abstract; it is that reimbursement plus fast, specific communication plus genuine ongoing demand for the product can carry a project through a loss that would have buried a protocol nobody was still using. Size, notably, was not the obstacle. It rarely is.

Curve and Poly Network: partial recovery and the honest thief

Survival is often partial, and that counts too. In July 2023, several Curve Finance pools were drained after a reentrancy-lock bug in specific versions of the Vyper compiler, a failure that lived below the protocol in its tooling. Losses landed somewhere between 50 and 70 million dollars depending on the source. One exploiter returned about 12.7 million dollars within a week, Curve’s governance passed a token-funded reimbursement plan, and the protocol kept running. It never returned to its pre-hack peak in total value locked, but it did not die either. If you want the mechanics of why an automated market maker like Curve is such a rich target, our explainer on AMM design walks through the pool math that these attacks bend.

The most extreme version of the honest-thief ending belongs to Poly Network. In August 2021, an attacker took roughly 611 million dollars across three chains, at the time one of the biggest crypto thefts on record, then handed almost all of it back and declined both a 500,000 dollar bounty and an offer to become the project’s chief security advisor. Nicknamed Mr White Hat, the attacker was never charged. Poly Network survived on the strength of returned funds and community goodwill rather than a bulletproof relaunch. Partial is still survival, and both cases show a pattern: when the funds come back, even a wounded protocol usually gets to keep breathing.

Survivors and casualties at a glance

ProtocolYearAmountRoot causeResponseWhere it stands in 2026
Euler2023~197M dollarsFlash-loan logic flawFunds returned, v2 relaunchSurvived, rebuilt
Wormhole2022~320M dollarsSignature verificationBacker replaced funds; clawbackSurvived via bailout
Ronin2022~625M dollarsValidator key compromiseRaise plus reimbursementSurvived, active
Curve2023~50 to 70M dollarsCompiler-level bugPartial return, reimbursementSurvived, below peak
Poly Network2021~611M dollarsCross-chain access controlAttacker returned nearly allSurvived, diminished
Bybit2025~1.5B dollarsSigning UI supply chainFunds replaced, bounty, disclosureSurvived, still trading
Mango Markets2022~110M dollarsPrice manipulationDAO vote, later SEC settlementWound down
Terra2022~40B dollarsStablecoin design failureFork to Terra 2.0Effectively dead
Multichain2023~265M dollarsKey control, likely insiderNone; team goneShut down
Nomad2022~190M dollarsFaulty upgrade, open lootingPartial return, relaunchFaded away
Bunni2025~8.4M dollarsRounding-precision errorBug fixed, then closedShut down

Terra: the zombie chain

Terra is the clarifying casualty because it was never a code exploit at all. In May 2022, the algorithmic stablecoin UST lost its dollar peg and dragged its sister token LUNA into a death spiral, erasing roughly 40 billion dollars in weeks. There was no line of malicious calldata to point to and no patch to ship, because the failure was the design itself: a stablecoin held up by reflexive faith in a paired volatile token. A hard fork produced Terra 2.0, and it never regained relevance. Neither the new chain nor the old one recovered.

The legal coda underlined how final the collapse was. Founder Do Kwon pleaded guilty to fraud in 2025, and on December 11, 2025, a federal judge sentenced him to 15 years in prison, above the 12-year cap prosecutors had agreed not to exceed. Judge Paul Engelmayer called even that agreed figure “unreasonably lenient” for what he described as “a fraud on an epic, generational scale.” The takeaway for survival analysis is cold: when the flaw is fundamental to the design rather than a bug bolted onto a sound idea, there is nothing to fix, and a fork is a new project wearing a dead one’s name. No amount of capital or communication reverses a broken premise.

Multichain and Nomad: no team, no trust

Multichain is the darkest outcome in this entire roster, because it produced no post-mortem at all. There was no one left to write one. Around 265 million dollars flowed out of the cross-chain protocol in early July 2023 under circumstances Chainalysis flagged as a possible inside job, after its chief executive had reportedly been detained by Chinese authorities. The team simply announced that operations were ceasing. When a hack blurs into a possible exit scam, you cross from the world of survivable accidents into the world we mapped in our look at DeFi rug pulls, where the responsible party is not trying to recover, but to disappear.

Nomad shows the other way to lose. In August 2022, a botched upgrade turned the bridge into a free-for-all, and hundreds of copycat addresses looted about 190 million dollars in what observers called chaotic, permissionless looting. Roughly 37 million came back through a bounty, the team relaunched that December, and then almost nobody returned. The reputational damage was terminal even though the project technically stayed alive. The accountability tail ran into 2025, when Nomad’s parent company settled a US Federal Trade Commission complaint over unfair security practices, a consumer-protection regulator, not a markets one, stepping into territory the SEC does not reach. Nomad proves the harshest point about the trust dimension: you can reimburse, relaunch, and still be over, because trust is the one thing a checkbook cannot reissue.

Bunni: dead even after fixing the bug

If Terra shows that fundamental flaws are fatal and Multichain shows that a missing team is fatal, Bunni shows that being small is its own kind of fatal. In September 2025, the DeFi protocol lost about 8.4 million dollars to a rounding-precision error exploited through a sequence of tiny withdrawals. By the standards of this article that is a modest loss, the sort Ronin or Euler absorbed and moved past. Bunni did the responsible thing, identified the flaw and shipped a fix, and then shut down permanently, unable to fund the six- or seven-figure security program a credible relaunch would require.

The asymmetry is the whole story. The auditing firms that review this code operate at a scale that lets them absorb a miss and keep working; a small protocol that gets hit once often cannot raise the capital or the confidence to try again. Survival, it turns out, is partly a function of how much runway you had before the hack, which is why the same-sized loss can be a footnote for one team and an obituary for another.

Mango Markets: surviving the hack, losing the aftermath

Some protocols survive the exploit and lose the aftermath. In October 2022, a trader drained more than 100 million dollars from the Solana-based lending venue Mango Markets by manipulating the price of its own MNGO token, then argued in public that this was nothing more than a highly profitable trading strategy the protocol had allowed. The Mango DAO negotiated directly: token holders voted to let him keep a slice of the proceeds in exchange for returning the rest, and for a moment it looked like another on-chain settlement, another quiet survival.

The reprieve did not hold. Regulators did not treat a DAO vote as a settlement, and after sustained enforcement pressure the token and the platform were effectively unwound, with the DAO moving in early 2025 to wind the protocol down in the wake of an SEC settlement. Mango is the reminder that the deal a project strikes on-chain in its first week is not the last word. Courts, regulators and a poisoned reputation can finish a protocol months or years after its own post-mortem declared the matter closed, which is why survival has to be measured in years, not news cycles.

The five factors that decide who comes back

Line up the survivors against the casualties and the deciding variables are consistent. None of them is the headline number.

FactorSurvivorsCasualties
Capital or backstopTreasury, raise, or deep-pocketed backer (Ronin, Wormhole)No reserves to fund a relaunch (Bunni, Nomad)
Communication speedFast, specific, public disclosure (Bybit, Ronin)Silence or vague statements (Multichain)
Intact, identifiable teamFounders stay and rebuild (Euler)Team detained, anonymous, or gone (Multichain)
Isolated flaw vs design failureA fixable bug in a sound system (Euler, Curve)The design itself is the flaw (Terra)
Community and demandUsers still want the product (Ronin)Reputation gone, nobody returns (Nomad)

The absence on that list is the loudest signal. The size of the loss is not a survival factor. The three biggest events here, Bybit at roughly 1.5 billion dollars, Ronin at 625 million, Wormhole at 320 million, all survived, while Bunni died over 8.4 million. Bybit, the largest crypto theft ever, is instructive: hit in February 2025 through a compromised signing interface rather than a contract bug, it replaced the missing assets within days, published forensic findings from outside investigators, and offered a bounty of up to 140 million dollars to trace the funds. It is still trading. What separates survivors from casualties is rarely how much they lost, and almost always some combination of what they had in reserve, how they behaved in the first 48 hours, and whether the thing that broke was a bug or the blueprint.

The 2026 twist: the least survivable hacks are the ones rising

Here is why the survival playbook is getting less reliable, not more. Nearly every case in the survivor column was a smart-contract or logic bug: a discrete, on-chain, reproducible failure with a clean fix and, often, recoverable funds. That is exactly the category crypto has gotten better at handling. But as the H1 2026 data showed, that is no longer where the money goes. Three quarters of stolen value now comes from compromised keys, custody systems and signing infrastructure, and those incidents are structurally harder to survive. There is frequently no contract to patch, the funds usually leave through professional laundering pipelines toward state-linked actors, and there is no repentant attacker to negotiate with.

This is where the response toolkit runs out of tools. You cannot negotiate with a state intelligence unit, and you cannot patch a stolen signing key the way you patch a contract. The on-chain bounty, the governance vote and the redeployed contract were all built for a world where the money was still reachable and the attacker still had a reason to deal. Operational compromises break both assumptions. The funds are often gone within hours through mixers and cross-chain hops, the attacker answers to a sanctions regime rather than a bounty offer, and the only real remediation is slow, unglamorous work on internal security that no writeup can perform after the fact. The genre crypto perfected is very good at explaining code failures and much weaker at the failures now doing most of the damage.

Coldcard sits at the far end of that shift, an operational and firmware failure with no protocol to rebuild and no path to recovery for the people who lost coins. Coinkite has suggested that AI-assisted code review is now surfacing latent bugs faster than human experts can, which cuts both ways: defenders and attackers read the same open-source firmware. The attack surface keeps widening in directions the old response ritual does not cover. Autonomous software is a live example; the trust and key-management questions we raised about AI agents operating on-chain are the operational-security frontier, not the contract-bug one. So is shared security: the more protocols lean on borrowed trust, the more a single failure can cascade, a risk we examined in our guide to restaking and rented security. The uncomfortable implication is that the survival stories that reassured the market from 2021 to 2023 were drawn from the failure mode that is now shrinking as a share of the damage.

What survival costs, and what it cannot buy back

Even the clean comebacks are partial. Euler rebuilt but sits below the deposit base its predecessor once commanded. Curve kept running but never revisited its peak. Wormhole made users whole yet spent the years since as a bailed-out cautionary tale as much as a success. Survival, on close inspection, almost always means the users kept their money and the protocol kept a pulse, while the thing that originally made it matter, its momentum, its default-choice status, its aura of safety, is diminished or gone. Making depositors whole is not the same as restoring trust, and the four dimensions of survival almost never all come back together.

For anyone using these systems, the honest lesson is defensive. Bailouts are discretionary, not owed; the biggest one here happened because a specific firm chose to write a specific check. Reimbursement funds run dry. And the failure modes now responsible for most of the losses are precisely the ones with no recovery path. The safest working assumption is that a hack is permanent, which pushes the burden back onto prevention and self-custody discipline rather than post-hoc rescue.

For builders, the same evidence points somewhere more demanding than a better incident-response template. Survival correlates with things you have to bank before the attack: a treasury or a backer with the will to use it, a team that will still be standing and reachable on the worst day, a design whose failure modes are bounded rather than existential, and enough genuine demand that users have a reason to come back at all. Those are strategic choices made in calm quarters, not crisis-comms decisions made at 3 in the morning. The post-mortem culture is real medicine for the failures it can see clearly, and it deserves the credit it gets. It simply cannot resurrect a project that had none of those things in reserve.

So read the next post-mortem for what it actually is. It is crypto’s most honest document, and it is only the first chapter. Whether there is a second one depends on questions the writeup usually does not answer, and for a sobering share of projects, the honest answer is that there will be no second chapter at all.

Frequently Asked Questions

Do crypto protocols usually survive being hacked?

It is genuinely mixed, and the outcome depends far less on the size of the loss than on five factors: whether the team has capital or a backer to fund reimbursement, how quickly and transparently it communicates, whether the founding team is intact, whether the flaw was an isolated bug or a fundamental design failure, and whether users still want the product. Large hacks like Ronin at 625 million dollars and Wormhole at 320 million dollars were survived, while much smaller ones like Bunni at 8.4 million dollars ended in permanent shutdown.

What is the biggest crypto hack a project survived?

The Bybit exchange hack of February 2025, at roughly 1.5 billion dollars the largest crypto theft on record, is the clearest example: Bybit replaced the missing funds within days, published outside forensic findings, offered a bounty of up to 140 million dollars, and kept trading. Among DeFi-style protocols, Ronin’s recovery from a 625 million dollar bridge theft in 2022, funded partly by a 150 million dollar raise led by Binance, is the standout survival case.

Do hack victims get their money back?

Sometimes, but you should not count on it. Euler, Ronin and Wormhole all made users whole, in Euler’s case because the attacker returned the funds and in Wormhole’s because a backer covered the loss. But recovery is the exception once value leaves through compromised keys or custody systems, which accounted for about 76 percent of stolen value in the first half of 2026, and hardware-wallet victims in the 2026 Coldcard exploit have no recovery path at all.

What usually kills a crypto protocol after a hack?

Four things recur. No capital to fund a relaunch, which ended small protocols like Bunni. A team that is gone, detained or anonymous, as with Multichain, which left no one even to write a post-mortem. A fundamental design failure rather than a fixable bug, the Terra pattern, where a fork could not revive a broken premise. And terminal loss of trust, as with Nomad, which reimbursed and relaunched yet found almost no users willing to return.

Are 2026 crypto hacks harder to survive than earlier ones?

By value, yes. Most stolen value in 2026 now comes from compromises of keys, custody and signing infrastructure rather than smart-contract bugs, and those incidents are the hardest to survive because there is often no contract to patch, funds typically vanish into professional laundering toward state-linked actors, and there is no attacker to negotiate a return with. The survival stories that reassured the market from 2021 to 2023 mostly came from the code-bug category that is shrinking as a share of total damage.

By Anneke de Vries, security correspondent at HOGE Wire.

Share 𝕏 Post Telegram