ChainCatcher Message, SlowMist releases an analysis of stolen funds in Q4 2025. In Q4 2025, there were 300 reports of funds being stolen (excluding cases reported through other channels), with approximately 1 million USD successfully frozen or recovered in 9 cases.
The three main causes of theft incidents are: phishing attacks, scams, and private key leaks. Phishing remains the primary reason for losses, ranging from fake domains to auto-complete hijacking redirects. Phishing is no longer limited to “clicking the wrong link.” One victim mistakenly sent 50 million USDT to a fake address that closely resembles the real one — the first 3 characters and the last 4 characters are exactly the same.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
SlowMist: Phishing attacks remain the primary reason for Q4 fund thefts, with 300 stolen cases recovered and $1 million USD recovered.
ChainCatcher Message, SlowMist releases an analysis of stolen funds in Q4 2025. In Q4 2025, there were 300 reports of funds being stolen (excluding cases reported through other channels), with approximately 1 million USD successfully frozen or recovered in 9 cases. The three main causes of theft incidents are: phishing attacks, scams, and private key leaks. Phishing remains the primary reason for losses, ranging from fake domains to auto-complete hijacking redirects. Phishing is no longer limited to “clicking the wrong link.” One victim mistakenly sent 50 million USDT to a fake address that closely resembles the real one — the first 3 characters and the last 4 characters are exactly the same.