2025 Mid-year Blockchain Security and AML Report
2025-07-01 • Slowmist •
https://www.slowmist.com/report/SlowMist-first-half-of-the-2025-report(EN).pdf
Attachments
SlowMist’s mid-year blockchain security and AML review records a high-loss threat environment in which 121 blockchain security incidents caused about $2.373 billion in losses during the first half of 2025. The excerpt highlights account compromises, smart contract vulnerabilities, phishing, fake Telegram safeguards, malicious browser extensions, LinkedIn recruitment phishing, social engineering, supply-chain backdoors, and unrestricted LLM abuse as major risk areas. Centralized exchange incidents accounted for about $1.883 billion in losses, while DeFi remained the most frequently targeted sector. The report separately includes a Lazarus Group section under threat actor developments, making the AML and asset-tracing context relevant for DPRK-linked cryptocurrency theft and laundering monitoring without attributing the listed incidents beyond the excerpt.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | slowmist.medium.com | 2022-08-16 | 2025-09-01 |
| URL | https://user.guancha.cn/main/co… | 2025-07-01 | 2025-07-01 |
| URL | https://www.zaobao.com.sg/realt… | 2025-07-01 | 2025-07-01 |
| URL | https://www.rmit.edu.au/news/fa… | 2025-07-01 | 2025-07-01 |
| DOMAIN | user.guancha.cn | 2025-07-01 | 2025-07-01 |
| DOMAIN | venice.ai | 2025-07-01 | 2025-07-01 |
| DOMAIN | dune.com | 2023-07-03 | 2025-07-01 |
| URL | https://slowmist.medium.com | 2022-08-16 | 2025-07-01 |