Comparative Risk: Centralized vs. Decentralized
Published 7/25/2026, 7:36:59 AM
The perception that centralized crypto projects face higher hack risks is driven by the concentration of assets into single points of failure, the high severity of individual breaches, and a shift in sophisticated attacker behavior (such as North Korean state-sponsored groups) toward centralized targets.
While decentralized finance (DeFi) experiences a higher frequency of incidents, centralized exchanges (CEXs) account for the vast majority of total value lost due to the massive scale of their custodial holdings.
Comparative Risk: Centralized vs. Decentralized (2025 Data)
Research data from early 2025 highlights a stark contrast between the frequency of attacks and the resulting financial impact across both sectors.
| Metric | Centralized Exchanges (CEX) | DeFi Protocols |
|---|---|---|
| Total Incidents | 22 | 126 |
| Total Losses | ~$1.809 Billion | ~$649 Million |
| Share of Q1 2025 Losses | 88% | ~12% |
| Primary Attack Vector | Infrastructure/Private Key Compromise | Code/Smart Contract Exploits |
[Source: https://slowmist.com], [Source: https://coinlaw.club]
Key Drivers of Centralized Risk Perception
1. Single Points of Failure and Infrastructure Attacks
Centralized projects concentrate attack surfaces in custodial wallets, admin keys, and centralized servers. In 2025, infrastructure attacks—rather than code exploits—drove the clear majority of losses, with code exploits accounting for only 12.1% of total stolen value [Source: https://trm-labs.com]. A prominent example is the Bybit hack in February 2025, which resulted in losses of approximately $1.46–$1.5 billion (representing 51% of all 2025 losses at that time) due to a Safe{Wallet} compromise involving multi-sig and vendor dependency flaws [Source: https://coinlaw.club].
2. Amplified Impact of Breaches
A successful breach of a centralized entity often exposes all users simultaneously. Unlike DeFi exploits, which are frequently scoped to a specific liquidity pool or smart contract, CEX breaches target the core treasury or hot wallets. This leads to "high severity" events where a single incident can result in hundreds of millions in losses, whereas DeFi incidents are more numerous but typically less impactful per event [Source: https://slowmist.com].
3. Targeted Attacks by Sophisticated Actors
State-sponsored actors, specifically from North Korea (DPRK), have shifted their focus toward centralized services. In the second half of 2025, over 83% of DPRK-linked incidents targeted centralized exchanges rather than DeFi protocols [Source: https://global-ledger.io]. This strategic shift reinforces the perception that CEXs are the primary "honey pots" for the world's most advanced cybercriminals.
4. Insider Threats and Operational Risks
Centralized entities introduce human-centric risks that are largely absent in trustless code. Internal fraud and collusion are estimated to represent approximately 11% of CEX attacks [Note: not independently confirmed]. Reports also indicate that centralized infrastructure is vulnerable to contractor bribery and insider threats, such as a reported May 2025 data breach at Coinbase estimated to cost between $180–$400 million [Note: not independently confirmed] [Source: https://sqmagazine.com].
Summary of Findings
The data suggests that while DeFi is "riskier" in terms of the number of bugs and exploits, centralized projects are "riskier" in terms of total capital at stake. The perception of higher risk in centralized projects is not necessarily about the frequency of failure, but the catastrophic scale and the centralized nature of the "keys to the kingdom" that make them attractive targets for high-level attackers.