This survey of crypto asset investors found that 40.9% of respondents have experienced hacking or other forms of unauthorized access.
What's particularly striking is the paradox that users who are confident in their security measures — and active users who diligently use two-factor authentication — show higher victimization rates.
Why do the most security-conscious investors become targets for attackers?
Drawing on detailed data broken down by age group, years of investing experience, and security awareness, this article reveals the risk management practices investors truly need to protect their assets in the crypto asset market.
A 40.9% Hacking Victimization Rate

Response | Respondents | Share |
|---|---|---|
No damage | 415 | 55.6% |
Affected (funds safe) | 216 | 29.0% |
Affected (funds lost) | 89 | 11.9% |
Roughly Four in Ten Experienced Unauthorized Access
In this survey of crypto asset investors, 40.9% of all respondents reported having experienced some form of unauthorized access or hacking.
This figure shows that security risk in the Web3 space is no longer just an issue for a handful of technical experts — it is now an everyday threat that ordinary investors cannot afford to ignore.
While more than half — 55.6% — avoided harm, the fact that roughly two out of every five investors have been targeted by an attack represents an extremely serious level of risk.
This reflects a reality in which opportunities for attack are expanding daily alongside the market's rapid growth, underscoring the need for every individual investor to strengthen their own defenses.
Investors should approach their environment with the assumption that their account or wallet could become a target at any moment.
Many users are potentially exposed to risk, and it's worth reaffirming that danger can lurk within everyday trading activity.
About One in Ten Ended Up Losing Funds
Among those who experienced an incident, 11.9% actually ended up losing crypto assets.
The remaining 29.0% were attacked but their assets remained safe — what could be described as an attempted, unsuccessful attack.
At first glance, the proportion who actually lost assets may seem small.
But while the majority did manage to protect their holdings, the fact that roughly one in ten suffered a fatal loss is not something that should be overlooked.
This data suggests that even when attackers gain access, prompt action — such as disconnecting a wallet — can still prevent losses.
At the same time, it's a stark warning that a single moment of carelessness or a delayed response can be the decisive blow that wipes out assets entirely.
These figures vividly illustrate just how difficult it is to fully protect one's assets as an investor.
Keep Your Asset-Protection Mindset Continuously Updated
Those who were attacked but kept their assets safe may have benefited from some form of protective action, such as early detection of something unusual or avoiding suspicious sites.
Their success is the best proof that proper risk management can stop an attack in its tracks.
However, a single success does not guarantee safety going forward.
While security technology advances by the day, attack methods are becoming similarly more sophisticated, and there are a growing number of cases where past countermeasures no longer work.
It's clear that simply implementing security measures does not create an environment of complete safety.
It is essential for every individual investor to review their asset management practices and continually update their security mindset — this is the key to long-term asset management.
The ongoing effort to keep pace with evolving threats and update one's knowledge to protect one's crypto assets is, in fact, a responsibility that comes with being an investor.
A More Than Fourfold Gap in Victimization Rates by Age

Age Group | Victimization Rate | Of Which: Funds Lost |
|---|---|---|
20s | 65.3% | 17.6% |
30s | 49.8% | 13.0% |
40s | 35.0% | 8.0% |
50s | 20.8% | 5.0% |
60s | 18.0% | 6.2% |
Victimization Rate for People in Their 20s Stands Out at 65.3%
The most striking finding in this survey was the high victimization rate among people in their 20s.
At 65.3%, the figure is overwhelmingly higher than any other age group.
This is likely driven by investment behavior characteristic of younger investors — gathering information via social media and actively participating in buzzy DeFi projects.
While they adapt quickly to new technology, they also have more opportunities to fall into the sophisticated traps set by attackers.
This figure is by no means a coincidence — it shows that the behavior patterns of younger investors are directly linked to attack risk.
Precisely because they are digital natives, this generation should further strengthen its guard against the latest threats.
Victimization Rates Are Moderate for People in Their 30s and 40s
Victimization rates for those in their 30s and 40s came in at 49.8% and 35.0%, respectively.
While lower than the rate for people in their 20s, these levels are still far from negligible.
Being in the prime of their working lives, people in this generation likely invest in the gaps between busy days.
Choosing platforms for convenience without having enough time to research them properly may be one factor that raises their risk.
While these mid-career investors have experience, their preparedness for security issues specific to crypto assets still appears to have room to improve.
Staying alert and thoroughly applying basic countermeasures is the surest path to protecting one's assets.
Victimization Rates Are Low for People 50 and Older
On the other hand, the victimization rate falls markedly with age, coming in at 20.8% for people in their 50s and 18.0% for those in their 60s.
The gap compared with younger investors is stark.
Older investors tend to strongly favor a conservative investment approach.
Their lower rate of victimization is likely linked to less frequent engagement with high-risk new services and complex on-chain transactions.
This does not mean they avoid harm because their security awareness is extraordinarily high.
Rather, the low victimization rate stems from the fact that they engage in relatively fewer activities that make them targets for attack.
What we can read from this is a structural difference based on investment style — the sheer volume of activity itself functions as a defensive wall protecting assets.
Victimization Rates Peak Among Investors with 1 to 2 Years of Experience

Years of Investing Experience | Hacking Victimization Rate | Rate of Funds Lost |
|---|---|---|
Less than 1 year | 30.0% | 12.0% |
1–2 years | 51.4% | 15.0% |
2–3 years | 48.0% | 12.0% |
3–5 years | 45.0% | 10.0% |
5+ years | 42.0% | 8.0% |
Damage Tends to Concentrate in the Early Stages of Investing
A striking finding emerged: the one-to-two-year mark after starting to invest is when investors are most vulnerable to hacking.
The victimization rate reaches 51.4%, meaning more than half of investors at this stage have experienced some form of damage.
The early period after entering the crypto asset market is a time when investors are still unfamiliar with trading operations and wallet management.
This low level of proficiency during that period can be inferred to make them prime targets for attackers.
The curiosity that drives investors to explore many different projects may be one factor that causes them to neglect risk management.
Establishing the basics first is what's needed.
Analyzing the Correlation Between Experience and Risk
Among investors with five or more years of experience, the victimization rate tends to fall to 42.0%.
Meanwhile, the rate of asset loss is held down to 8.0%, which can be seen as evidence that experience helps investors avoid risk.
This is likely because staying in the market for a long time improves both security knowledge and the ability to handle problems.
Years of investing experience are not merely a length of time — they can be seen as time spent building immunity to protect one's crypto assets.
Even experienced investors are never at zero risk.
Continuing to manage assets while letting go of overconfidence is the best strategy for protecting them.
Investors with Less Than a Year of Experience Show Unwavering Vigilance
Investors with less than a year of experience have the lowest victimization rate, at 30.0%.
This may reflect not only their lower trading volume but also a result of them acting more cautiously precisely because there is still so much they don't yet understand.
However, if market conditions change and they are lured in by tempting talk while still lacking knowledge, they could suddenly find themselves victims of an attack.
It's precisely while still a beginner that it's essential to acquire proper security knowledge.
This period, before one's investment style has become fixed, is the best opportunity to invest time in learning.
Investors should build robust defenses from the very start.
A 60.6% Victimization Rate Among Those Confident in Their Security

Security Awareness | Victimization Rate |
|---|---|
Confident I'm doing it thoroughly | 60.6% |
Know it's important but find it a hassle | 49.4% |
Doing the bare minimum | 31.7% |
Not too concerned about it | 14.5% |
Victimization Rate Reaches 60.6% Among the Most Confident
This survey found that among respondents who said they were "confident I'm doing security thoroughly," the victimization rate reached 60.6%.
This figure is dramatically higher than the 14.5% recorded among those who said they are "not too concerned about it."
This is a truly striking, paradoxical finding.
It would normally be natural to assume that higher security awareness means a lower chance of being victimized, yet this survey reveals the exact opposite.
Why do the most confident users show the highest victimization rates?
This very gap illustrates just how complex the security risks surrounding crypto assets truly are.
The Paradoxical Structure Between Risk Awareness and Reality
The fact that those most confident in their security are more likely to be targeted does not mean that countermeasures are meaningless.
Rather, it's more reasonable to conclude that these users are simply operating in an environment where they are more likely to be targeted.
Investors who use many services and manage their assets with complex configurations tend to become more attractive targets for attackers.
A sense of "confidence" may simply be the flip side of pride in one's own active on-chain activity.
Even with a strong security mindset, today's crypto asset market is rife with schemes sophisticated enough to overcome it.
Threats that awareness alone cannot prevent absolutely do exist.
Activity Level, Not Awareness Alone, Is What Determines Risk
The difference in victimization rates is more likely attributable to differences in investors' "activity level" than to whether or not security measures are in place.
Investors who actively use DeFi or trade a wide variety of tokens have more points of contact with the outside world.
As those points of contact increase, so too, inevitably, do the opportunities for attack.
These results suggest that people are not being victimized because their security measures are inadequate, but because they are active in an environment with more opportunities for attack.
The more active an investor is, the more robust the defenses they need to put in place to protect their own assets.
It's important to objectively assess your own activity level and take countermeasures suited to it.
Damage Concentrates Among Those Who Use 2FA and Perform Revocations

2FA Setup Status | Respondents | Victimization Rate |
|---|---|---|
Set up on some services | 333 | 52.6% |
Set up on all services | 219 | 43.4% |
Not set up | 148 | 21.6% |
Don't know what 2FA is | 46 | 6.5% |
Revocation Practice | Respondents | Victimization Rate |
|---|---|---|
Know about it and do it regularly | 95 | 65.3% |
Know about it but don't do it | 172 | 61.0% |
Have heard of it | 229 | 43.7% |
Don't know about it | 227 | 15.9% |
The High Risk Faced by Those Who Set Up 2FA
The victimization rate among users who have set up two-factor authentication (2FA) is clearly higher than among those who have not.
Specifically, 52.6% of those who have "set it up on some services" and 43.4% of those with it "set up on all services" have experienced an incident.
By contrast, the victimization rate among those who don't know what 2FA is stands at just 6.5%.
This gap does not suggest that having or not having security measures is a direct cause of the damage.
Rather, it's evidence that users who consciously set up two-factor authentication are precisely the ones actively using crypto asset services.
The more actively a user trades, the more likely they are to become an attack target, which raises their victimization rate as a result.
Victimization Rate Among Those Who Revoke Approvals Tops 60%
A similar pattern was confirmed for revocation — the practice of withdrawing smart contract approvals.
Among those who "know about it and do it regularly," the victimization rate is an extremely high 65.3%.
Performing revocations regularly means that a user is engaging with that many more DApps (decentralized applications) and DeFi services.
Frequently approving new contracts is, in effect, exposing oneself to risk without realizing it.
Meanwhile, the victimization rate among those who "don't know" what revocation is stands at just 15.9%.
This result vividly illustrates how the breadth of one's on-chain activity and security threats go hand in hand.
The Real Cause of Victimization Is Activity Level, Not Countermeasures
The data so far reveals a paradoxical correlation: the more security measures a person takes, the more likely they are to be victimized.
Those who properly apply defenses such as two-factor authentication and revocation are, to begin with, active in areas of inherently higher risk.
It's not that the countermeasures themselves cause the damage — it's more rational to conclude that a higher level of activity increases the opportunities for attack.
This absolutely does not mean "countermeasures are pointless"; what matters is being aware that you are operating in a place where you need to strengthen your defenses.
Accurately understanding one's own level of on-chain activity is the first step toward genuine security.
Rather than relying on tools alone, continuously setting a level of vigilance that matches your own trading frequency is an essential condition for protecting your assets.
Summary
This survey revealed the reality that roughly four in ten crypto asset investors have experienced hacking or unauthorized access.
What deserves particular attention is the paradoxical structure in which people with high security awareness, and active users who take defensive measures such as two-factor authentication and revocation, show higher victimization rates.
This does not mean countermeasures are unnecessary — rather, it suggests that active on-chain engagement itself creates an environment more likely to be targeted by attackers.
While it's difficult to prevent damage entirely, the data showing that newer investors are more prone to victimization also demonstrates that knowledge and experience serve as a protective wall for one's assets.
Security is not simply a matter of configuration settings.
Objectively assessing your own activity level and risk, and continually updating your level of vigilance, is truly the first step toward sound asset management.
Survey Overview
Survey date: April 10, 2026
Survey method: Internet survey
Survey population: Men and women residing in Japan who currently invest, or have previously invested, in crypto assets
Valid responses: 746
Conducted by: Clabo Inc.
Survey Questions
- Do you have experience investing in crypto assets (also known as virtual currencies)?
- How many years of experience do you have investing in crypto assets?
- Have you set up two-factor authentication (2FA)?
- Honestly, how do you feel about security measures?
- Do you know about revocation (withdrawing approvals)? Do you practice it?
- Have you ever experienced hacking or phishing?
This article is for informational purposes only and does not constitute financial or investment advice. Please consult a qualified professional before making investment decisions.







