Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, with a small number of major breaches driving most of the damage, according to CoinGecko’s 2026 crypto security report. The 10 largest attacks represented more than 72.5% of all losses recorded during the 19-month period, concentrating the sector’s financial exposure in a handful of failures involving major services and widely used infrastructure.
Infrastructure and supply-chain breaches were the largest source of losses, accounting for more than $1.8 billion, CoinGecko reported. Those attacks affected both centralized platforms and decentralized protocols, showing how vulnerabilities in third-party software, cloud services, signing systems, code dependencies and operational tools can bypass the differences between custody models.
Bybit and KelpDAO were among the incidents cited in connection with infrastructure or supply-chain attack vectors. Such breaches can place platforms at risk even when their core smart contracts or trading systems have undergone technical reviews, since attackers may target the systems used to deploy updates, manage keys or connect services rather than the primary application itself.
Largest attacks dominated the loss totals
The concentration of losses among the 10 biggest incidents means headline-grabbing exploits continued to shape the industry’s overall security record more than the long tail of smaller hacks. A major compromise of a large venue, bridge or infrastructure provider can rapidly exceed the combined losses from dozens of lower-value attacks.
CoinGecko’s figures also point to different weak points in centralized and decentralized systems. Private-key leakage was identified as the most common failure point for centralized venues. A private key is the cryptographic credential that authorizes movement of assets from a wallet; once exposed, an attacker can often transfer funds without needing to defeat the platform’s public-facing defenses.
Decentralized applications faced a different pattern. Smart-contract vulnerabilities caused $546 million in losses, according to the report. Smart contracts are programs that execute transactions and financial rules directly on a blockchain, and flaws in their code can allow attackers to manipulate balances, withdraw collateral or bypass restrictions built into a protocol.
Oracle failures and market manipulation also affected both types of platform. Oracles supply blockchain applications with outside data, including asset prices. If that data is distorted, a lending or derivatives protocol may calculate collateral values incorrectly and enable harmful trades or withdrawals. CoinGecko linked internal mechanism failures to incidents involving Bitget, Binance and Hyperliquid.
Audits offered limited protection from operational failures
The report found that audits did not prevent a substantial share of the losses recorded over the period. Of the 245 compromised protocols and platforms in the dataset, 147 had undergone an audit before the incident. Those cases accounted for 88.44% of all funds lost.
That result does not necessarily indicate that audits were ineffective at identifying code flaws within their scope. CoinGecko said many attacks against audited systems involved external infrastructure, unaudited upgrades or governance-based manipulation of protocol functions. A review of a smart contract’s original code may not cover a later deployment change, a compromised administrator wallet, an off-chain service, or a vote that alters system parameters.
Only about 11% of recorded incidents fell within the audited smart-contract scope, CoinGecko said, though those attacks still produced $396 million in losses. The data places greater weight on the operational security surrounding protocols: key management, upgrade controls, governance safeguards, vendor dependencies and monitoring systems.
For users, an “audited” label therefore describes a narrower review than many may assume. It can indicate that a particular version of code was examined for known vulnerabilities, but it does not provide protection against compromised credentials, manipulated price feeds, malicious governance proposals or failures in connected infrastructure.
Insurance capacity contracts as exploit activity rises
On-chain crypto insurance capacity declined during the period despite the elevated exploit totals. Effective coverage available through leading insurance protocols fell 20.2% to $130.2 million from $163.2 million, while cumulative payouts stood at roughly $33 million, according to CoinGecko.
The mismatch between billions of dollars in reported thefts and about $130 million in effective coverage illustrates the limited scale of decentralized insurance relative to the risks carried by major platforms. Coverage may also exclude incidents that users would regard as a hack, depending on how a policy defines a covered event.
CoinGecko said some policies cover only verified smart-contract vulnerabilities or specified infrastructure failures. Losses arising from private-key compromises, market manipulation, governance actions or social engineering may fall outside those terms. As of August 2026, five of nine on-chain insurance protocols had either stopped operating or moved to other business lines, further narrowing the options available for users seeking third-party protection.
Centralized venues have increasingly used internal user-protection funds to address that shortfall. These funds can provide a route to compensation after certain exploit-related losses, but their availability and payout rules depend on each platform’s policies rather than a standardized insurance framework.
Theft figures vary across security datasets
TRM Labs separately reported more than $1.2 billion in losses across 276 breaches by early August 2026, according to the material provided. The figure differs from CoinGecko’s $3.63 billion total, reflecting a different reporting period and incident count. Crypto-security datasets can vary depending on whether they track confirmed thefts, attempted exploits, recovered assets, platform failures, sanctions-related seizures or other categories of illicit activity.
Social engineering remains one route around technical safeguards. The supplied material cited an expert identified as Smart, who said attackers increasingly use deception to persuade targets to disclose access credentials directly. It also referenced a prior theft involving 780 Bitcoin in which such tactics reportedly bypassed strict digital controls.
The recent incident data suggests that the most persistent risks increasingly sit beyond the contract code itself. Platforms holding large asset pools face pressure to secure the systems around their software, while users assessing custody options and compensation policies must account for exclusions that can leave major categories of loss uncovered.
Worried about rising crypto hacks? Learn how improve crypto safety and protect your assets across centralized and decentralized platforms.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
