toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Crypto thefts reach $3.63 billion in 19 months

2026-08-28 07:40

Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, with a small number of major breaches driving most of the damage, according to CoinGecko’s 2026 crypto security report. The 10 largest attacks represented more than 72.5% of all losses recorded during the 19-month period, concentrating the sector’s financial exposure in a handful of failures involving major services and widely used infrastructure.

Infrastructure and supply-chain breaches were the largest source of losses, accounting for more than $1.8 billion, CoinGecko reported. Those attacks affected both centralized platforms and decentralized protocols, showing how vulnerabilities in third-party software, cloud services, signing systems, code dependencies and operational tools can bypass the differences between custody models.

Bybit and KelpDAO were among the incidents cited in connection with infrastructure or supply-chain attack vectors. Such breaches can place platforms at risk even when their core smart contracts or trading systems have undergone technical reviews, since attackers may target the systems used to deploy updates, manage keys or connect services rather than the primary application itself.

Largest attacks dominated the loss totals

The concentration of losses among the 10 biggest incidents means headline-grabbing exploits continued to shape the industry’s overall security record more than the long tail of smaller hacks. A major compromise of a large venue, bridge or infrastructure provider can rapidly exceed the combined losses from dozens of lower-value attacks.

CoinGecko’s figures also point to different weak points in centralized and decentralized systems. Private-key leakage was identified as the most common failure point for centralized venues. A private key is the cryptographic credential that authorizes movement of assets from a wallet; once exposed, an attacker can often transfer funds without needing to defeat the platform’s public-facing defenses.

Decentralized applications faced a different pattern. Smart-contract vulnerabilities caused $546 million in losses, according to the report. Smart contracts are programs that execute transactions and financial rules directly on a blockchain, and flaws in their code can allow attackers to manipulate balances, withdraw collateral or bypass restrictions built into a protocol.

Oracle failures and market manipulation also affected both types of platform. Oracles supply blockchain applications with outside data, including asset prices. If that data is distorted, a lending or derivatives protocol may calculate collateral values incorrectly and enable harmful trades or withdrawals. CoinGecko linked internal mechanism failures to incidents involving Bitget, Binance and Hyperliquid.

Audits offered limited protection from operational failures

The report found that audits did not prevent a substantial share of the losses recorded over the period. Of the 245 compromised protocols and platforms in the dataset, 147 had undergone an audit before the incident. Those cases accounted for 88.44% of all funds lost.

That result does not necessarily indicate that audits were ineffective at identifying code flaws within their scope. CoinGecko said many attacks against audited systems involved external infrastructure, unaudited upgrades or governance-based manipulation of protocol functions. A review of a smart contract’s original code may not cover a later deployment change, a compromised administrator wallet, an off-chain service, or a vote that alters system parameters.

Only about 11% of recorded incidents fell within the audited smart-contract scope, CoinGecko said, though those attacks still produced $396 million in losses. The data places greater weight on the operational security surrounding protocols: key management, upgrade controls, governance safeguards, vendor dependencies and monitoring systems.

For users, an “audited” label therefore describes a narrower review than many may assume. It can indicate that a particular version of code was examined for known vulnerabilities, but it does not provide protection against compromised credentials, manipulated price feeds, malicious governance proposals or failures in connected infrastructure.

Insurance capacity contracts as exploit activity rises

On-chain crypto insurance capacity declined during the period despite the elevated exploit totals. Effective coverage available through leading insurance protocols fell 20.2% to $130.2 million from $163.2 million, while cumulative payouts stood at roughly $33 million, according to CoinGecko.

The mismatch between billions of dollars in reported thefts and about $130 million in effective coverage illustrates the limited scale of decentralized insurance relative to the risks carried by major platforms. Coverage may also exclude incidents that users would regard as a hack, depending on how a policy defines a covered event.

CoinGecko said some policies cover only verified smart-contract vulnerabilities or specified infrastructure failures. Losses arising from private-key compromises, market manipulation, governance actions or social engineering may fall outside those terms. As of August 2026, five of nine on-chain insurance protocols had either stopped operating or moved to other business lines, further narrowing the options available for users seeking third-party protection.

Centralized venues have increasingly used internal user-protection funds to address that shortfall. These funds can provide a route to compensation after certain exploit-related losses, but their availability and payout rules depend on each platform’s policies rather than a standardized insurance framework.

Theft figures vary across security datasets

TRM Labs separately reported more than $1.2 billion in losses across 276 breaches by early August 2026, according to the material provided. The figure differs from CoinGecko’s $3.63 billion total, reflecting a different reporting period and incident count. Crypto-security datasets can vary depending on whether they track confirmed thefts, attempted exploits, recovered assets, platform failures, sanctions-related seizures or other categories of illicit activity.

Social engineering remains one route around technical safeguards. The supplied material cited an expert identified as Smart, who said attackers increasingly use deception to persuade targets to disclose access credentials directly. It also referenced a prior theft involving 780 Bitcoin in which such tactics reportedly bypassed strict digital controls.

The recent incident data suggests that the most persistent risks increasingly sit beyond the contract code itself. Platforms holding large asset pools face pressure to secure the systems around their software, while users assessing custody options and compensation policies must account for exclusions that can leave major categories of loss uncovered.


Worried about rising crypto hacks? Learn how improve crypto safety and protect your assets across centralized and decentralized platforms.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.