SINGAPORE — Cryptocurrency platforms lost more than $3.63 billion to hacks and other security breaches between January 2025 and July 2026, with a relatively small number of major attacks accounting for most of the stolen assets, according to CoinGecko’s 2026 State of Crypto Security Report.
CoinGecko said it documented 245 incidents during the 19-month period, with the 10 largest attacks responsible for more than 72.5% of total losses.
The findings highlight a changing security threat in which organized criminal operations and state-sponsored hackers have increasingly replaced individual attackers. CoinGecko cited North Korean hacking groups among those using cryptocurrency mixers, cross-chain bridges and staggered withdrawals to make stolen assets more difficult to trace.
Infrastructure and supply-chain attacks were the largest source of losses, accounting for more than $1.8 billion stolen from centralized and decentralized cryptocurrency platforms.

Private Keys, Smart Contracts Among Biggest Risks
The types of attacks differed depending on how cryptocurrency platforms operate, according to CoinGecko.
Among centralized exchanges, or CEXes, compromised private keys remained the most common point of failure. Decentralized applications, meanwhile, lost $546 million through smart-contract exploits.
CoinGecko said decentralized exchanges also are increasingly being targeted through fraudulent user interfaces and malicious integrations.
Both centralized and decentralized platforms remain vulnerable to oracle and market manipulation, as well as failures involving their internal mechanisms, the report found.
CoinGecko cited security incidents involving Bybit and KelpDAO among examples of infrastructure and supply-chain vulnerabilities and pointed to Bitget, Binance and Hyperliquid in discussing losses tied to internal mechanisms.
Audits Didn’t Prevent Many Attacks
One of the report’s more significant findings is that independent security audits did not necessarily prevent platforms from being compromised.
Of the 245 incidents documented since the beginning of 2025, 147 — or about 60% — involved protocols that had undergone security audits before being attacked.
Those audited platforms accounted for 88.44% of the total amount stolen during the period.
CoinGecko said the findings do not necessarily mean the audits failed. Instead, many successful attacks involved risks outside the traditional scope of smart-contract audits, including external infrastructure, code changes made after an audit and governance-related vulnerabilities.

Additional Findings
Only about 11% of incidents involving audited platforms resulted from smart-contract vulnerabilities that were within the scope of the audit, according to the report. Those attacks nevertheless resulted in approximately $396 million in losses.
Centralized exchanges face a different set of risks. While they generally do not rely on the same audit structures as decentralized protocols, CEXes use compliance programs and financial attestations such as proof-of-reserves to build confidence among customers.
Those measures, however, provide limited protection against social engineering attacks or the theft of private keys, CoinGecko said.
Crypto Insurance Coverage Declines 20%
CoinGecko also found that insurance protection has declined even as cryptocurrency security losses have increased.
Active coverage provided by leading crypto insurance protocols fell 20.2%, to $130.2 million from $163.2 million.
Cumulative payouts, meanwhile, remained largely unchanged at approximately $33 million.
CoinGecko said high levels of risk may be discouraging investors from supplying capital to insurance protocols while also making premiums more expensive for customers.
Coverage also can be narrowly defined. Policies may cover verified smart-contract exploits or infrastructure failures while excluding losses caused by compromised private keys, human error or market volatility.
As of August, five of nine on-chain insurance protocols reviewed by CoinGecko had either become inactive or shifted into other business segments.
Exchanges Build Their Own Protection Funds
With traditional crypto insurance providing limited coverage, centralized exchanges increasingly are establishing their own protection funds designed to reimburse customers following security incidents, according to the report.




