Crypto platforms lost 3.63 billion USD across 245 documented security incidents between January 2025 and July 2026, according to CoinGecko’s State of Crypto Security Report published on Aug. 27 — and the numbers suggest the industry’s security problem is less about buggy smart contracts than about everything surrounding them.
The report’s most striking finding is how concentrated the damage was. The ten largest attacks accounted for more than 72.5 percent of all stolen value recorded worldwide during the 19-month window, while infrastructure and supply-chain compromises caused more than 1.8 billion USD in losses on their own.
The February 2025 Bybit breach was the single largest incident, at roughly 1.44 billion USD. That attack succeeded by compromising transaction-signing infrastructure rather than through any defect in an exchange smart contract. It was followed by the 292 million USD KelpDAO breach, the 285 million USD Drift Protocol attack and the 223 million USD Cetus exploit — three incidents with three different root causes that illustrate why no single security control covers the industry’s full attack surface.
Audits are not the safety net many assume
Perhaps the most uncomfortable finding concerns audits. Of the 245 affected platforms, 147 — about 60 percent — had completed an independent security audit before being attacked. Those audited platforms accounted for 88.44 percent of recorded losses.
CoinGecko is careful about what that does and does not mean. The report does not establish that auditors signed off on the components that failed; only about 11 percent of incidents involved vulnerabilities that fell within the scope of routine smart-contract audits. Most of the rest involved external infrastructure, unaudited software updates, compromised credentials or governance mechanisms the audit never assessed.
Even so, the in-scope failures were costly, producing roughly 396 million USD in losses. And an audit remains a snapshot of one code version: changes made after the review can introduce fresh vulnerabilities, and the value of the exercise depends on scope, methodology, auditor experience and whether developers actually resolved the findings. Ripple’s recent security review, which surfaced 96 issues before the affected code ever reached users, shows how effective audits can be when findings arrive before activation — but such cases underline that audits complement, rather than replace, continuous monitoring and operational security.
Private keys remain the soft underbelly
CoinGecko identified private-key compromise as the leading risk for centralized exchanges. Decentralized applications lost approximately 546 million USD through smart-contract exploits, while both categories also suffered from oracle manipulation and internal-mechanism failures.
Infrastructure attacks can target private keys, employee devices, front-end interfaces, software dependencies and bridge operators — components that usually sit outside the smart contracts reviewed in a conventional audit. The pattern extends to state actors: two North Korea-linked operations alone drained approximately 577 million USD through social engineering and bridge infrastructure compromises rather than ordinary contract flaws.
Insurance is shrinking as the threat grows
While losses mounted, the onchain insurance market moved in the opposite direction. Active coverage across leading onchain insurance protocols fell 20.2 percent, from 163.2 million USD to 130.2 million USD, with cumulative payouts stuck near 33 million USD. Five of the nine protocols CoinGecko tracked had become inactive or pivoted to other business areas by August 2026, a retreat the report attributes to elevated risk, expensive premiums and difficulty attracting capital providers.
The comparison between 130.2 million USD in active coverage and 3.63 billion USD in losses is not a formal coverage ratio — one is a point-in-time measure, the other a cumulative total across 19 months. But the direction of travel is unmistakable. Policy terms narrow the effective protection further: many contracts cover verified smart-contract failures while excluding phishing, private-key theft, employee mistakes, market volatility and unsupported chains.
Self-funded reserves fill the gap
Into that vacuum, centralized exchanges have increasingly established investor-protection funds rather than purchasing external insurance. Self-funded reserves can reimburse users faster after a breach, but they are not equivalent to regulated insurance: coverage depends on the exchange’s own terms, the custody and composition of the reserve, and management discretion over which events qualify.
Proof-of-reserves attestations, meanwhile, address a different question — whether an exchange controls assets matching customer balances — without establishing secure key management or proving that all liabilities have been disclosed.
One caveat applies to the headline figure itself: the report does not clearly state whether recovered or frozen assets were deducted, so the 3.63 billion USD should be read as a reported gross loss estimate rather than a final net-loss tally.
What comes next
The report frames the industry’s next test plainly: whether platforms expand auditing beyond smart contracts into operational systems, bridges and software dependencies, and whether insurers can broaden protection without pricing premiums beyond reach. Until then, the data suggests the biggest risks are the ones nobody was paid to check — and that a sticker saying “audited” says far less than most users believe.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
bybit lost 1.44B to a signing infrastructure compromise, not a contract bug. audits literally cannot catch that class of attack and the industry keeps pretending they can
which is why multisig signer policy and insurance matter more than another certificate. the 88 percent figure is an ops failure stat wearing an audit costume
10 attacks = 72.5 percent of 3.63B stolen. the tail is noise, the head is the whole story. secure the ops layer and most of this number disappears
secure the ops layer is doing a lot of work in that sentence. key ceremony hygiene, signer isolation, vendor checks, boring stuff nobody budgets for
boring stuff is exactly it. key ceremonies and signer isolation prevented more losses this decade than every audit badge combined
secure the ops layer is a poster slogan until someone actually budgets for it. bybit had a runbook too and still got got at the signer
kelp at 292M, drift at 285M, cetus at 223M, three completely different root causes. anyone selling you one security tool that fixes everything is lying
1.8 billion from infrastructure and supply chain compromises against a fraction from contract bugs. years of auditing solidity while attackers just went after humans and servers
60 percent of the hacked platforms were audited beforehand and they account for 88 percent of losses. audits are theater and this report proves it
not theater, just scoped wrong. an audit covers the contract, bybit got got at the signing layer. completely different job description
theater is harsh but scoped wrong is fair. bybit lost 1.44B at the signing layer, no solidity audit was ever going to catch that
bybit alone was 1.44B of the 3.63B total. compromised signing infra, no contract bug anywhere. audits cant catch a hijacked signer
kelp at 292M, drift at 285M, cetus at 223M, all with different root causes. no single control saves you in this market
245 incidents and audits caught almost none because 1.8B of it was infrastructure and supply chain. nobody audits your signers or your CI pipeline, thats the gap
bybit is the whole proof. 1.44B through compromised signing ops, zero smart contract bugs involved. audit reports were pristine and it still happened
quarterly pentest of the signing flow alone would cover more of that 1.8B than every certificate combined. cheap fix, almost nobody does it
245 incidents and 60 percent were audited. at some point the industry admits the badge is marketing and starts pricing operational risk instead
72.5 percent of losses in ten attacks tells you targeting works. the long tail is noise, the top ten are all key management failures dressed up as hacks
top ten attacks made up 72.5 percent of all stolen value. the tail risk is basically a shortlist of megabreaches, not a long tail
I still see projects printing audited by badges like it means safety. 147 of the 245 hacked platforms had one. let that math settle
147 of 245 hacked platforms were audited and people still treat the badge as a safety guarantee. the audit market sells checkboxes, not security
147 of 245 is the number that belongs on a conference mainstage slide. instead we will get another audit partnership announcement
that slide would clear rooms. 147 of the 245 hacked platforms were audited and they carried 88.44 percent of the losses. nobody sponsors that keynote
supply chain sits at 1.8B of the losses and half the replies are still fighting about solidity audits. the humans were always the weak layer, bybit proved it for 1.44B
3.63B across 245 incidents and the marketing answer is still another audit badge. the report basically says budget for ops and signing infra, contracts were never the main leak