Crypto Security Threats Grow More Sophisticated
The cryptocurrency industry lost an estimated $3.63 billion to security incidents between January 2025 and July 2026 according to a new report by CoinGecko. This underscores the growing scale and sophistication of attacks targeting digital-asset platforms,
CoinGecko’s 2026 State of Crypto Security Report records 245 documented security incidents during the period.
The report found that the ten largest attacks alone accounted for more than 72.5% of the total value stolen, highlighting how a relatively small number of major breaches can produce enormous losses across the industry.
These findings come as cryptocurrency platforms face an increasingly diverse threat landscape. The threat ranges from compromised private keys and smart-contract vulnerabilities to supply-chain attacks, malicious integrations and manipulation of blockchain infrastructure.
Supply-chain attacks: One of the biggest threats
Infrastructure and supply-chain vulnerabilities were among the most damaging attack vectors identified by CoinGecko, accounting for more than $1.8 billion in losses across both centralized and decentralized platforms.
The report points to major incidents involving Bybit and KelpDAO as examples of how weaknesses outside the core blockchain code can result in substantial losses. The 2 leads the charts for the largest Crypto Hacks in 2026.
The risks, however, differ depending on the type of platform being attacked.
For centralized exchanges, or CEXs, private-key compromise remains the most prevalent point of failure. Decentralized applications, meanwhile, have faced growing losses from sophisticated smart-contract exploits, with CoinGecko recording approximately $546 million drained through such attacks.
Both centralized and decentralized platforms remain vulnerable to oracle manipulation, market manipulation and failures in internal mechanisms. CoinGecko cites incidents involving Bitget, Binance and Hyperliquid as examples of losses linked to weaknesses in platform mechanisms.
CoinGecko Report Security audits are no guarantee
One of the report’s more striking findings is that having a security audit does not necessarily mean a crypto platform is protected against major attacks.
Of the 245 incidents documented by CoinGecko, 147 involved protocols that had undergone security audits before being compromised. Those audited platforms accounted for 88.44% of the capital drained during the period studied.
CoinGecko argues that conventional audits can leave significant parts of a crypto platform’s security architecture outside their scope.
Many attacks against audited platforms targeted external infrastructure, unaudited code changes or broader systems that could be manipulated through governance mechanisms. Only about 11% of the incidents involving audited systems were attributed to smart-contract vulnerabilities that fell within the conventional audit scope, although those attacks still resulted in approximately $396 million in losses.
The findings suggest that auditing individual smart contracts may be insufficient when the wider system includes wallets, front-end interfaces, third-party infrastructure, governance mechanisms and other interconnected components.
Insurance coverage is shrinking
The industry’s insurance infrastructure is also struggling to keep pace with the scale of losses.
CoinGecko found that active coverage provided by leading crypto insurance protocols declined 20.2%, from $163.2 million to $130.2 million, even as the number and value of exploits increased.
At the same time, cumulative payouts remained largely unchanged at around $33 million.
The report suggests that elevated risks may be discouraging users from providing capital to insurance protocols or purchasing coverage at increasingly expensive premiums.
Crypto insurance can also have significant limitations. Policies may cover only specific categories of incidents, such as verified smart-contract exploits or infrastructure failures, leaving users potentially exposed when losses result from human error, compromised private keys or broader market events.
By August 2026, five of nine on-chain insurance protocols tracked by CoinGecko had either become inactive or shifted into other areas, highlighting the difficulty of building a sustainable insurance market for digital assets.
Exchanges turn to protection funds
With traditional crypto insurance struggling to expand, centralized exchanges are increasingly developing their own protection mechanisms to shield customers from losses arising from security incidents.
CoinGecko identifies the emergence of exchange-funded protection pools as a notable development in the industry’s response to hacking risks. Such funds are designed to provide users with an additional layer of protection if an exchange suffers a major exploit.
The shift reflects a broader recognition that security is no longer simply a technical issue for crypto companies. For exchanges holding large amounts of customer assets, the ability to absorb and respond to a catastrophic breach has become an important part of maintaining user confidence.
Attackers are becoming more organised
The report also highlights a change in the profile of crypto attackers.
According to CoinGecko, the industry has moved beyond attacks dominated by individual rogue hackers toward organised criminal groups and state-sponsored actors.
North Korean-linked hackers, in particular, have become a significant threat. CoinGecko says such groups increasingly use mixers, blockchain bridges and staggered withdrawals to make stolen assets more difficult to trace.
The development complicates efforts by exchanges, blockchain analytics companies and law-enforcement agencies to recover stolen funds, while demonstrating that attackers are adapting their techniques alongside improvements in blockchain monitoring and security.
A changing security equation
CoinGecko’s findings point to a fundamental challenge for the crypto industry: security protections designed around individual smart contracts or isolated systems may no longer be sufficient for an ecosystem built around increasingly interconnected infrastructure.
The sheer concentration of losses also means that headline figures can be driven by a handful of catastrophic incidents. With the ten largest attacks accounting for more than 72.5% of all stolen funds recorded since the start of 2025, the industry’s overall security picture can change dramatically following a single major breach.
For investors and users, the report suggests that a security audit alone should not be treated as proof that a platform is safe. The resilience of private-key management, external infrastructure, governance systems, software updates and recovery mechanisms can be equally important.
As digital assets become more deeply integrated into financial markets, the cost of security failures is also increasing. CoinGecko’s latest findings therefore serve as a warning that the industry’s next stage of growth will depend not only on adoption and innovation, but also on its ability to prevent, absorb and recover from increasingly sophisticated attacks.
Source: CoinGecko, 2026 State of Crypto Security Report, updated August 27, 2026.

