From January 2025 to July 2026, crypto platforms experienced a staggering loss of $3.63 billion across 245 documented incidents, as detailed in the CoinGecko cybersecurity report.

The most devastating attacks were attributed to vulnerabilities in infrastructure and supply chains, leading to losses exceeding $1.8 billion for both centralized and decentralized projects.

Source: CoinGecko.

Among the largest hacking incidents were those involving Bybit, which incurred losses of $1.43 billion, and Kelp, with $292 million lost.

Source: CoinGecko.

In the case of centralized exchanges (CEX), the report identified the compromise of private keys as a primary risk factor. Decentralized applications suffered losses of $546 million due to smart contract hacks.

CoinGecko analysts noted the susceptibility of both models to manipulation via oracles and market factors, as well as internal mechanism failures at Bitget, Binance, and Hyperliquid.

A separate section of the report focused on audits, revealing that out of the 245 incidents, 147 involved protocols that had undergone audits prior to being hacked. These platforms accounted for 88.44% of the total capital withdrawn over the last 19 months.

Source: CoinGecko.

Approximately 11% of these incidents were linked to vulnerabilities within smart contracts that fell under the purview of audits, with damages amounting to $396 million.

CoinGecko also highlighted a declining trend in crypto insurance, noting that active coverage on the largest insurance protocols dropped by 20.2%, from $163.2 million to $130.2 million.

Source: CoinGecko.

Total payouts remained around $33 million. As of August 2026, five out of nine on-chain insurance protocols had either become inactive or shifted focus.

Another key finding concerned centralized exchanges that are establishing protection funds to cover user losses in the event of exploits. However, standard measures such as Proof-of-Reserve were deemed insufficient to protect against social engineering and critical failures regarding private key security.

It is worth noting that on August 27, the Moonwell protocol fell victim to a hacking incident that resulted in a loss of $8.7 million.