
Crypto platforms lost over $3.63 billion to security incidents between January 2025 and July 2026. CoinGecko documented 245 attacks during this period.
The top 10 incidents accounted for more than 72.5% of the total amount stolen, demonstrating that a relatively small number of major breaches accounted for most of the losses. Infrastructure and supply chain vulnerabilities have been the main sources of damage on both centralized and decentralized exchanges. Combined losses exceeded $1.8 billion.
The most attacked platforms have been audited
The security breaches involving Bybit and KelpDAO are notable examples. CoinGecko too find that the main weaknesses differ depending on how the platforms are built.
For centralized exchanges, compromised private keys remain the most common point of failure, while decentralized applications lost $546 million due to sophisticated smart contract exploits. Both centralized and decentralized platforms, however, remain exposed to oracles and market manipulation, with errors in internal mechanisms leading to significant losses for platforms such as Bitget, Binance and Hyperliquid.
After examining the role of safety controls, the report found that carrying out an independent audit had not prevented many incidents. Of the 245 attacks recorded since the start of 2025, 147 involved protocols that had been audited before being compromised. In fact, these audited platforms accounted for over 88% of the total capital drained during the 19-month period.
Conventional audits often do not cover areas exploited in major attacks. Many incidents involved external infrastructure, unaudited code changes, or systemic functionality manipulated through governance attacks. Only about 11% of incidents involving audited platforms were related to smart contract vulnerabilities falling within the scope of the audit, although these flaws still resulted in losses of $396 million.
CEXs generally do not use the same audit model as decentralized protocols and instead rely on compliance measures and financial attestations such as proof of reserve. However, CoinGecko said such safeguards provide limited protection against social engineering and serious private key security failures.
Crypto Insurance Declines
Even though exploits increased, active coverage of major crypto insurance protocols decreased by 20.2%, from $163.2 million to $130.2 million. Cumulative payments remained virtually unchanged at $33 million. The report said high risks in the sector may have discouraged users from providing capital or purchasing coverage at higher prices.
Crypto insurance can also be narrow in scope, as claims are often limited to verified smart contract exploits or infrastructure failures. Losses related to human error, compromised private keys, or market volatility may not qualify.
As of August 2026, five of the nine on-chain insurance protocols have become inactive or moved to other segments.
The article Crypto Lost $3.63 Billion to Exploits Since 2025: 60% of Successful Platforms Audited (CoinGecko) appeared first on CryptoPotato.