Bitcoin and Crypto Security Losses Hit $3.63 Billion as Attacks Outrun Audits and Insurance

Security remains a core concern across cryptocurrency, yet losses keep climbing. CoinGecko’s 2026 State of Crypto Security Report, published in late August, found that platforms lost $3.63 billion in 245 documented incidents from January 2025 through July 2026.

A small number of large events drove most of the damage.

The ten biggest attacks accounted for more than 72.5 percent of the total value taken.

Infrastructure and supply-chain failures were the costliest category for both centralized exchanges and decentralized platforms, exceeding $1.8 billion.

Notable examples included security breakdowns at Bybit and KelpDAO.

Risks differ by architecture. Centralized exchanges most often fail through compromised private keys.

Decentralized applications lost roughly $546 million to sophisticated smart-contract exploits.

Both types remain exposed to oracle and market manipulation as well as internal-mechanism errors, with losses recorded at Bitget, Binance, and Hyperliquid.

Attackers have also used fake interfaces and malicious integrations to expand their reach.

The threat actors themselves have professionalized. Isolated operators have given way to organized groups and state-linked teams, including North Korean actors that move funds through mixers, bridges, and staggered withdrawals to reduce traceability.

Independent audits have not closed the gap. About 60 percent of exploited platforms—147 of 245—had completed third-party security reviews before they were compromised.

Those audited projects represented 88.44 percent of all capital drained over the 19-month period.

Most successful attacks sat outside conventional audit scope, targeting external infrastructure, unaudited code updates, or governance features.

Only about 11 percent of incidents involved in-scope smart-contract flaws, though those still produced $396 million in losses.

Centralized venues typically rely on compliance frameworks and proof-of-reserves rather than public smart-contract audits, yet those measures offer limited protection against social engineering or key-management failures.

On-chain insurance has contracted even as incidents have multiplied. Active coverage among leading crypto insurance protocols fell 20.2 percent, from $163.2 million to $130.2 million, while cumulative payouts stayed near $33 million.

High perceived risk has discouraged both capital providers and buyers facing elevated premiums.

Coverage is often narrow, limited to verified smart-contract or infrastructure failures and excluding human error, private-key theft, or market volatility.

By August 2026, five of nine on-chain insurance protocols had gone inactive or shifted to other businesses.

Several centralized exchanges have responded by launching their own protection funds to cover users after an exploit. The report also highlights security infrastructure adopted by venues such as Toobit.

The overall picture is one of evolving tactics outpacing established controls. Audits, insurance, and compliance remain useful but leave substantial exposure in supply chains, key custody, and operational layers that conventional reviews rarely cover in full.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend