Almost eight months have passed in 2026, and the frequency of scams is yet to slow down. In fact, in H1 2026 alone, attackers carried out 207 separate hacks.
And yet, despite the hike in incidents, total losses were just $972 million, less than half of the $2.3 billion stolen during the first half of 2025.
CoinGecko’s recent report titled ‘2026’s State of Crypto Security’ shed light on the fact that between January 2025 and July 2026, crypto platforms saw 245 documented security incidents. These resulted in $3.63 billion in losses.
Yearly crypto hack breakdown
The damage was so massive that the largest 10 attacks accounted for more than 72.5% of all stolen funds. According to the report, DEXs and dApps faced greater exposure to smart-contract exploits, with around $546 million lost through such attacks.
However, threats increasingly extended beyond core code. Notably, more than $1.8 billion was lost to infrastructure and supply-chain vulnerabilities, including weaknesses in third-party services, integrations, and updates.
Of these, high-profile case studies included the security failures at Bybit and KelpDAO.


Of the 245 documented incidents, 147 involved audited protocols, which accounted for 88.44% of stolen capital.
However, only about 11% of these attacks targeted vulnerabilities within the audit’s scope, causing around $396 million in losses. Most attacks exploited areas such as infrastructure, third-party services, governance, front ends, or human error.


What else did the report say?
Despite the hike in crypto hacks, active insurance coverage fell to 20.2%, from $163.2 million to $130.2 million. This, while cumulative payouts remained around $33 million.
Here, it must be pointed out that the sector is also struggling to scale, with 5 of 9 on-chain insurance protocols becoming inactive or pivoting by August 2026.
This, on the back of the SEC revisiting its Custody Rule to clarify who can safeguard customer crypto.
On 25th August, they submitted proposed amendments to OIRA for review, with publication expected by October 2026, followed by at least 60 days of public comments. However, the rules are not yet effective. A further analysis and a second SEC vote mean mandatory compliance and could still take several years.
Final Summary
- Largest 10 attacks accounted for more than 72.5% of all stolen funds.
- Of the 245 documented incidents, 147 involved audited protocols, which accounted for 88.44% of all stolen capital.




Be the first to comment