Crypto Platforms Lose $3.63 Billion To Hacks Since 2025, CoinGecko Report

Blockonomics
Blockonomics


Crypto security has always remained a major challenge for investors. Attackers continue to target centralized and decentralized platforms with new methods. According to CoinGecko 2026 State of Crypto Security Report, crypto platforms recorded $3.63 billion in losses. This loss comes from 245 documented security incidents between January 2025 and July 2026.

The exclusive report by CoinGecko further highlights a shift in the crypto security landscape. Latest attacks are linked to organized criminal groups and state-sponsored actors, i.e., the North Korean hacking groups. The attackers have adopted more sophisticated methods, using mixers and bridges to make tracking of funds more difficult.

Supply Chain Attacks and Key Compromises Drive Major Losses

In 2025 and 2026, infrastructure and supply-chain vulnerabilities emerged as some of the most damaging attack vectors. These incidents resulted in more than $1.8 billion in losses across centralized exchanges (CEXs) and decentralized platforms. The major examples of these incidents include Bybit and KelpDAO.

The primary vulnerabilities vary depending on the type of platform. Attackers find the loopholes and then plan the heist accordingly. Private key compromises remain a major security risk for centralized exchanges. However, decentralized applications (dApps) are more prone to sophisticated smart contract exploits.

coinbase

In the same period, crypto platforms also faced oracle and market manipulation attacks. Even the most renowned platforms fell prey to this method, including Bitget, Binance, and Hyperliquid. Meanwhile, decentralized exchanges and applications remain exposed to smart contract vulnerabilities that can be compounded by malicious integrations and fraudulent user interfaces.

Security Audits Failed to Prevent Most Major Losses

The report by CoinGecko questions the effectiveness of conventional security audits. Around 60% of the exploited platforms had undergone independent security audits before suffering an attack. Despite having completed audits, these platforms accounted for 88.44% of the total capital stolen during the period.

CoinGecko noted that most attacks occurred outside the scope of traditional audits. Only around 11% of incidents involved smart contract vulnerabilities. Many other incidents involved external infrastructure, unaudited code changes, or systemic weaknesses exploited through governance attacks. Centralized platforms face additional risks, including social engineering and private key compromises.

Crypto Insurance Coverage Falls Despite Rising Security Risks

Crypto insurance has also struggled to keep pace with the growing threat environment. Active coverage from leading on-chain insurance protocols declined 20.2%. The rate has fallen from $163.2 million to $130.2 million. At the same time, cumulative payouts remained relatively unchanged at $33 million.

CoinGecko attributed the decline in coverage to elevated security risks. This fact is discouraging both capital providers and users from purchasing insurance. Restrictive policy terms also limit protection. Many policies exclude risks such as human error, compromised private keys, and market volatility. This makes users skip the idea of insurance. This has resultantly caused 5 out of 9 on-chain insurance protocols either becoming inactive or shifting their focus to other areas.

As security threats continue to evolve, centralized exchanges are increasingly introducing protection funds. With an aim of providing users with additional coverage in case a security incident hits, protection funds are somehow replacing crypto insurance. The extensive findings of CoinGecko highlight the limitations of relying on a single security measure.



Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*