Crypto Hacks Cost $3.63B and Audits Failed to Stop 88% of Losses

By Giuseppe Ciccomascolo // August 27, 2026 @ 08:09 PM Make AlphaWire Logo preferred on Google News

Share

Teen Mastermind to Plead Guilty in $240M Bitcoin Heist

Share

Points of Focus

  • Crypto platforms lost $3.63 billion between January 2025 and July 2026.
  • Around 60% of hacked platforms had undergone independent security audits.
  • Only 11% of incidents involving audited platforms came from vulnerabilities within the conventional audit scope.

 

 

Crypto platforms have lost more than $3.63 billion to hacks and exploits since the beginning of 2025, exposing the limits of traditional security audits as attackers increasingly target infrastructure, private keys, and vulnerabilities outside smart contract code.

CoinGecko’s 2026 State of Crypto Security report found 245 documented security incidents between January 2025 and July 2026. The 10 largest attacks alone accounted for more than 72.5% of all funds stolen, showing how a handful of major breaches can dominate industry-wide losses.

Perhaps more concerning, roughly 60% of the compromised platforms had previously undergone independent security audits. Those audited projects accounted for 88.44% of the total capital lost, suggesting that passing an audit is far from a guarantee against increasingly sophisticated attacks.

The report also highlighted a growing protection gap. While crypto losses have climbed, active coverage offered by leading onchain insurance protocols has fallen more than 20%.

 

Audited platforms accounted for most losses

Of the 245 incidents documented by CoinGecko, 147 affected platforms that had completed an independent audit before they were compromised.

However, that does not necessarily mean auditors missed billions of dollars in vulnerable smart contract code.

 

Top 20 largest crypto hacks
Top 20 largest crypto hacks. Source: CoinGecko

 

CoinGecko found that only around 11% of incidents involving audited platforms stemmed from vulnerabilities that actually fell within the scope of conventional smart contract audits. Those flaws nevertheless resulted in approximately $396 million in losses.

Most attacks instead exploited areas outside the original audit scope, including external infrastructure, unaudited code updates, governance mechanisms, and other operational weaknesses.

Infrastructure and supply-chain attacks were particularly damaging, generating more than $1.8 billion in losses. Centralized exchanges remained especially vulnerable to compromised private keys, while decentralized applications lost about $546 million through smart contract exploits.

Crypto insurance coverage shrinks as hacks rise

The rise in attacks has not translated into greater insurance coverage.

Active coverage across leading crypto insurance protocols dropped 20.2%, from $163.2 million to $130.2 million, while cumulative payouts remained around $33 million.

 

Crypto hacks breakdown by attack vendor
Crypto hacks breakdown by attack vendor. Source: CoinGecko

 

CoinGecko said elevated risk, expensive premiums, and restrictive coverage conditions have limited adoption. Policies may cover specific smart contract or infrastructure failures while excluding incidents caused by compromised private keys, human error, or other vulnerabilities.

The sector has consequently struggled to gain scale. As of August 2026, five of the nine onchain insurance protocols CoinGecko examined had either become inactive or pivoted into other businesses.

Exchanges turn to their own protection funds

With third-party coverage remaining limited, centralized exchanges are increasingly relying on self-funded protection mechanisms designed to compensate customers after major security incidents.

The trend reflects a broader shift in crypto security.

 

CEX protection funds
CEX protection funds. Source: CoinGecko

 

Audits remain an important defense against code-level vulnerabilities, but CoinGecko’s findings suggest the industry’s largest losses increasingly originate elsewhere.

As hackers move toward supply chains, stolen credentials, social engineering, and infrastructure attacks, platforms may need to treat audits as only one layer of security rather than proof that users’ funds are safe.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles