Points of Focus
- Crypto platforms lost $3.63 billion between January 2025 and July 2026.
- Around 60% of hacked platforms had undergone independent security audits.
- Only 11% of incidents involving audited platforms came from vulnerabilities within the conventional audit scope.
Crypto platforms have lost more than $3.63 billion to hacks and exploits since the beginning of 2025, exposing the limits of traditional security audits as attackers increasingly target infrastructure, private keys, and vulnerabilities outside smart contract code.
CoinGecko’s 2026 State of Crypto Security report found 245 documented security incidents between January 2025 and July 2026. The 10 largest attacks alone accounted for more than 72.5% of all funds stolen, showing how a handful of major breaches can dominate industry-wide losses.
Perhaps more concerning, roughly 60% of the compromised platforms had previously undergone independent security audits. Those audited projects accounted for 88.44% of the total capital lost, suggesting that passing an audit is far from a guarantee against increasingly sophisticated attacks.
The report also highlighted a growing protection gap. While crypto losses have climbed, active coverage offered by leading onchain insurance protocols has fallen more than 20%.
Audited platforms accounted for most losses
Of the 245 incidents documented by CoinGecko, 147 affected platforms that had completed an independent audit before they were compromised.
However, that does not necessarily mean auditors missed billions of dollars in vulnerable smart contract code.

CoinGecko found that only around 11% of incidents involving audited platforms stemmed from vulnerabilities that actually fell within the scope of conventional smart contract audits. Those flaws nevertheless resulted in approximately $396 million in losses.
Most attacks instead exploited areas outside the original audit scope, including external infrastructure, unaudited code updates, governance mechanisms, and other operational weaknesses.
Infrastructure and supply-chain attacks were particularly damaging, generating more than $1.8 billion in losses. Centralized exchanges remained especially vulnerable to compromised private keys, while decentralized applications lost about $546 million through smart contract exploits.
Crypto insurance coverage shrinks as hacks rise
The rise in attacks has not translated into greater insurance coverage.
Active coverage across leading crypto insurance protocols dropped 20.2%, from $163.2 million to $130.2 million, while cumulative payouts remained around $33 million.

CoinGecko said elevated risk, expensive premiums, and restrictive coverage conditions have limited adoption. Policies may cover specific smart contract or infrastructure failures while excluding incidents caused by compromised private keys, human error, or other vulnerabilities.
The sector has consequently struggled to gain scale. As of August 2026, five of the nine onchain insurance protocols CoinGecko examined had either become inactive or pivoted into other businesses.
Exchanges turn to their own protection funds
With third-party coverage remaining limited, centralized exchanges are increasingly relying on self-funded protection mechanisms designed to compensate customers after major security incidents.
The trend reflects a broader shift in crypto security.

Audits remain an important defense against code-level vulnerabilities, but CoinGecko’s findings suggest the industry’s largest losses increasingly originate elsewhere.
As hackers move toward supply chains, stolen credentials, social engineering, and infrastructure attacks, platforms may need to treat audits as only one layer of security rather than proof that users’ funds are safe.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


