CoinGecko: Crypto hacks cost $3.63B in 19 months
CoinGecko says crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, and a small number of huge breaches did most of the damage.
- Top 10 attacks: more than 72.5% of stolen funds
- Largest loss: Bybit’s February 2025 breach
- Main weak spots: infrastructure, supply chain, and private keys
- Insurance backstop: shrinking, not scaling
The State of Crypto Security Report paints a familiar but still embarrassing picture for the industry: crypto keeps spending energy polishing its code while attackers keep targeting the mess around it, keys, developer machines, front ends, dependencies, and operational workflows. The contract may be fine. The rest of the machine, not so much.
A few giant hacks did most of the damage
CoinGecko says the ten largest attacks accounted for more than 72.5% of all recorded stolen funds. That concentration matters because it shows how a handful of failures can dominate the sector’s risk picture. One bad breach can do more damage than a hundred small ones combined.
The report puts infrastructure and supply-chain compromises at more than $1.8 billion in losses. In plain English, that means attackers often went after the systems around the protocol rather than the contract logic itself. Think compromised employee devices, malicious updates, vendor dependencies, bridge infrastructure, or tampered interfaces. The “front end” is the website or app users interact with. If that gets hijacked, the onchain code may never get a fair fight.
CoinGecko identifies private-key compromise as the leading risk for centralized exchanges. That is the core custody problem in one sentence: whoever controls the keys often controls the assets. If those keys are stolen, social-engineered, or exposed through sloppy operational security, the money can disappear fast.
On the decentralized side, CoinGecko says decentralized applications lost about $546 million through smart-contract exploits. That is still a brutal number, but the report adds an important wrinkle: only 11% of incidents involved vulnerabilities covered by routine smart-contract audit scopes, and those in-scope failures caused about $396 million in losses.
That is the part the industry keeps trying to wave away. A routine audit can help, but it does not secure everything. It is a review of contract code at a point in time, not a guarantee that keys, front ends, developers, vendors, or update pipelines are safe. If a project markets an audit like a force field, that is just expensive confidence cosplay.
The biggest breach still sets the tone
The largest incident in CoinGecko’s dataset was the February 2025 Bybit breach, which the report places at about $1.44 billion in losses. Chainalysis has described the theft as nearly $1.5 billion worth of ether, so the exact valuation varies by source and method, but the scale is not in dispute: it was enormous.
Chainalysis said the Bybit attack involved a compromise of a Safe developer’s computer and malicious frontend manipulation that made a transaction appear legitimate. That is a useful reminder that crypto’s biggest losses are often not caused by some dramatic onchain wizardry. They come from the boring, ugly stuff: compromised systems, deceptive interfaces, and people being tricked into signing the wrong thing.
Other major incidents cited by CoinGecko include the KelpDAO breach at $292 million, the Drift Protocol attack at $285 million, and the Cetus exploit at $223 million. These are not nuisance losses. They are large enough to shake confidence, distort markets, and remind everyone that “decentralized” does not automatically mean “hard to break.”
Chainalysis also said it helped freeze more than $40 million in stolen Bybit funds. That does not undo the theft, but it does push back against the lazy claim that blockchain crime is always final and irreversible. Public ledgers are transparent, and that transparency can help investigators trace flows and move quickly enough to block some exits. Not a cure. A better-than-nothing tool.
Why audits keep missing the real attack surface
CoinGecko says 147 incidents involved audited platforms, and those platforms accounted for 88.44% of reported losses. That does not mean audits caused the losses. It means many victims had already been through standard review processes, yet still got hit through paths those reviews did not fully cover.
That distinction matters. A smart-contract audit can catch logic bugs in code, but it usually does not prove safe custody, strong key management, secure employee devices, trustworthy integrations, or resilient operational controls. If a bridge, exchange, or app can be gutted by a stolen key or a compromised build pipeline, the security problem is bigger than the audit report.
Here is the clean version of the lesson: audits are useful, but they are narrow. Crypto’s attack surface is wider. The gap between those two facts is where attackers keep making money.
Onchain insurance is shrinking while losses stay huge
The report also says the industry’s crypto-native backstops are under strain. Active onchain insurance coverage fell 20.2% during the period, declining from $163.2 million to $130.2 million. Cumulative payouts remained near just $33 million.
Onchain insurance is a crypto-native form of coverage offered by decentralized protocols. In practice, it is still small, narrow, and nowhere near the scale needed to match the kind of losses crypto keeps generating. A healthy risk market would not shrink while the wreckage keeps piling up.
CoinGecko also notes that five of the nine protocols it tracked had become inactive or moved into other business areas by August 2026. That says a lot about how fragile this corner of the market still is. If the firms meant to absorb risk are disappearing, pivoting, or going quiet, the “coverage” may be more theoretical than reassuring.
Centralized exchanges have increasingly leaned on protection funds or self-funded reserves instead. That can help, but it is not the same thing as insurance. A protection fund is an exchange-controlled pool of money, not an external policy with the same obligations, transparency, or scope. Users should not confuse a reserve with a real backstop just because both sound comforting in a press release.
What this means for crypto security
The numbers point to one blunt conclusion: crypto security problems are increasingly operational, not just code-level. The old habit of treating a smart-contract audit like the finish line is not just outdated, it is dangerous.
The biggest threats now sit in the seams:
Smart-contract risk is the code itself, where bugs can be exploited onchain.
Operational and key-management risk is everything around the code, including custody, access controls, employee devices, and signing processes.
Supply-chain and frontend risk covers the vendors, updates, dependencies, and interfaces users rely on before anything ever reaches the chain.
That broader view is where the industry has to mature. A protocol can be well audited and still be soft in all the places that matter most. A centralized exchange can prove asset holdings with a proof-of-reserves attestation and still be weak on operational security. A public dashboard can look tidy while the actual attack surface is a disaster zone.
There is a more useful, less melodramatic takeaway too: crypto’s transparency makes these failures visible. The same public ledgers that help thieves move money also help investigators trace it. That is not enough, but it is real. The sector can see its weaknesses more clearly than many legacy systems ever could. The problem is that seeing a hole is not the same thing as fixing it.
Key takeaways
-
Were most losses caused by bad smart contracts?
No. CoinGecko says many of the biggest losses came from infrastructure and supply-chain compromises outside routine smart-contract audit scope. -
Did audits matter?
Yes, but only partly. Audits can catch some contract bugs, yet they do not secure keys, front ends, employee devices, vendor dependencies, or other operational weak points. -
Is onchain insurance growing?
No. Active coverage fell 20.2%, from $163.2 million to $130.2 million, while cumulative payouts stayed near $33 million. -
What was the biggest incident?
The February 2025 Bybit breach, which CoinGecko places at about $1.44 billion and Chainalysis describes as nearly $1.5 billion worth of ether. -
Are protection funds the same as insurance?
No. Protection funds are exchange-held reserves, usually self-funded and more discretionary, not the same as external or regulated insurance coverage.
Crypto does not need more hype about “trustless” systems. It needs less sloppy operational security, tighter key management, and fewer teams pretending an audit report means the job is done. Otherwise the industry will keep earning the same lesson the hard way: a clean contract is nice, but a compromised stack will still torch the treasury.
Further reading
For a broader look at the security mess and how expensive it keeps getting, these are worth your time.
- Cryptocurrency Security Losses Exceed $3.63 Billion Since
- 60% of Hacked Crypto Platforms Had Security Audits
- The 2026 Crypto Crime Report
- Crypto Hacks Top $17B as Private Keys and Bridges Become Prime Targets
- Web3 Security Crisis: $482M Lost to Crypto Hacks in Q1
- Crypto Hacks Soar 96% in March 2023: $52M Lost in DeFi and