Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, with audited protocols accounting for 88.44 percent of all stolen capital.
Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, with audited protocols accounting for 88.44 percent of all stolen capital.

Crypto platforms lost $3.63 billion across 245 documented security incidents from January 2025 through July 2026, according to CoinGecko's 2026 State of Crypto Security Report published in late August.
"Infrastructure and supply-chain vulnerabilities have proven to be the most devastating for both CEXes and DEXes," the report read, citing weaknesses in third-party services, integrations, and updates as the largest single category of losses.
Of the 245 incidents, 147 involved protocols that had completed independent security audits before being breached, and those platforms accounted for 88.44 percent of stolen funds. Yet only 11 percent of exploits targeted vulnerabilities within the audit's scope, causing roughly $396 million in losses. Infrastructure and supply-chain attacks drained more than $1.8 billion, while smart-contract exploits on decentralized applications cost about $546 million. The 10 largest attacks produced 72.5 percent of everything taken across the 19-month window.
The damage is concentrated in a handful of events — the Bybit exchange breach alone accounted for approximately $1.436 billion, followed by KelpDAO at $292 million and Drift Protocol at $285 million. Active on-chain insurance coverage fell 20.2 percent to $130.2 million, with five of nine insurance protocols going inactive or pivoting by August 2026. The SEC submitted proposed amendments to its Custody Rule to the Office of Information and Regulatory Affairs on Aug. 25, with publication expected by October 2026.
The first seven-plus months of 2026 recorded 164 breaches, nearly 70 percent more than the 97 incidents logged across all of 2025. DefiLlama data shows 233 separate incidents so far in 2026 worth roughly $1.31 billion, compared with 92 incidents and $2.37 billion in losses during the same stretch of 2025. Average loss per incident dropped from $25.8 million to $5.6 million, though the $1.5 billion Bybit theft inflated the prior-year total.
Smaller attacks now arrive frequently. August alone brought an $8.5 million governance exploit at Term Labs. May's Stake DAO breach showed the limit of contract reviews — an attacker compromised a deployer key rather than exploiting contract logic. On centralized exchanges, stolen private keys remained the most common point of failure.
Active underwriting on major on-chain insurance protocols fell about 20 percent to roughly $130 million, with several protocols becoming inactive or shifting focus. Cumulative payouts remained around $33 million. Some centralized exchanges have expanded their own user protection funds in response.
The threat surface extends beyond digital attacks. Chainalysis identified approximately 158,000 personal-wallet compromise incidents in 2025, affecting at least 80,000 unique victims. Physical crypto theft is also rising — criminals stole more than $30 million through kidnappings and home invasions in 2026, on pace to exceed the $58 million taken through such attacks in 2025.
The SEC's proposed Custody Rule amendments, submitted to OIRA on Aug. 25, could reshape who can safeguard customer crypto. Publication is expected by October 2026, followed by at least 60 days of public comments, a second SEC vote, and a compliance timeline that could stretch several years.
This article is for informational purposes only and does not constitute investment advice.