BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

CoinGecko 2026 Cryptocurrency Security Report

golem
Odaily资深作者
@web3_golem
2026-08-28 07:29
This article is about 1603 words, reading the full article takes about 3 minutes
Since 2025, $3.63 billion has been stolen in the crypto space.
AI Summary
Expand
  • Key Takeaway: Since the start of 2025, the cryptocurrency sector has lost over $3.63 billion due to security vulnerabilities. Attack methods are continuously evolving, with most incidents exceeding the scope of traditional audits. Meanwhile, insurance underwriting capacity has declined, prompting centralized exchanges to rely on self-funded protection funds to manage risks.
  • Key Elements:
    1. Between January 2025 and July 2026, 245 security incidents resulted in total losses of $3.63 billion, with the top ten attacks accounting for over 72.5% of the total.
    2. Infrastructure and supply chain vulnerabilities proved to be the most destructive, causing over $1.8 billion in losses; centralized exchanges were primarily impacted by private key leaks, while decentralized applications lost $546 million due to smart contract vulnerabilities.
    3. 147 attacks targeted protocols that had previously passed audits, accounting for 88.44% of total losses; however, only about 11% of the vulnerabilities fell within the realm of smart contracts, as most attacks targeted external infrastructure or unaudited code updates.
    4. Effective coverage from leading crypto insurance protocols declined by 20.2% to $130.2 million, with cumulative payouts of approximately $33 million; due to limited coverage and insufficient user demand, 5 of the 9 on-chain insurance protocols have ceased operations or pivoted their business models.
    5. To bridge the insurance gap, centralized exchanges are launching protection funds designed to ensure users receive financial safeguards in the event of vulnerability-related attacks.

Security remains a top priority in the cryptocurrency space, yet security losses continue to climb, with $3.63 billion stolen since 2025. Centralized exchanges are most vulnerable to private key compromise, while decentralized exchanges face threats from smart contract vulnerabilities. Fake user interfaces and malicious integrations have also exacerbated the problem.

Attackers are also rapidly "evolving." From initial individual hackers to organized crime syndicates and state-sponsored hacker groups (including North Korean hackers), they now employ tactics such as mixers, cross-chain bridges, and phased withdrawals to hide their tracks. This report analyzes the evolving threat landscape, covering everything from audit and insurance protocols to the security infrastructure deployed by centralized exchanges like Toobit to protect users.

Here are the four key highlights from CoinGecko's 2026 Cryptocurrency Security Report.

  • Since early 2025, crypto platforms have lost over $3.63 billion, primarily due to supply chain attacks, smart contract vulnerabilities, and private key theft;
  • Approximately 60% of attacked crypto platforms had completed independent security audits, yet most attacks exceeded the scope of traditional audits;
  • Despite the increase in exploit incidents, the effective coverage of crypto insurance platforms has dropped by 20.2%, from $163.2 million to $130.2 million;
  • Centralized exchanges have launched protection funds to ensure users are safeguarded in the event of exploits.

Since Early 2025, Crypto Platforms Have Lost Over $3.63 Billion

The frequency of exploits targeting cryptocurrencies has reached a new level. In recent years, crypto platforms have suffered severe security breaches. Between January 2025 and July 2026, crypto platforms lost up to $3.63 billion across 245 recorded incidents. Notably, the top ten attacks accounted for over 72.5% of the total losses during this period.

Infrastructure and supply chain vulnerabilities have proven to be the most destructive for both centralized and decentralized exchanges, with losses from such vulnerabilities exceeding $1.8 billion. The security breaches at Bybit and KelpDAO are two typical examples.

Vulnerabilities vary significantly across different platform architectures. For centralized exchanges, the most common point of failure remains private key compromise. In contrast, decentralized applications have lost $546 million due to complex smart contract vulnerabilities.

Despite these differences, both types of platforms are susceptible to oracle and market manipulation. Internal mechanism errors have led to significant losses for prominent institutions, including Bitget, Binance, and Hyperliquid.

Most Attacks Exceed the Scope of Traditional Audits

Even for audited platforms, pervasive security vulnerabilities remain an ongoing threat. Since early 2025, 147 of the 245 recorded incidents involved protocols that had undergone audits prior to being breached. These audited entities account for as much as 88.44% of the total funds lost over the past 19 months.

Audit reports often fail to provide a comprehensive view of risk. Most attacks targeting audited systems exploited external infrastructure, unaudited code updates, or system features manipulated through governance attacks. Surprisingly, only about 11.0% of incidents involved vulnerabilities within the smart contract scope, yet even these still resulted in $396 million in losses.

Centralized platforms employ a different security paradigm. Although centralized exchanges typically bypass decentralized audit processes, they must comply with strict regulatory frameworks and financial attestations (such as proof of reserves) to bolster user confidence. However, these safeguards offer little protection against social engineering attacks or catastrophic private key security failures.

Effective Coverage of Crypto Insurance Platforms Drops by 20.2%

Despite the increase in attack incidents, the effective coverage of top crypto insurance protocols has steadily declined by 20.2%, from $163.2 million to $130.2 million, while cumulative payouts have remained largely flat at $33 million.

This is likely due to the already elevated risk levels in the cryptocurrency space, which makes users reluctant to commit funds and unwilling to purchase insurance at high prices.

Furthermore, crypto-based coverage can be extremely limited, often restricted to verified smart contract vulnerabilities or infrastructure failures. If an exploit stems from human error, private key compromise, or market volatility, users may be unable to receive compensation.

Consequently, demand for on-chain insurance has never truly gained traction. As of August 2026, 5 of the 9 on-chain insurance protocols have ceased operations or pivoted to other areas.

Insurance Funds Launched by Centralized Exchanges

exchange
Safety
smart contract
currency
Welcome to Join Odaily Official Community