Security remains a top priority across crypto, yet losses continue to climb, with $3.63 billion stolen since 2025. CEXes are most exposed through private key compromise, while DEXes face smart contract exploits, increasingly compounded by fake UIs and malicious integrations.
The actors have evolved just as fast. Rogue individuals have given way to organized cartels and state-sponsored groups, including North Korean hackers, who now use mixers, bridges, and staggered withdrawals to stay untraceable. This report examines the shifting threat landscape, from auditing and insurance protocols to the security infrastructure CEXes like Toobit deploy to protect users.
We’ve summarized the key highlights, but be sure to dig into the full 15 slides in the full report below.
Top 4 Highlights of CoinGecko’s State of Crypto Security Report 2026
-
Crypto Platforms Have Lost Over $3.63B Since The Start of 2025, Largely Due To Supply-Chain Attacks, Smart Contract Exploits, and Stolen Private Keys
-
Roughly 60% of Exploited Crypto Platforms Had Completed Independent Security Audits, Though Most Attacks Fall Beyond the Conventional Audit Scope
-
Active Coverage by Crypto Insurance Platforms Has Fallen -20.2% from $163.2M to $130.2M Despite the Rise in Exploits
-
Centralized Exchanges Launch Protection Funds to Guarantee User Coverage in the Event of an Exploit
1. Crypto Platforms Have Lost Over $3.63B Since The Start of 2025, Largely Due To Supply-Chain Attacks, Smart Contract Exploits, and Stolen Private Keys


The frequency of crypto-specific exploits has reached unprecedented levels in recent years. Between January 2025 and July 2026, crypto platforms suffered a staggering $3.63 billion in losses across 245 documented incidents. Notably, the top 10 largest attacks accounted for more than 72.5% of the total value stolen during this period.
Infrastructure and supply chain vulnerabilities have proven to be the most devastating for both CEXes and DEXes, with over $1.8 billion lost to such breaches. High-profile examples include the security failures at Bybit and KelpDAO.
Vulnerabilities vary significantly across different platform architectures. For centralized exchanges (CEXes), the most prevalent point of failure remains the compromise of private keys. Conversely, decentralized applications (dApps) saw $546 million drained due to sophisticated smart contract exploits.
Despite these differences, both platform types remain susceptible to oracle and market manipulation. Internal-mechanism errors have led to significant losses for prominent entities, including Bitget, Binance, and Hyperliquid.
2. Roughly 60% of Exploited Crypto Platforms Had Completed Independent Security Audits, Though Most Attacks Fall Beyond the Conventional Audit Scope

The prevalence of security breaches remains a persistent threat, even for vetted platforms. Out of 245 documented incidents since early 2025, 147 involved protocols that had undergone audits before being compromised. These vetted entities represented a staggering 88.44% of the total capital drained over the last 19 months.
Audit reports often fail to capture the full spectrum of risk. Most exploits on audited systems target external infrastructure, unaudited code updates, or systemic features manipulated via governance attacks. Surprisingly, only about 11.0% of these incidents involved in-scope smart contract flaws, though these still resulted in $396.0 million in losses.
Centralized platforms operate under different security paradigms. While CEXes typically bypass decentralized audit formats, they must navigate rigorous compliance frameworks and financial attestations, such as Proof-of-Reserve, to bolster user confidence. Nonetheless, these protections offer little defense against social engineering or catastrophic failures in private key security.
3. Active Coverage by Crypto Insurance Platforms Has Fallen -20.2% from $163.2M to $130.2M Despite the Rise in Exploits

Despite the rise in exploits, active coverage on the top crypto insurance protocols has steadily decreased by -20.2% from $163.2 million to $130.2 million, while cumulative payouts have largely remained stagnant at $33.0 million.
This is likely due to already-heightened risk levels in the crypto space, which has discouraged users from providing capital as well as purchasing premiums at elevated prices.
Furthermore, the scope of crypto-based protection can be extremely restrictive, limiting claims to only verified smart contract exploits or infrastructure failures. Users may be unable to receive a payout if the exploit stems from human error, compromised private keys or general market volatility.
As such, the demand for on-chain cover has never truly entered the limelight; as of August 2026, 5 of the 9 on-chain insurance protocols have gone inactive or pivoted to other segments.
4. Centralized Exchanges Launch Protection Funds to Guarantee User Coverage in the Event of an Exploit

Read the Report: CoinGecko’s State of Crypto Security Report 2026
We would appreciate a link credit to our State of Crypto Security Report 2026 on CoinGecko if any insights are used. A link credit allows us to keep supplying you with data-led content that you may find useful.
If you have an account on CoinGecko, you can browse and download previous reports here! Not yet a CoinGecko user? Create an account now.
Receive daily crypto updates, straight in your inbox - sign up for our newsletter today!