Crypto Hacks Have Cost the Industry $3.63B in 2026
The crypto industry has lost $3.63 billion to hacks and exploits between January 2025 and July 2026, according to CoinGecko's newly released "2026 State of Crypto Security Report," with 245 documented incidents and the top 10 attacks accounting for over 72.5% of total losses.
Key findings from CoinGecko's 2026 security report
1. Total losses: $3.63 billion stolen across 245 security incidents from January 2025 through July 2026.
2. Incident surge: 2026 alone has already seen 164 incidents in just seven months, nearly 70% more than the full-year 2025 count of 97.
3. Concentration risk: The 10 largest hacks represent more than 72.5% of the total value stolen, underscoring how a few catastrophic breaches drive headline losses.
4. Average loss per incident: Roughly $26.3 million in 2025 (heavily skewed by Bybit), dropping to about $7.3 million in 2026 as incident frequency rises but individual sizes shrink.
5. Notable breaches: Bybit ($1.43 billion) and KelpDAO ($292 million) stand out as the two largest single incidents in the period.
Where the money is going
CoinGecko breaks down losses by how attackers got in, not just who got hit. The biggest bucket is infrastructure and supply-chain style failures, which have caused over $1.8 billion in damage across both centralized and decentralized platforms.
1. Supply-chain & infrastructure attacks: $1.806 billion in losses, making this the single costliest category.
2. Smart contract exploits: $777 million lost, predominantly affecting DeFi protocols and dApps.
3. Private key compromises: $431 million stolen, with centralized exchanges (CEXes) especially exposed to key management failures.
4. Social engineering & related vectors: Around $311 million, reflecting phishing, fake UIs, and manipulated integrations.
Architecture matters. CEXes tend to fail via private key compromise and operational security gaps, while dApps and DeFi protocols lose funds mainly through smart contract bugs, oracle manipulation, and governance attacks.
The audit paradox
One of the report's most uncomfortable findings is that security audits are not a silver bullet. Out of 245 incidents, 147 involved platforms that had completed independent security audits before being exploited.
1. Audited but breached: 60% of hacked platforms had prior audits.
2. Loss concentration: These audited platforms account for 88.44% of all funds stolen in the period.
3. In-scope flaws: Only about 11% of incidents involved vulnerabilities that would typically fall within a standard smart contract audit scope, though those still resulted in roughly $396 million in losses.
The takeaway is not that audits are useless, but that many breaches stem from external infrastructure, unaudited code paths, upgraded contracts, or systemic design flaws that routine audits don't fully cover.
2025 vs 2026
The data tells two stories at once. 2025 saw $2.55 billion lost across 97 incidents, heavily inflated by the Bybit breach attributed to North Korean actors. Excluding Bybit, 2025's remaining 96 incidents totaled around $1.1 billion.
In contrast, 2026 (January-July) shows:
1. $1.2 billion lost across 164 incidents.
2. Lower average loss per incident ($7.3 million) but much higher frequency, indicating a broader, more distributed attack surface.
3. April 2026 spike: Over $644 million lost in a single month, with several incidents again linked to North Korean–associated groups.
Historically, 2022 was the previous peak year for crypto losses at $2.77 billion; 2025's $2.55 billion came close, and with 2026 already on pace for a high incident count, the industry is clearly facing a structural escalation in threat volume.
DeFi's collateral damage
The report highlights how hacks create ripple effects far beyond the immediate stolen funds. The KelpDAO exploit, which leveraged a LayerZero bridge vulnerability, didn't just drain assets; it triggered a broader loss of confidence.
1. Aave TVL impact: Aave's total value locked fell from roughly $26 billion to $14.4 billion after the incident, a $11.5 billion drop that dwarfs the direct exploit amount.
2. Token price contagion: Assets like STEP, DRIFT, and BONK saw sharp declines following major hacks, even when not directly compromised, as risk-off sentiment spread.
This "collateral damage" is a key reason why security is a market-wide issue, not just a protocol-level problem.
Insurance is shrinking just as risk is rising
While exploits climb, on-chain insurance capacity is contracting. CoinGecko notes that active coverage across top crypto insurance protocols fell by 20.2%, from $163.2 million to $130.2 million, even as cumulative payouts have remained largely flat around $33 million.
Drivers include:
1. High risk perception: Elevated exploit frequency discourages capital providers and pushes premiums up.
2. Narrow coverage: Many policies only cover specific smart contract exploits or infrastructure failures, excluding human error, key compromises, or market volatility.
3. Protocol attrition: As of August 2026, 5 of 9 on-chain insurance protocols have gone inactive or pivoted to other segments.
In response, several centralized exchanges have launched or expanded their own protection funds to guarantee user coverage in the event of an exploit, effectively internalizing part of the insurance function.
Who's behind the attacks?
The actor landscape has matured from lone hackers to organized cartels and state-sponsored groups. North Korean–linked actors feature prominently in the data, with the Bybit breach in 2025 and a cluster of April 2026 incidents attributed to groups associated with Pyongyang.
These actors increasingly use:
1. Mixers and bridges to obscure fund flows.
2. Staggered withdrawals and complex laundering chains to stay untraceable.
3. Cross-chain strategies to move assets quickly between ecosystems.
What this means for the industry
For protocols and exchanges, the report reinforces that security must be treated as a continuous, system-wide discipline:
1. Beyond audits: Complement smart contract audits with infrastructure reviews, upgrade processes, and governance risk assessments.
2. Key management: For CEXes, robust key custody, multi-sig policies, and operational controls are critical.
3. Monitoring & response: Real-time anomaly detection, circuit breakers, and clear incident response playbooks can limit blast radius.
For users, the implications are equally clear:
1. Diversify risk: Avoid concentrating all assets on a single platform or chain.
2. Understand coverage: Know what (and what not) your platform's protection fund or any insurance product actually covers.
3. Stay alert: Phishing, fake UIs, and malicious integrations remain major vectors, especially in DeFi.





Leave a Comment