Crypto platforms lost a combined $3.63 billion across 245 documented security incidents between January 2025 and July 2026, according to a new report from CoinGecko. The study points to a market still vulnerable to large-scale exploits even after many projects completed third-party security reviews.
The data also shows that losses were concentrated in a relatively small number of attacks. CoinGecko said the 10 biggest incidents accounted for more than 72.5% of the total value stolen during the 19-month period.
Audited protocols made up most of the losses
CoinGecko found that 147 of the 245 documented incidents involved protocols that had been audited before they were compromised. Those previously vetted platforms represented 88.44% of all funds drained in the period covered by the report.
The figures suggest that a completed audit did not shield many projects from the largest thefts. At the same time, the report does not present audits as the direct cause of those losses; rather, it highlights that major attacks still hit platforms that had already undergone independent review.
Smart contract bugs were only part of the problem
Only about 11.0% of documented incidents were tied to in-scope smart contract flaws, according to the report. Even so, those failures still led to roughly $396 million in losses.
CoinGecko said the bigger source of damage came from weaknesses outside that narrower category. Infrastructure and supply chain vulnerabilities accounted for more than $1.8 billion in losses, while decentralized applications recorded another $546 million drained through smart contract exploits.
Insurance coverage shrank as losses mounted
The report also pointed to weakening protection from crypto insurance providers during the same period. Active coverage fell 20.2%, dropping from $163.2 million to $130.2 million.
Cumulative payouts stood at $33 million, a figure that remained far below the total losses recorded across hacks and exploits. The gap underscores how limited on-chain protection has been relative to the scale of recent incidents.
Market backdrop and next confirmed data point
CoinGecko's figures cover the period from January 2025 through July 2026, with the report describing a threat environment shaped by sophisticated exploits and repeated high-value breaches. The concentration of losses in a handful of attacks suggests that a small number of incidents had an outsized effect on the aggregate total.
As of August 2026, five of the nine on-chain insurance protocols tracked in the report had either gone inactive or pivoted. That is the latest confirmed status update cited in the study and provides the clearest next reference point for how the sector's defensive tools are evolving.
Source: dailyhodl.com