Crypto protocols that had already passed independent security audits represented 88.44% of all funds stolen in hacks tracked since January 2025, according to CoinGecko’s 2026 state of crypto security report. The study covered 245 incidents through July 2026 and tallied total losses of $3.63 billion.

The findings point to a gap between traditional smart contract reviews and the way major crypto breaches are now unfolding. CoinGecko said 147 of the hacked platforms had been cleared by outside auditors before they were later compromised.

Most losses did not come from audited contract bugs

The report said audits failed to prevent 147 of the 245 incidents it tracked. Only 11% of exploits were tied to in-scope smart contract flaws, although those cases still caused $396 million in losses.

CoinGecko attributed much of the damage to issues outside the narrow scope of many contract reviews, including external infrastructure, code introduced after an audit was completed, and system features that could be manipulated through governance. Across decentralized applications, smart contract exploit-driven losses totaled $546 million.

Supply chain and infrastructure breaches were the largest single category, accounting for more than $1.8 billion in losses. The report said these vulnerabilities have become especially destructive across both centralized and decentralized platforms.

Keys, deployment systems, and governance remain major weak points

The examples in the report underscore how attackers are often bypassing audited contract logic. In the Stake DAO breach in May, the compromise reportedly came through a deployer key rather than a flaw in the contract itself.

For centralized exchanges, stolen private keys remained the most common failure point. CoinGecko summarized the trend by arguing that infrastructure and supply chain vulnerabilities have been the most damaging attack path for both CEXes and DEXes.

The concentration of losses was also striking. The 10 biggest attacks accounted for 72.5% of all funds stolen during the 19-month period covered in the study.

Incident count rose while average loss fell

CoinGecko’s data shows hacking activity becoming more frequent even as the average size of incidents declines. DefiLlama recorded 233 incidents in 2026 so far, with losses of about $1.31 billion. In 2025, it logged 92 incidents and $2.37 billion in losses.

That pushed the average loss per incident down from $25.8 million in 2025 to $5.6 million in 2026. The report noted that 2025’s total was heavily affected by the $1.5 billion Bybit theft.

Among the largest hacks cited for the 2025-2026 period were Kelp DAO at $292 million and Drift Protocol at $285 million. The report also pointed to a continuing stream of smaller breaches, including an $8.5 million governance exploit at Term Labs in August.

Insurance shrank as the threat model shifted

The report said active on-chain insurance dropped 20.2% to $130.2 million over the period reviewed. At the same time, five of nine insurance protocols either became inactive or shifted direction.

CoinGecko’s broader conclusion was that the industry’s security problem may be as much about audit scope as audit quality. As more value accumulates in deployment keys, governance settings, and surrounding infrastructure, reviews limited to contract code may miss the attack paths that matter most.

The next confirmed data point is the continuation of the 2026 incident trend: more numerous but generally smaller attacks, even as outsized breaches still dominate total losses when they occur.

Source: beincrypto.com