|
Getting your Trinity Audio player ready...
|
Cryptocurrency platforms lost more than $3.63 billion to cyberattacks and stolen credentials between January 2025 and July 2026, according to a new report from crypto market data site CoinGecko, and the most unsettling detail buried in that number isn’t the total itself, it’s who was getting hacked. Around 60 percent of the affected platforms had already completed independent security audits before they were breached, and those audited platforms accounted for a staggering 88 percent of all funds stolen during the period. Passing a security review, it turns out, has become a remarkably poor predictor of whether a crypto platform will actually stay safe.
CoinGecko’s 2026 State of Crypto Security Report, published August 27, documented 245 separate security incidents across the roughly 19-month window it covers. The damage was heavily concentrated rather than evenly spread, with the ten largest attacks alone accounting for more than 72.5 percent of the total value stolen. Two incidents in particular dominated the headline figures: a breach at exchange Bybit that resulted in losses of $1.43 billion, and a $292 million loss tied to KelpDAO. Those two events alone represent nearly half of everything lost across the entire 19-month period covered by the report.
What makes the audit finding genuinely important isn’t simply that audited platforms still got hacked, it’s understanding why. According to CoinGecko’s analysis, only about 11 percent of the 147 audited-and-later-breached incidents actually involved smart contract vulnerabilities that fell within a typical audit’s intended scope, and even those in-scope failures still accounted for $396 million in losses. The overwhelming majority of successful attacks targeted areas that conventional security audits simply aren’t designed to catch in the first place, things like private key custody practices, third-party infrastructure dependencies, and supply chain relationships sitting outside the core smart contract code that audits traditionally focus on reviewing line by line.
That distinction matters enormously once you break down where the actual losses came from. Infrastructure and supply chain vulnerabilities, covering weaknesses in third-party services, integrations, and the surrounding technical ecosystem a platform depends on rather than its own core code, caused more than $1.8 billion in losses across both centralized and decentralized platforms, easily the single costliest category identified in the report. By comparison, smart contract exploits specifically drained approximately $546 million from decentralized applications, a meaningful sum but considerably smaller than what infrastructure failures accounted for. Separate research from blockchain analytics firm TRM Labs reinforces this same pattern, finding that infrastructure and operational compromises represented only about 15 percent of documented incidents during the first half of 2026, yet accounted for roughly 76 percent of all funds stolen, a lopsided ratio that underscores just how disproportionately damaging these harder-to-audit vulnerability categories have become.
The risk profile also varies meaningfully depending on how a given platform is structured. Centralized exchanges remain most vulnerable through compromised private keys, the digital credentials controlling access to a platform’s actual holdings, a risk that has little to do with code quality and everything to do with operational security practices around who can access those keys and how they’re stored. Decentralized applications, by contrast, face their exposure primarily through sophisticated smart contract exploits, though CoinGecko’s report notes both architectures remain exposed to oracle manipulation, market manipulation tactics, and internal mechanism errors, pointing specifically to notable incidents at Bitget, Binance, and Hyperliquid as examples spanning this broader category.
The attackers themselves have also grown considerably more organized over the period the report covers. CoinGecko’s analysis describes a shift away from individual rogue hackers and toward organized criminal syndicates and state-sponsored groups, specifically naming North Korean hacking operations as increasingly prominent actors within the crypto theft ecosystem. These more sophisticated groups have adopted techniques including mixers, cross-chain bridges, and staggered withdrawal patterns specifically designed to make stolen funds harder to trace once an exploit has succeeded, a level of operational discipline that mirrors tactics more commonly associated with traditional financial crime and money laundering operations rather than opportunistic individual hackers.
Perhaps the most concerning trend identified in the report involves the safety net that’s supposed to catch users when platforms do fail. Active coverage across on-chain crypto insurance protocols has actually contracted by 20.2 percent over the reporting period, falling from $163.2 million to $130.2 million, even as the frequency and cost of exploits has continued climbing. By August 2026, five of the nine on-chain insurance protocols CoinGecko tracked had either gone inactive entirely or pivoted their business toward other areas, leaving total payouts largely flat around $33 million despite billions in documented losses across the broader industry. Some centralized exchanges have responded by launching their own dedicated protection funds to cover user losses directly in the event of an exploit, though the report specifically cautions that standard safeguards like Proof-of-Reserve disclosures offer relatively weak protection against the kind of social engineering and private key security failures that continue driving the largest losses.
Regulatory movement on custody standards has been slow to catch up with the scale of the problem. The US Securities and Exchange Commission has been revisiting its Custody Rule specifically to clarify who is permitted to safeguard customer crypto holdings, submitting proposed amendments for regulatory review in late August with publication expected around October 2026, followed by a mandatory public comment period lasting at least 60 days. Given the additional analysis and formal voting process still required after that comment period concludes, meaningful mandatory compliance requirements tied to custody practices could realistically remain years away, leaving the current gap between audit-based security assurances and actual attacker behavior largely unaddressed in the near term.
For crypto investors and platform operators alike, CoinGecko’s findings point to a fairly clear conclusion: passing an independent security audit remains a genuinely useful signal of code quality, but it has become an increasingly unreliable proxy for whether a platform is actually safe from the kinds of attacks currently driving the largest losses. Until infrastructure security, private key custody practices, and third-party integration risk receive the same rigorous scrutiny that smart contract code already gets, the gap between “audited” and “secure” seems likely to keep costing the crypto industry billions rather than closing.
The full report is available through CoinGecko’s official research page. For more coverage of cryptocurrency security and digital asset regulation, visit Business Tech.