Crypto platforms experienced 245 documented security incidents between January 2025 and July 2026, resulting in cumulative losses of $3.63 billion, according to CoinGecko's 2026 State of Crypto Security report.
The largest 10 attacks accounted for more than 72.5% of all stolen funds. In the first half of 2026 alone, attackers carried out 207 separate hacks, though total H1 losses of $972 million fell below the $2.3 billion stolen during the first half of 2025.
Audited Protocols Account for Majority of Losses
Of the 245 documented incidents, 147 involved audited protocols, which accounted for 88.44% of stolen capital. However, only about 11% of these attacks targeted vulnerabilities within the audit's scope, resulting in approximately $396 million in losses. The remaining attacks exploited areas outside audit coverage, including infrastructure, third-party services, governance, front ends, and human error.
Infrastructure Vulnerabilities a Major Threat
Decentralized exchanges and decentralized applications faced particular exposure to smart-contract exploits, with around $546 million lost through such attacks. Beyond core code vulnerabilities, more than $1.8 billion was lost to infrastructure and supply-chain weaknesses, including deficiencies in third-party services, integrations, and updates.
Insurance Coverage Declining
Active insurance coverage in the sector fell to 20.2%, with covered assets declining from $163.2 million to $130.2 million, while cumulative payouts remained around $33 million. The on-chain insurance sector is struggling to scale, with 5 of 9 protocols becoming inactive or pivoting by August 2026.
Meanwhile, the SEC submitted proposed amendments to its Custody Rule to OIRA for review on August 25, with publication expected by October 2026, followed by at least 60 days of public comment. Mandatory compliance could take several years following further analysis and a second SEC vote.


