Home Latest Insights | News Crypto Industry Loses $3.63 Billion to 245 Security Incidents in 19 Months

Crypto Industry Loses $3.63 Billion to 245 Security Incidents in 19 Months

Crypto Industry Loses $3.63 Billion to 245 Security Incidents in 19 Months

The cryptocurrency sector has suffered $3.63 billion in losses from 245 documented security incidents between January 2025 and July 2026, according to CoinGecko’s 2026 State of Crypto Security Report.

The figure covers roughly 19 months and accounts for a substantial share of total historical crypto hack losses, which now exceed $14 billion since 2016.

Incident frequency accelerated in 2026. The first seven-plus months of the year alone recorded 164 breaches, nearly 70% more than the 97 incidents logged across all of 2025.

Average losses per incident declined as the large-scale events that defined 2025 became less dominant. One outlier still stands out: the Bybit exchange breach, which alone accounted for approximately $1.436 billion and was linked to sophisticated actors.

Other major incidents in the period included KelpDAO ($292 million), Drift Protocol ($285 million), and Cetus ($223 million). The top 20 exploits made up the bulk of total stolen funds.

Infrastructure and supply-chain vulnerabilities emerged as the most damaging attack vectors, responsible for more than $1.8 billion in losses across both centralized exchanges and decentralized platforms.

Centralized exchanges were frequently hit through private-key compromises, while decentralized applications lost around $546 million to smart-contract exploits. Oracle and market-manipulation issues also contributed to losses at several major platforms.

A striking finding is the limited protection offered by traditional security audits. Roughly 60% of the exploited platforms (147 out of 245) had undergone independent audits before being compromised, and those audited platforms accounted for nearly 88.5% of all stolen funds.

However, only about 11% of incidents involved vulnerabilities within the actual scope of those audits. Most successful attacks targeted areas outside typical smart-contract reviews, such as infrastructure, key management, governance mechanisms, and supply-chain weaknesses.

On-chain crypto insurance coverage has also contracted. Active underwriting on major insurance protocols fell about 20% to roughly $130 million, with several protocols becoming inactive or shifting focus. In response, some centralized exchanges have expanded their own user protection funds.

As cryptocurrency continues to mature and integrate into mainstream finance, it remains a critical element in modern criminal operations.

Individual cryptocurrency holders are also facing a growing threat. Chainalysis identified approximately 158,000 personal-wallet compromise incidents in 2025, affecting at least 80,000 unique victims. Although the total value stolen from personal wallets declined compared with the previous year, the sharp increase in incidents demonstrates that crypto theft is becoming increasingly widespread.

At the same time, decentralized finance has shown signs of becoming more resilient. Improvements in security monitoring, governance and incident response have helped limit some of the losses historically associated with DeFi exploits.

Yet another threat is emerging outside the digital environment altogether: physical crypto theft.

Criminals are increasingly targeting cryptocurrency holders through kidnappings, home invasions, and other forms of coercion in an attempt to force victims to surrender their digital assets. Chainalysis estimates that more than $30 million had already been stolen through violent crypto attacks in 2026, putting the year on pace to potentially exceed the $58 million stolen through such attacks in 2025.

The development illustrates a fundamental change in cryptocurrency crime. As digital assets become more valuable and more widely held, criminals are finding new ways to access them—whether through sophisticated cyberattacks, compromised employees, or direct physical intimidation.

For the cryptocurrency industry, the challenge is therefore becoming broader than protecting blockchain networks and smart contracts. Exchanges, custodians, companies and individual investors must increasingly defend against social engineering, insider threats, compromised credentials, sophisticated laundering networks and even physical attacks

While decentralized finance (DeFi) has historically been a major target, Chainalysis found that individual attacks against centralized services have become increasingly severe.

The data paints a clear picture of an industry still grappling with persistent security gaps even as defenses and professional practices improve. While individual incident sizes have trended smaller in 2026, the rising volume of attacks continues to extract a heavy toll.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here