Crypto Lost $3.6B To Hacks In 2026, Here’s What It Reveals

CoinGecko's 2026 Crypto Security Report found $3.63B stolen since 2025, shrinking insurance coverage, and new exchange protection funds.
Soumen Datta
August 28, 2026
Table of Contents
Crypto platforms lost $3.63 billion to hacks and exploits between January 2025 and July 2026, according to CoinGecko's 2026 State of Crypto Security Report, published August 27, 2026. The report tracked 245 separate incidents over 19 months and found that most of the money was lost to infrastructure failures and stolen private keys, not the smart contract bugs most audits are built to catch.
What Did the Report Find?
CoinGecko's report, based on 245 documented incidents, points to four main takeaways:
- Crypto platforms lost more than $3.63 billion since the start of 2025, with the 10 largest attacks alone making up over 72.5% of that total
- About 60% of hacked platforms had passed an independent security audit before they were breached
- Active coverage on top on-chain insurance protocols fell 20.2%, even as losses kept climbing
- Several centralized exchanges have built dedicated reserve funds to cover users if a breach happens
How Much Have Crypto Platforms Lost Since 2025?
The single biggest hack in the period was Bybit, which lost $1,436 million. Several other platforms also suffered nine-figure losses:
- KelpDAO: $292 million
- Drift Protocol: $285 million
- Cetus: $223 million
- Balancer: $128 million
- Bitget: $100 million
- Nobitex: $90 million
- Phemex: $74 million
- BTCTurk: $52 million
- Infini: $50 million
Incidents were not spread evenly across the 19 months. Monthly totals stayed in the single digits through most of 2025, then climbed sharply in 2026. May 2026 recorded 33 separate incidents, the highest monthly count in the report, split between 16 audited and 17 unaudited platforms.
Which Attack Methods Caused the Most Damage?
Supply chain and infrastructure attacks caused the most financial damage by far, responsible for $1,806 million of the total, more than the next three categories combined. Notable examples cited in the report include Bybit and KelpDAO.
Smart contract exploits caused $777 million in losses across the period, with $546 million of that tied specifically to decentralized apps. Private key compromise, the most common failure point at centralized exchanges, cost $431 million. Social engineering added another $311 million. The remaining categories, including oracle manipulation, reentrancy attacks, access control exploits, flash loan attacks, and governance attacks, combined for roughly $305 million.
Do Security Audits Actually Stop Hacks?
Not reliably. Of the 245 incidents, 147 platforms, about 60%, had completed an independent audit beforehand. Those audited platforms accounted for 88.44% of all money stolen in the period.
The gap is one of scope. Only about 11% of incidents involved a flaw that a conventional smart contract audit would have caught, and those still caused $396 million in losses.
Most attacks instead hit external infrastructure, code changes made after the audit, or governance mechanisms, all of which typically fall outside what an audit reviews. Centralized exchanges lean on different safeguards, such as compliance checks and Proof-of-Reserve attestations, but these do little against social engineering or a compromised private key.
Why Is Crypto Insurance Coverage Shrinking?
Active coverage across the nine largest on-chain insurance protocols dropped 20.2%, from $163.2 million to $130.2 million, between July 2025 and July 2026. Cumulative payouts stayed roughly flat at $33 million over the same period. By August 2026, five of those nine protocols had gone inactive or shifted into other business lines.
Discover Promising Projects...
Promising Projects...
(Advertisement)
Part of the problem is scope. Most policies only pay out for verified smart contract exploits or confirmed infrastructure failures, not losses caused by human error, stolen private keys, or ordinary market swings, which excludes many of the incidents in the report.
How Are Exchanges Protecting Users Now?
With on-chain insurance shrinking, several centralized exchanges (CEXes) have built their own reserve funds instead, funded and managed directly by the exchange rather than a third party:
- Binance's Secure Asset Fund for Users (SAFU), established in July 2018, holds roughly $1.16 billion and is automatically topped back up to $1 billion if it drops below $800 million
- Bitget's Protection Fund launched in August 2022 with $200 million and now holds about $423.6 million, after the minimum threshold was raised to $300 million following FTX's collapse
- BingX's Shield Fund launched in June 2025 and holds about $126.7 million, with wallets published for on-chain verification
- MEXC's Guardian Fund launched in June 2025 and holds about $101.5 million
- WEEX's Protection Fund, fully segregated from operational funds, holds about $77.1 million
- Toobit's Shield Fund launched in October 2025 with a dedicated $50 million pool and now holds about $40.2 million
Conclusion
CoinGecko's 2026 report shows crypto security losses concentrated in infrastructure failures and stolen private keys rather than smart contract bugs, with audited platforms still accounting for the majority of stolen funds. On-chain insurance coverage has shrunk even as incidents rose, pushing several major centralized exchanges to fund their own reserve pools, ranging from Binance's $1.16 billion SAFU fund down to Toobit's $40.2 million Shield Fund, as a direct backstop for users.
Resources
- CoinGecko: The full 2026 State of Crypto Security Report, including the 15-slide data deck this article is based on
- KuCoin: News coverage confirming the report's audit statistics and August 27, 2026 publish date
- Bloomingbit: Coverage of the report's findings on why most hacks fall outside conventional audit scope
Read Next...
Frequently Asked Questions
Disclaimer
Disclaimer: The views expressed in this article do not necessarily represent the views of BSCN. The information provided in this article is for educational and entertainment purposes only and should not be construed as investment advice, or advice of any kind. BSCN assumes no responsibility for any investment decisions made based on the information provided in this article. If you believe that the article should be amended, please reach out to the BSCN team by emailing info@bsc.news.
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.
Crypto Project & Token Reviews
Project & Token Reviews
Comprehensive reviews of crypto's most interesting projects and assets
Learn about the hottest projects and tokens
Latest Crypto Articles
Get up to date with the latest crypto news stories and events











