CoinGecko: Crypto Exploits Drain $3.63 Billion Across 19-Month Span
CoinGecko reports $3.63B in crypto security losses across 245 incidents from Jan 2025 to Jul 2026. Photo: Pexels
Technology & Security

CoinGecko: Crypto Exploits Drain $3.63 Billion Across 19-Month Span

A comprehensive CoinGecko study reveals that crypto platforms suffered $3.63 billion in losses across 245 documented security incidents over 19 months.

Make us preferred on Google

Digital asset platforms lost a cumulative $3.63 billion across 245 documented security breaches between January 2025 and July 2026, according to findings from CoinGecko’s State of Crypto Security Report published on August 27, 2026. The empirical study provides an exhaustive accounting of threat vectors, protocol vulnerabilities, and institutional risk management trends across both centralized finance (CeFi) and decentralized finance (DeFi) ecosystems. The findings demonstrate that while smart-contract security has matured in narrow contexts, external operational dependencies, infrastructure vulnerabilities, and sophisticated social engineering tactics continue to expose institutional and retail assets to systemic risk.

The study emphasizes that total recorded losses were heavily concentrated within a relatively small subset of high-profile security compromises. The ten largest attacks accounted for more than 72.5% of the total value stolen globally during the 19-month observation window. Furthermore, operational infrastructure failures and supply-chain compromises, rather than simple code defects in deployed protocols, represented the single primary driver of capital loss, causing more than $1.8 billion in direct damages.

Concentration of Capital Losses and Key Vector Analysis

The empirical data highlights a stark divergence in threat models depending on platform architecture. Centralized exchanges and custody providers faced their primary threat in private-key management and compromised authorization infrastructure. The single largest breach documented in the report occurred in February 2025, when centralized exchange Bybit suffered an exploit resulting in approximately $1.44 billion in stolen assets. The incident stemmed from compromised transaction-signing infrastructure and administrative authorization workflows rather than an explicit vulnerability within an exchange-managed smart contract.

In contrast, decentralized applications and smart-contract protocols lost approximately $546 million to direct protocol exploits during the study period. These losses were driven by complex technical attack vectors, including flash-loan-assisted price oracle manipulation, economic logic failures, and access-control bypasses. Among the largest decentralized protocol breaches cited in the report were:

  • The $292 million exploit of liquid staking protocol KelpDAO, which involved compromised administrative parameters and vault control.
  • The $285 million attack on Solana-based perpetual DEX Drift Protocol, executing complex economic logic manipulations across liquidity pools.
  • The $223 million compromise of Move-based DEX Cetus, which targeted concentrated liquidity mechanisms and pool state updates.

Beyond internal logic failures, advanced threat actors, including state-sponsored cyber syndicates, increasingly directed resources toward multi-stage operational compromises. North Korea-linked cyber operations, for instance, accounted for approximately $577 million in stolen assets across two major incidents during the report timeframe. These operations bypassed traditional smart-contract security parameters by targeting developer workstations, cross-chain bridge operator nodes, and corporate communication channels through structured social engineering campaigns.

Audits Cover Only a Small Fraction of Exploited Weaknesses

One of the most notable insights from CoinGecko’s report is the structural disconnect between third-party smart-contract audits and real-world exploit mitigation. The data reveals that 147 of the 245 compromised platforms, representing roughly 60% of all affected entities, had completed at least one independent smart-contract security audit prior to experiencing a breach. More critically, these previously audited entities accounted for 88.44% ($3.21 billion) of total reported financial losses.

However, CoinGecko clarified that this statistic does not imply auditor oversight or technical failure within the audited codebase. In fact, only approximately 11% of all documented security incidents involved vulnerabilities that actually fell within the explicitly defined scope of routine smart-contract audits. These in-scope smart-contract failures accounted for roughly $396 million in total losses.

The overwhelming majority of capital losses resulted from vulnerabilities completely outside standard audit parameters. Threat actors routinely exploited elements of the technology stack that third-party code reviews do not assess, including:

  • Off-chain transaction signing infrastructure, key management systems (KMS), and cold/hot storage access workflows.
  • Unaudited post-review software patches, governance updates, and administrative parameter adjustments deployed after audit completion.
  • Third-party front-end web interfaces, domain name service (DNS) configurations, and software dependency libraries.
  • Cross-chain messaging bridges, validator sets, and multisig threshold administration.

The report underscores that a smart-contract audit represents a static snapshot of a specific code version at a single point in time. It cannot guarantee security against subsequent operational changes, unverified code updates, or broader infrastructure compromises.

Contraction of Onchain Insurance Capacity and Shift Toward Self-Reserves

As physical security breaches and infrastructure compromises escalated, the commercial availability of onchain risk mitigation tools experienced a sharp decline. Active coverage capacity across major onchain insurance protocols fell 20.2% during the study period, contracting from $163.2 million to $130.2 million. Cumulative historical payouts across these underwriting platforms remained stagnant near $33 million.

Of the nine dedicated decentralized insurance protocols tracked by CoinGecko, five had either ceased operations entirely or pivoted away from protocol underwriting by August 2026. Industry experts attribute this contraction to severe structural challenges within the decentralized insurance market, including unsustainably high premium pricing, difficulty attracting capital providers to underwrite tail-risk events, and overly restrictive policy definitions. Many existing policies restrict payout triggers strictly to verified onchain smart-contract bugs, explicitly excluding common real-world loss vectors such as private-key theft, phishing attacks, operator errors, and bridge compromises.

In response to declining external insurance options, centralized platforms and major decentralized protocols have shifted toward internal, self-funded reserve mechanisms. Centralized exchanges increasingly allocate a percentage of transaction fees into dedicated investor protection funds to ensure immediate liquidity for user reimbursement following a security event.

While self-funded reserve funds offer faster payout execution than traditional claims processes, they differ fundamentally from regulated commercial insurance. Coverage terms, reserve asset composition, custody segregation, and payout eligibility remain entirely at the discretion of the operating platform. Similarly, while proof-of-reserves (PoR) attestations have become standard practice for verifying on-chain asset backing, they verify solvency at a single moment rather than guaranteeing secure key custody, internal operational safeguards, or complete disclosure of off-chain liabilities.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

DeFi & FinTech, News, Technology & Security

More from CoinScreamer