CoinGecko's 2026 State of Crypto Security Report finds crypto platforms lost $3.63B since early 2025 to supply-chain attacks, smart contract exploits, and stolen keys.
Security & Exploits ·
Crypto platforms have incurred $3.63 billion in losses across 245 incidents from January 2025 through July 2026, according to CoinGecko's 2026 State of Crypto Security Report. The ten most damaging attacks represented more than 72.5% of total theft. Supply-chain and infrastructure breaches accounted for over $1.8 billion of this total, while decentralized applications suffered $546 million from smart contract vulnerabilities. Centralized exchanges remained most vulnerable to private key compromises.
Attack sophistication has shifted alongside the threat actors themselves. What were once individual hackers have evolved into organized criminal syndicates and state-backed groups, including North Korean operations, employing mixers, bridges, and staged fund transfers to obscure movement. Centralized and decentralized platforms face distinct vectors: CEXes struggle primarily with key theft, while DEXes encounter contract exploits alongside fake interfaces and malicious code integrations.
A critical gap persists between audit coverage and actual protection. Of the 245 compromised platforms, 147 had completed independent security reviews beforehand—representing 88.44% of stolen capital. Yet roughly 89% of attacks targeted areas beyond conventional audit scope: external infrastructure, unapproved code pushes, or governance-based manipulation. Only 11% involved smart contract flaws within audit boundaries, though these still drained $396 million. Crypto insurance coverage has contracted by 20.2%, falling from $163.2 million to $130.2 million despite rising exploit frequency.