Between January 2025 and July 2026, cryptocurrency platforms suffered 245 documented security breaches resulting in losses of $3.63 billion. According to CoinGecko’s latest report, the overwhelming majority of these funds were siphoned through infrastructure compromises and private-key theft rather than simple smart-contract flaws.
The scale of financial damage remains heavily skewed toward a handful of major events. The ten largest attacks alone account for over 72.5% of total losses. Among these, the February 2025 breach of Bybit stands as the most significant, with attackers draining approximately $1.44 billion by compromising transaction-signing infrastructure. Other notable incidents include the $292 million KelpDAO breach and the $285 million attack on Drift Protocol, highlighting that vulnerabilities often exist far beyond the scope of traditional code audits.
The Failure of Conventional Audits
Data suggests that 147 of the affected platforms had completed independent security reviews prior to being exploited. While these audited entities accounted for 88.44% of total losses, CoinGecko notes that only 11% of the incidents involved vulnerabilities that would have been covered under standard smart-contract audit scopes. Most losses stemmed from broader systemic failures, including compromised private keys, social engineering, and flaws in bridge infrastructure.
As the threat landscape shifts, the industry is seeing a retreat in formal insurance coverage. Active onchain insurance capacity dropped by 20.2% to $130.2 million, with five of the nine tracked protocols pivoting away from the space due to high premiums and mounting risk. In response, centralized exchanges are increasingly opting for self-funded protection reserves, though these lack the standardized regulatory oversight of traditional insurance policies.
Comments (0)
No comments yet. Be the first!