
The analytical platform CoinGecko has published a comprehensive study on the state of cybersecurity in the cryptocurrency industry, covering the period from early 2025 through July 2026. According to the data presented, over these 19 months various crypto projects collectively lost $3.63 billion as a result of 245 documented incidents. The most destructive category of threats proved to be vulnerabilities in core infrastructure and software supply chain compromises, which caused losses exceeding $1.8 billion for both centralized and decentralized platforms.
Among the most large-scale incidents, the report highlights the attack on the Bybit exchange resulting in a loss of $1.43 billion, and the hack of the Kelp protocol with damages of $292 million. For centralized trading platforms, the key risk vector remains the compromise of private keys used for asset management, while decentralized applications suffered combined losses of $546 million due to the exploitation of smart contract vulnerabilities. Researchers also drew attention to the susceptibility of both business models to manipulation via oracle mechanisms and market operations, recording additional losses caused by internal system failures at platforms such as Bitget, Binance, and Hyperliquid.
A significant portion of the study is devoted to the effectiveness of pre-incident security audits. Of the total number of documented incidents, 147 cases involved protocols that had undergone code review procedures prior to being hacked. These platforms accounted for 88.44% of the total volume of stolen funds during the period under review. At the same time, approximately 11% of such cases were directly linked to vulnerabilities in smart contracts that fell within the scope of the audits conducted, resulting in damages of $396 million. These statistics point to the limitations of existing code verification approaches and the need to develop more comprehensive security methodologies.
A dedicated section of the report addresses the state of the decentralized insurance market for digital assets. The volume of active coverage across the largest insurance protocols declined by 20.2%, falling from $163.2 million to $130.2 million. Total insurance claim payouts remained at approximately $33 million. As of August 2026, five out of nine on-chain insurance protocols had ceased active operations or changed their business focus, indicating systemic challenges in building a sustainable insurance model within the cryptocurrency ecosystem.
The study's authors also analyzed the effectiveness of preventive measures employed by centralized exchanges. Many platforms establish specialized protection funds to compensate users for potential losses in the event of successful exploits. However, standard Proof-of-Reserve mechanisms, according to the analysts, offer limited protection against social engineering methods and critical failures in private key management systems. The ongoing relevance of cybersecurity issues was underscored by a recent incident on August 27, when the Moonwell protocol on the Base network fell victim to an attack causing $8.7 million in damages.
***
This material is prepared for informational purposes only and does not constitute financial advice or a recommendation.
