EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

In 2026, cryptocurrency was hacked and lost US$3.6 billion. What was revealed behind it?

2026-08-29 00:16:14
Bookmark

Quick overview of report highlights

According to the "2026 Cryptocurrency Security Status Report" released by CoinGecko on August 27, 2026, from January 2025 to July 2026, the cryptocurrency platform lost a total of US$3.63 billion due to hacking and exploit. The report tracked 245 separate incidents over a 19-month period and found that most of the losses were caused by infrastructure failures and private key leaks, rather than smart contract vulnerabilities that most audits aim to prevent.

What did the report find?

CoinGecko's report summarizes four core findings based on 245 recorded incidents:

Since the beginning of 2025, cryptocurrency platforms have lost more than US$3.63 billion, and the top ten attacks alone account for more than 72.5% of the total losses; About 60% of the attacked platforms have passed independent security audits before being compromised; Against the backdrop of rising losses, the effective coverage of top-level on-chain insurance agreements fell by 20.2%; several centralized exchanges have established special reserve funds to cover user losses in the event of an intrusion.

How much have cryptocurrency platforms lost since 2025?

The largest hacking attack during the

period was the Bybit incident, which resulted in losses of US$1.436 billion. Other platforms that suffered nine-figure losses include: KelpDAO lost $292 million, Drift Protocol lost $285 million, Cetus lost $223 million, Balancer lost $128 million, Bitget lost $100 million, Nobitex lost $90 million, Phemex lost $74 million, BTCTurk lost $52 million, and Infini lost $50 million.

Events were not evenly distributed over a 19-month period. The number of monthly events will remain in single digits for most of 2025, but will rise sharply in 2026. In May 2026, 33 independent incidents were recorded, the monthly highest in the report, of which 16 involved audited platforms and 17 involved unaudited platforms.

Which attack methods cause the most damage?

The economic losses caused by supply chain and infrastructure attacks far exceed those of other types, totaling US$1.806 billion, exceeding the sum of the latter three types of attacks. Typical cases mentioned in the report include Bybit and KelpDAO. Smart contract vulnerabilities caused $777 million in losses during this period, of which $546 million was directly related to decentralized applications. Private key leaks are the most common failure point for centralized exchanges, causing $431 million in losses. Social engineering attacks increased by another $311 million. The remaining categories, including oracle manipulation, re-entry attacks, access control vulnerabilities, lightning loan attacks and governance attacks, total approximately $305 million.

Can security audits really stop hackers?

The answer is unreliable. Of the 245 incidents, 147 platforms (approximately 60%) completed independent audits in advance, but these audited platforms accounted for 88.44% of all stolen funds during the period. The gap lies in the limitations of the audit scope. Only about 11% of incidents involved vulnerabilities that traditional smart contract audits could discover, and even so, these vulnerabilities still caused $396 million in losses. Most attacks target external infrastructure, code changes that occur after audits are completed, or governance mechanisms, which are usually outside the scope of audit review. Centralized exchanges rely on different security measures, such as compliance checks and certificate of reserve audits, but these measures are of little use when responding to social engineering attacks or private key leaks.

Why is cryptocurrency insurance coverage shrinking?

From July 2025 to July 2026, the effective underwriting amount of the nine major chain insurance agreements dropped from US$163.2 million to US$130.2 million, a drop of 20.2%. The cumulative compensation amount during the same period was basically flat, at approximately US$33 million. As of August 2026, five of these nine agreements have ceased operations or moved to other business areas. Part of the problem is limited coverage. Most policies only cover verified smart contract vulnerabilities or confirmed infrastructure failures and do not cover losses caused by human error, private key leaks, or general market fluctuations, which excludes many incidents reported.

How does the exchange protect users now?

As the scale of on-chain insurance shrinks, many centralized exchanges have turned to establish their own reserve funds, which are directly funded and managed by the exchanges, rather than relying on third parties: Binance's User Security Assets Fund was established in July 2018 and currently holds approximately US$1.16 billion. If the fund size falls below US$800 million, it will automatically replenish it to US$1 billion; Bitget's protection fund was launched in August 2022 with an initial capital of US$200 million. After the FTX crash, the minimum threshold was raised to US$300 million and currently holds approximately US$423.6 million;BingX's shield fund was launched in June 2025, holding approximately US$126.7 million, and announced that the wallet address is supplied for on-chain verification;MEXC's guardian fund was launched in June 2025, holding approximately US$101.5 million; WEEX's protection fund is completely separated from working capital and holds approximately US$77.1 million;Toobit's Shield Fund was launched in October 2025 and has a dedicated pool of US$50 million and currently holds approximately US$40.2 million.

Conclusion

CoinGecko's 2026 report shows that cryptocurrency security losses are mainly concentrated on infrastructure failures and private key leaks, rather than smart contract vulnerabilities, and audited platforms still account for the majority of stolen funds. Despite the rise in the number of incidents, on-chain insurance coverage is shrinking, prompting several major centralized exchanges to establish their own reserve funds-from Binance's $1.16 billion User Security Asset Fund to Toobit's $40.2 million Shield Fund-to serve as direct backing for users.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP