EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Cryptocurrency has evaporated billions of dollars in 19 months: Why?

2026-08-28 00:50:05
Bookmark

CoinGecko's 2026 Cryptocurrency Security Report shows that between January 2025 and July 2026, a total of 245 attacks occurred, with a total loss of US$3.63 billion. What is even more shocking is that about 60% of the platforms that were attacked had previously undergone an independent security audit.

Security loopholes in the cryptocurrency field continue to expand.

According to CoinGecko, between January 2025 and July 2026, a total of US$3.63 billion was lost in 245 recorded incidents. Moreover, most of the losses were concentrated in a few large attacks. Among the top ten attacks, the stolen amount accounted for more than 72.5% of the total value.

The reasons behind this number vary by platform. In centralized exchanges, theft of private keys is a major problem; in decentralized applications, smart contract vulnerabilities pose a greater challenge.

What are the biggest reasons for cryptocurrency attacks?

CoinGecko's report pointed out that the most serious losses were infrastructure and supply chain loopholes. The total damage caused by such attacks on CEX and DEX platforms exceeds $1.8 billion. In centralized exchanges, the most common problem is theft of private keys. In decentralized applications, attackers exploit smart contract vulnerabilities as the main means, and such incidents caused approximately US$546 million in losses.

In addition, oracle systems and market manipulation pose common risks to two different types of platforms. The losses suffered by large players such as Bitget, Binance and Hyperliquid suggest that not only is the smart contract code flawed, but the platform's own operating mechanisms are also at risk of being attacked.

The problem goes far beyond that. Attackers are no longer just looking for direct code vulnerabilities. Fake user interfaces and malicious integrations also become part of the security risk.

At the top of the list is Bybit, with a loss of US$1.436 billion. KelpDAO lost $292 million, Drift Protocol lost $285 million, and Cetus lost $223 million, followed closely.

Why are projects that pass security audits still hacked?

One of the most eye-catching findings in the report is here. Since the beginning of 2025, 147 of the 245 incidents recorded, the platform under attack had previously undergone an independent security audit. Stolen funds from these platforms accounted for 88.44% of the total stolen capital. This means that just because a protocol is audited does not mean that it is immune to attacks.

According to CoinGecko, an important reason lies in the scope of the audit. Many attacks do not stem directly from errors in the smart contract itself being audited. Instead, attackers target external infrastructure, subsequent unaudited code updates, or governance mechanisms. Interestingly, only 11% of incidents were directly related to smart contract vulnerabilities within the audit scope. Still, the attacks caused approximately $396 million in damage.

This situation shows that audit reports by themselves are not sufficient to constitute a reliable layer of security. When it comes to centralized exchanges, the situation is different. These platforms often rely on financial verification mechanisms such as compliance inspections and certificates of reserve rather than decentralized protocol audits. However, these measures also fail to prevent social engineering attacks or theft of private keys.

Why are cryptocurrency insurance funds decreasing?

Despite the increasing number of attacks, there is an opposite trend in cryptocurrency insurance. CoinGecko pointed out that active guarantees in the largest on-chain insurance agreements have dropped from $163.2 million to $130.2 million, a drop of 20.2%. Moreover, while total claims remain at about $33 million, insurance coverage is shrinking.

One of the important reasons is that the high-risk environment makes it difficult for users to provide guarantees and pay high premiums. In addition, the coverage of insurance products is often very limited. For example, some policies only cover verified smart contract attacks or specific infrastructure issues. Losses caused by human error, theft of private keys, or general market fluctuations may not be covered.

Therefore, in the cryptocurrency space, when attack incidents increase, insurance does not grow simultaneously, creating new security holes.

How does the exchange protect users?

In response to this situation, centralized exchanges began to adopt a different approach: protecting funds. CoinGecko's report pointed out that some centralized exchanges have set up special reserves to make up for users 'losses in the event of an attack or security breach. This approach shows that users are not only beginning to focus on technical security, but also on how to protect them after being attacked.

However, the issues facing the entire industry are broader. After 245 incidents recorded between January 2025 and July 2026, five of the nine agreements in the on-chain insurance ecosystem have ceased operations or moved to other areas.

The conclusion drawn from this is very clear: in the cryptocurrency field, attack costs continue to rise, security audits themselves are no longer enough to deal with risks, and insurance capabilities have not been expanded simultaneously. CoinGecko's data reveals that security is now no longer just a matter of auditing code; infrastructure, key management, integration, and user protection after an attack all need to be considered together.

This content is based on general market data and does not constitute investment advice. It is recommended that you conduct independent research.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP