Crypto faces $3.63 billion security crisis despite audited protocols — Details

Nearly eight months have handed in 2026, and the frequency of scams is but to decelerate. In reality, in H1 2026 alone, attackers carried out 207 separate hacks.
And but, regardless of the hike in incidents, whole losses have been simply $972 million, lower than half of the $2.3 billion stolen in the course of the first half of 2025.
CoinGecko’s latest report titled ‘2026’s State of Crypto Safety’ make clear the truth that between January 2025 and July 2026, crypto platforms noticed 245 documented safety incidents. These resulted in $3.63 billion in losses.
Yearly crypto hack breakdown
The harm was so large that the most important 10 assaults accounted for greater than 72.5% of all stolen funds. In line with the report, DEXs and dApps confronted larger publicity to smart-contract exploits, with round $546 million misplaced by such assaults.
Nevertheless, threats more and more prolonged past core code. Notably, greater than $1.8 billion was misplaced to infrastructure and supply-chain vulnerabilities, together with weaknesses in third-party companies, integrations, and updates.
Of those, high-profile case research included the safety failures at Bybit and KelpDAO.


Of the 245 documented incidents, 147 concerned audited protocols, which accounted for 88.44% of stolen capital.
Nevertheless, solely about 11% of those assaults focused vulnerabilities inside the audit’s scope, inflicting round $396 million in losses. Most assaults exploited areas resembling infrastructure, third-party companies, governance, entrance ends, or human error.


What else did the report say?
Regardless of the hike in crypto hacks, energetic insurance coverage protection fell to twenty.2%, from $163.2 million to $130.2 million. This, whereas cumulative payouts remained round $33 million.
Right here, it should be identified that the sector can be struggling to scale, with 5 of 9 on-chain insurance coverage protocols changing into inactive or pivoting by August 2026.
This, on the again of the SEC revisiting its Custody Rule to make clear who can safeguard buyer crypto.
On twenty fifth August, they submitted proposed amendments to OIRA for assessment, with publication anticipated by October 2026, adopted by no less than 60 days of public feedback. Nevertheless, the principles usually are not but efficient. An additional evaluation and a second SEC vote imply necessary compliance and will nonetheless take a number of years.
Ultimate Abstract
- Largest 10 assaults accounted for greater than 72.5% of all stolen funds.
- Of the 245 documented incidents, 147 concerned audited protocols, which accounted for 88.44% of all stolen capital.





