Particle.news
Download on the App Store

CoinGecko Finds $3.63 Billion Lost to Crypto Hacks Driven by Mega Breaches

Routine audits focus on smart contracts and miss infrastructure and key management failures, leaving insurance too small to cover losses from concentrated mega breaches.

Overview

  • CoinGecko published its State of Crypto Security report on Aug. 27 that estimates $3.63 billion lost across 245 security incidents from January 2025 through July 2026.
  • A tiny number of very large attacks drove most losses: the top 10 breaches made up about 72.5% of the total and the Feb. 2025 Bybit breach accounted for roughly $1.4–$1.5 billion.
  • Although 147 of the 245 hacked platforms had completed independent audits, those audited projects represented 88.44% of reported losses while only about 11% of incidents exploited code within routine audit scopes.
  • Infrastructure, supply‑chain and key‑management failures were the largest sources of theft at more than $1.8 billion, with private keys, signing systems, third‑party services and bridge operations repeatedly targeted.
  • Active on‑chain insurance capacity fell about 20.2% to $130.2 million, prompting more exchanges to rely on self‑funded protection reserves and raising the risk that future mega breaches will overwhelm available coverage.