Exchange Risk & Security

CoinGecko Report Claims Crypto Hacks Exceeded $3.63 Billion Over Nineteen Months Across Platforms

According to a report published by CoinGecko, crypto platforms suffered $3.63 billion in losses across 245 security incidents between January 2025 and July 2026. The findings, which are not officially confirmed by independent security auditors or affected entities, indicate that the majority of attacks targeted vulnerabilities outside routine smart-contract audit scopes, highlighting persistent infrastructure vulnerabilities across centralized and decentralized platforms worldwide.

Digital abstract visualization representing crypto security metrics and infrastructure risks across global exchanges
Image: crypto.news

Overview of Reported Losses and Concentration of Attacks

Data published by CoinGecko revealed that digital asset platforms experienced a cumulative loss of $3.63 billion across 245 documented security incidents spanning a nineteen-month timeframe from January 2025 through July 2026. This comprehensive industry overview indicates that financial damage was heavily concentrated among a small number of high-profile breaches, with the ten largest security incidents accounting for more than 72.5 percent of all recorded stolen funds worldwide. Such concentration underscores the severe systemic risks posed by sophisticated threat actors targeting high-value infrastructure.

Among the notable events cited in the published metrics, the February 2025 breach involving Bybit stood out as the largest single incident, resulting in approximately $1.44 billion in losses due to compromised transaction-signing infrastructure. Additional major events included significant protocol breaches such as those affecting KelpDAO, Drift Protocol, and Cetus. These diverse operational failures demonstrate that modern security threats extend far beyond isolated smart-contract coding errors, encompassing complex multi-vector attacks against institutional custody and transaction routing systems.

Limitations of Routine Smart-Contract Audits and Infrastructure Risks

The published research indicates that approximately 60 percent of the affected platforms had completed independent security assessments prior to being compromised, yet these audited platforms still accounted for the vast majority of total reported losses. However, the data highlights that only a small fraction of analyzed security incidents involved vulnerabilities that fell directly within the standard scope of routine smart-contract audits. The remaining vast majority of breaches originated from external infrastructure vectors, unaudited software updates, compromised administrative credentials, or governance mechanisms that were never evaluated during initial code reviews.

State-backed threat groups and sophisticated criminal syndicates have increasingly pivoted toward operational vectors that bypass smart-contract logic entirely. Incidents involving bridge infrastructure compromises, front-end user interface manipulations, and sophisticated social engineering campaigns have resulted in substantial capital outflows. Because traditional audits provide merely a static snapshot of a specific code version at a given moment, continuous operational monitoring and comprehensive security frameworks covering employee devices and software dependencies remain essential for mitigating these broader attack surfaces.

Decline in Onchain Insurance Capacity and Rise of Self-Funded Reserves

Alongside escalating security breaches, the broader digital asset ecosystem experienced a contraction in available risk-mitigation products, as active onchain insurance capacity decreased significantly during the study period. Cumulative coverage across leading decentralized insurance protocols fell by more than 20 percent, dropping from higher historical levels down to a substantially reduced total. Furthermore, a considerable number of tracked insurance protocols became inactive or pivoted away from underwriting digital asset risks due to elevated claim frequencies, expensive reinsurance premiums, and difficulties in attracting sustainable capital providers.

As external insurance coverage diminished and premiums remained prohibitive, centralized exchanges increasingly established internal investor-protection funds and self-funded reserves to manage potential breach liabilities. While these internal reserves offer the advantage of faster reimbursement processes following an incident, they do not function as regulated insurance policies. The adequacy of a self-funded reserve depends entirely on the exchange's specific terms, asset composition, reserve custody arrangements, and institutional discretion over what constitutes a qualifying reimbursable event for affected users.

Centralized Exchange Vulnerabilities and Custodial Security Challenges

For centralized exchange operators, private-key compromise was identified as the primary operational risk vector leading to severe fund drains. Centralized platforms manage substantial volumes of user assets, making their transaction-signing mechanisms and key management modules lucrative targets for advanced attackers. Protecting these centralized architectures requires stringent multi-party computation configurations, hardware security modules, and strict internal access controls that prevent malicious actors or compromised credentials from initiating unauthorized outbound transfers.

While proof-of-reserves attestations have become increasingly common to demonstrate that exchanges maintain adequate assets to cover customer balances, these attestations address only a distinct aspect of institutional solvency. Independent cryptographic proofs of asset holdings do not verify whether an exchange maintains secure private-key management practices or whether all platform liabilities have been fully disclosed to the public. Consequently, industry observers emphasize that operational transparency must extend well beyond basic reserve snapshots to encompass end-to-end security governance and risk management.

Conclusion and Concrete Findings on Unconfirmed Platform Metrics

In conclusion, this Cexvia risk intelligence assessment finds that reported losses across crypto platforms reached $3.63 billion across 245 security incidents between January 2025 and July 2026, though these figures remain not officially confirmed by independent regulatory or first-party audit verifications. The affected entities include major centralized exchanges such as Bybit and numerous decentralized finance protocols, impacting institutional investors and retail cryptocurrency users worldwide. What changes now is that risk management standards must expand beyond routine smart-contract audits to incorporate rigorous infrastructure monitoring, supply-chain verification, and private-key security protocols.

As the next immediate action, digital asset users and platform operators must separately review reported incident datasets against actual custody configurations, verifying that internal security reserves and multi-party computation controls are fully operational. While media reports highlight severe infrastructure vulnerabilities and declining onchain insurance capacity, stakeholders are advised to distinguish between preliminary third-party loss estimates and verified net-loss totals. Continuous operational vigilance remains mandatory as the cryptocurrency ecosystem navigates evolving threat landscapes and shifting regulatory expectations.

Cexvia conclusion

Assessment of Reported Security Metrics and Necessary Operational Adjustments

The reported data indicates that centralized exchange platforms and decentralized finance protocols experienced significant security breaches driven primarily by infrastructure vulnerabilities and private-key compromises rather than traditional smart-contract flaws. These assertions remain not officially confirmed by comprehensive independent audits, pointing to systemic vulnerabilities affecting digital asset custodians and retail users alike.

Risk meaning
The concentration of losses in major infrastructure attacks demonstrates that traditional security assessments focusing solely on smart-contract code are insufficient for mitigating modern digital asset risks. Platforms must expand risk management protocols to include private-key custody, operational security, and third-party software dependencies to protect user funds effectively.
User action
Users should carefully evaluate the custody practices and internal security reserves of the centralized and decentralized platforms they use. Participants should prioritize platforms that implement robust multi-factor authentication, transparent reserve attestations, and comprehensive operational security measures beyond basic smart-contract audits.
CoinGecko