CoinGecko published the Status of Encryption Security on 27 August and reported that between January 2025 and July 2026, encryption platforms had accumulated $3.63 billion in losses from 245 recorded security incidents. The report shows that losses are concentrated in a small number of large cases, with the top 10 attacks accounting for more than 72.5 per cent of stolen funds worldwide.
Losses are concentrated in a few big cases.
The Bybit incident in February 2025 was reported to be the largest single case in the statistical period, involving approximately US$ 14.40 billion. CoinGecko argued that the incident was related to the breach of the trading signature infrastructure rather than to the shortcomings of the exchange ' s smart contract itself.
Other significant events include KelpDAO's $292 million loss, Drift Protocol's $285 million loss, and Cetus' $223 million attack. The report notes that attacks at the infrastructure and supply chain levels combined cost more than $1.8 billion, suggesting that a single security measure could not cover the entire industry.
CoinGecko also mentioned that the primary risk to a centralized transaction was private key disclosure. De-centreized applications lost approximately $546 million due to smart contract loopholes. In addition, both types of platforms are affected by the manipulation of prophecies and the failure of internal mechanisms.
Limited routine audit coverage
Of the 245 affected platforms, 147, or approximately 60 per cent, had completed an independent security audit prior to the attack. These platforms, however, account for 88.44 per cent of all recorded losses.
CoinGecko states that this does not imply that the audit body had previously endorsed the relevant loophole. According to the report, only about 11 per cent of incidents relate to the extent of loopholes that conventional smart contract audits typically cover. While this portion of the incident continued to result in losses of approximately $396 million, more cases came from external infrastructure, unaudited software updates, voucher leakage or governance mechanisms.
The report also noted that the audit was essentially a stage check of a certain version of the code. The change in code following the audit, the setting of audit coverage, the audit methodology and whether the development team has repaired the identified problems will all affect the end effect.
The chain's insurance coverage is down.
The report shows a 20.2 per cent decline in the effective coverage of insurance agreements on the main chain, from $163.2 million to $130.2 million, while the cumulative level of payments remained at approximately $33 million. By August 2026, 5 of the 9 agreements followed by CoinGecko had ceased active operations or moved to other operations.
CoinGecko attributed this change to increased risk, higher premiums and difficulties in accessing funding sources. At the same time, the report reminds that the scale of insurance coverage of $130.2 million is not directly comparable to the loss of $3.63 billion, as the former is stock data at a given point in time, while the latter is cumulative loss from events within 19 months.
Many policies also have a narrower definition of compensation. Some of the products cover only empirically proven smart contract failures, excluding fishing attacks, theft of private keys, employee error, market fluctuations or loss of support chain.
Exchanges rely more on their own security.
According to the report, more and more central exchanges have chosen to establish investor protection funds rather than to purchase full external insurance. Such reserves may provide a faster recovery capability after an attack on the platform.
However, protection funds are not equivalent to regulated insurance. Actual coverage continues to depend on the terms of the exchange, the manner in which the reserve assets are held, the composition of the assets and the Platform ' s determination of the award event.
CoinGecko also referred to the fact that the certificate of reserve only indicates that the exchange controls a portion of the assets corresponding to the customer ' s balance, does not prove the security of the private key management or that the full amount of the liability has been disclosed.
