Headline: CoinGecko: Crypto Hacks Have Cost Platforms $3.63B in 19 Months — But the Risk Profile Is Changing CoinGecko’s State of Crypto Security report (Aug. 27) finds that crypto platforms reported $3.63 billion in losses across 245 documented security incidents between January 2025 and July 2026. The number is a reported loss estimate from CoinGecko’s dataset — it’s not clear whether recovered or frozen assets were fully subtracted — and it exposes a shifting, concentrated threat landscape. Key takeaways - Total reported losses: $3.63 billion across 245 incidents (Jan 2025–Jul 2026). - Concentration: the top 10 breaches accounted for more than 72.5% of the total stolen value. - Infrastructure and supply-chain compromises: responsible for over $1.8 billion of losses. - dApps: roughly $546 million lost to smart-contract exploits. - CEX risk: private-key compromise identified as the leading vulnerability for centralized exchanges. - Largest single incident: the February 2025 Bybit breach (~$1.44 billion) — driven by compromised transaction-signing infrastructure, not a smart-contract bug. Major incidents mentioned - Bybit (Feb 2025): ~$1.44B — compromised transaction-signing infrastructure. - KelpDAO: ~$292M breach. - Drift Protocol: ~$285M attack. - Cetus: ~$223M exploit. - Two North Korea-linked campaigns: ~ $577M drained via social engineering and bridge/infrastructure compromises (not typical contract flaws). Why one security control isn’t enough The report emphasizes that many high-dollar incidents stem from infrastructure and supply-chain failures: private keys, employee devices, front-end code, software dependencies and bridge operators — elements that often lie outside the scope of routine smart-contract audits. CoinGecko estimates only about 11% of incidents involved vulnerabilities that would typically fall within a standard smart-contract audit, though those in-scope failures still caused roughly $396 million in losses. Audit reality: helpful but limited - 147 of the 245 affected platforms (~60%) had completed independent security audits prior to being attacked; these platforms represented 88.44% of recorded losses. - Audits are snapshots of specific code at a specific time. Post-audit code changes, unaudited updates, and operational or governance weaknesses can introduce new risks. - CoinGecko cites Ripple’s security review — which flagged 96 issues before code reached users — as an example of how timely audits can prevent losses, but stresses audits can’t replace continuous monitoring and robust operational security. Insurance and coverage: shrinking, narrow protection - Onchain insurance coverage tracked by CoinGecko fell 20.2%, from $163.2M to $130.2M; cumulative payouts stayed near $33M. - Five of nine tracked insurance protocols were inactive or pivoted by Aug. 2026. CoinGecko attributes retreats to higher risk, costly premiums and difficulty attracting capital. - Coverage definitions are often narrow: many policies exclude phishing, private-key theft, employee mistakes, unsupported chains and market volatility. The $130.2M coverage figure is a snapshot and not directly comparable to the $3.63B cumulative loss figure. CEX alternatives and caveats - More centralized exchanges are building investor-protection funds instead of buying broad external insurance; these funds can speed reimbursements but are not synonymous with regulated insurance — coverage depends on fund terms, custody, asset mix and discretionary payout rules. - Proof-of-reserves attestations show an exchange controls assets equivalent to reported customer balances but don’t prove secure key management or that all liabilities are fully disclosed. What’s next CoinGecko’s report signals two key shifts needed across the industry: - Expand security scope beyond smart contracts to include operational systems, bridges, software dependencies, signing infrastructure and governance processes. - Insurance markets must evaluate whether they can offer broader, meaningful coverage without pricing premiums out of reach. Bottom line: Losses remain heavily concentrated and increasingly driven by infrastructure and operational failures rather than just contract bugs. Audits and insurance can help, but they are not a panacea — the industry needs broader, continuous controls and risk-transfer products that reflect the real attack surface. Read more AI-generated news on: undefined/news