Active crypto insurance coverage dropped 20.2% from $163.2 million to $130.2 million between January 2025 and July 2026, even as security exploits surged. Crypto platforms lost over $3.63 billion across 245 attacks during the period. The 10 largest incidents accounted for more than 72.5% of total losses. Infrastructure and supply-chain vulnerabilities caused over $1.8 billion in damages. Most attacked platforms had been audited: 147 of the 245 attacks involved audited protocols, which accounted for over 88% of total funds drained. Audits often miss external infrastructure, unaudited code changes, and governance attacks. Crypto insurance is shrinking, with cumulative payouts unchanged at $33 million, and five of nine on-chain insurance protocols have become inactive.
Crypto platforms lost more than $3.63 billion to security incidents between January 2025 and July 2026, with 245 attacks documented. The 10 largest incidents accounted for more than 72.5% of the total amount stolen.
Infrastructure and supply-chain vulnerabilities were the biggest sources of damage across both centralized and decentralized exchanges. Combined losses exceeded $1.8 billion.
Notable security failures involved Bybit and KelpDAO. As stated in a security report, the main weaknesses differ depending on how platforms are built.
For centralized exchanges, compromised private keys remained the most common point of failure. Decentralized applications lost $546 million through sophisticated smart contract exploits.
Both centralized and decentralized platforms remain exposed to oracle and market manipulation. Errors in internal mechanisms caused major losses for platforms including Bitget, Binance, and Hyperliquid.
The report found that having an independent audit did not prevent many incidents. Of the 245 attacks, 147 involved protocols that had undergone audits before being compromised.
These audited platforms accounted for over 88% of the total capital drained during the 19-month period. Conventional audits often do not cover the areas exploited in major attacks.
Many incidents involved external infrastructure, unaudited code changes, or systemic features manipulated through governance attacks. Only about 11% of incidents involving audited platforms were linked to smart contract vulnerabilities within the audit scope, though those flaws still caused $396 million in losses.
Centralized exchanges generally do not use the same audit model as decentralized protocols. They instead rely on compliance measures and financial attestations such as Proof-of-Reserve, which provide limited protection against social engineering and private-key failures.
Even as exploits increased, active coverage across leading crypto insurance protocols declined 20.2%, falling from $163.2 million to $130.2 million. Cumulative payouts have remained largely unchanged at $33 million.
The report said high risks in the sector may have discouraged users from supplying capital or buying coverage at higher premium prices. Crypto insurance can also have a narrow scope, as claims are often limited to verified smart contract exploits or infrastructure failures.
Losses linked to human error, compromised private keys, or market volatility may not qualify. As of August 2026, five of nine on-chain insurance protocols had become inactive or moved to other segments.
