Crypto scams and hacks continued at a high frequency in 2026, with attackers carrying out 207 separate hacks during the first half of the year. Despite the increase in incidents, total losses fell to $972 million, less than half of the $2.3 billion stolen during the first half of 2025.
CoinGecko’s recent report, titled ‘2026’s State of Crypto Security’, documented 245 security incidents affecting crypto platforms between January 2025 and July 2026. Together, the incidents resulted in $3.63 billion in losses.
Crypto hack losses remain concentrated
The 10 largest attacks accounted for more than 72.5% of all stolen funds. Decentralized exchanges (DEXs) and decentralized applications (dApps) faced significant exposure to smart-contract exploits, which caused approximately $546 million in losses.
However, crypto security threats increasingly extended beyond core code. More than $1.8 billion was lost through infrastructure and supply-chain vulnerabilities, including weaknesses in third-party services, integrations, and software updates. High-profile examples included security failures at Bybit and KelpDAO.
Of the 245 documented incidents, 147 involved audited protocols. These incidents accounted for 88.44% of all stolen capital.
Only about 11% of the attacks targeting audited protocols exploited vulnerabilities within the scope of the relevant audits, resulting in approximately $396 million in losses. Most attacks instead involved infrastructure, third-party services, governance systems, front ends, or human error.
Crypto insurance coverage declines
Despite the increase in crypto hacks, active insurance coverage declined from $163.2 million to $130.2 million, covering 20.2% of the sector. Cumulative payouts, meanwhile, remained at approximately $33 million.
The on-chain insurance sector also struggled to scale. By August 2026, five of nine on-chain insurance protocols had become inactive or pivoted to other activities.
SEC reviews crypto custody rules
The developments came as the SEC revisited its Custody Rule to clarify who can safeguard customers’ crypto assets.
On 25th August, the agency submitted proposed amendments to OIRA for review. Publication was expected by October 2026, followed by at least 60 days of public comments. The rules are not yet effective, however. Further analysis and a second SEC vote would still be required, meaning mandatory compliance could take several years.
The report’s key findings show that the largest 10 attacks accounted for more than 72.5% of all stolen funds, while 147 of the 245 documented incidents involved audited protocols and represented 88.44% of all stolen capital.
Source: cryptonews.net
