My analysis of the latest cybersecurity data has revealed a troubling trend: between January 2025 and July 2026, the crypto industry lost a staggering $3.63 billion as a result of 245 documented incidents. These are not just numbers—this is a systemic crisis of trust that demands an immediate reassessment of asset protection approaches.

Infrastructure—the primary point of failure

The most devastating attack vector has been vulnerabilities in infrastructure and supply chains. These alone accounted for over $1.8 billion in combined losses across both centralized and decentralized platforms. The largest targets for hackers were the exchange Bybit, which lost $1.43 billion, and the Kelp protocol, with losses of $292 million.

For centralized exchanges (CEX), the compromise of private keys remains a critical risk. At the same time, decentralized applications lost $546 million due to smart contract exploits. Notably, both models proved vulnerable to manipulation through oracles and market mechanisms, as well as to internal errors—this affected even giants such as Bitget, Binance, and Hyperliquid.

Audits do not guarantee security

The audit paradox deserves special attention. Of the 245 incidents, 147 involved protocols that had passed verification before the hack. These platforms accounted for 88.44% of all capital drained over the 19-month period. Meanwhile, only about 11% of cases were linked to vulnerabilities that an audit should have identified—with damages amounting to $396 million. This suggests that standard checks often fail to cover real attack vectors.

The insurance sector is shrinking

Another important signal is the contraction of the crypto insurance market. Active coverage on the largest insurance protocols fell by 20.2%, from $163.2 million to $130.2 million. Cumulative payouts remain at $33 million, while five of the nine on-chain insurance protocols are now inactive or have shifted their focus. This creates a protection vacuum for investors.

Centralized exchanges are attempting to offset risks through protection funds, yet measures such as Proof-of-Reserve, in my assessment, are largely ineffective against social engineering and critical failures in key security. I should note that on August 27, the Moonwell protocol already suffered an $8.7 million attack, which only confirms the systemic nature of the problem.

My conclusion: the industry is at a tipping point. Current security measures are outdated, and insurance mechanisms are failing to keep pace with the growing complexity of attacks. Without the implementation of fundamentally new standards—from multi-layered authentication to dynamic audits—we risk seeing even more massive losses in the coming quarters.