The scale of cyber threats to the crypto industry continues to grow at an alarming rate. From January 2025 to July 2026, cumulative platform losses reached $3.63 billion, spread across 245 documented incidents. This is not just statistics—it is a systemic challenge for the entire ecosystem, requiring a rethink of security approaches.

Infrastructure Under Attack

The most devastating attack vector has been vulnerabilities in infrastructure and supply chains. Centralized and decentralized projects lost over $1.8 billion due to these. The largest targets for hackers were the exchange Bybit with damages of $1.43 billion and the Kelp protocol, which lost $292 million. These incidents clearly demonstrate: even leading players are not immune to fatal flaws in their defenses.

For centralized exchanges, the main source of risk remains the compromise of private keys. At the same time, decentralized applications suffered $546 million in losses due to smart contract exploits. Analysts also note the vulnerability of both models to manipulation through oracles and market mechanisms, as confirmed by incidents involving Bitget, Binance, and Hyperliquid.

Audits Are Not a Panacea

Special attention deserves the section on audit quality. Of the 245 incidents, 147 involved protocols that had passed verification before the hack. These platforms accounted for 88.44% of all capital drained over 19 months. Moreover, only 11% of these cases were linked to errors that an audit could have identified within its scope, with damages amounting to $396 million. This calls into question the effectiveness of current code review standards.

Insurance Is Shrinking

A worrying signal is the contraction of the crypto insurance segment. Active coverage on the largest insurance protocols dropped by 20.2%—from $163.2 million to $130.2 million. Cumulative payouts remain at $33 million, and five of the nine on-chain insurance protocols either became inactive or shifted segments by August 2026. The insurance protection market is clearly failing to keep pace with the growth of threats.

Centralized exchanges are trying to offset risks through user protection funds, but standard measures like Proof-of-Reserve offer weak resistance to social engineering and critical security failures of keys. I should note that on August 27, the Moonwell protocol also suffered an attack of $8.7 million—this is just another link in the chain of systemic problems.

My analysis: The market clearly underestimates the complexity of protecting infrastructure. The fact that most hacked platforms had passed audits points to a formal approach to verification. The industry needs not just new tools, but a paradigm shift: from reactive defense to proactive threat modeling and multi-layered monitoring systems. Otherwise, the $3.63 billion figure may seem insignificant against the backdrop of future losses.