The scale of damage in the crypto sector continues to grow at an alarming rate. Between January 2025 and July 2026, I recorded 245 documented incidents, with total losses reaching $3.63 billion. This is not just statistics—it is a systemic security crisis that requires an immediate reassessment of approaches to asset protection.

Infrastructure Under Attack

The most devastating attack vector has been vulnerabilities in infrastructure and supply chains. This category accounts for over $1.8 billion in losses suffered by both centralized and decentralized platforms. Notably, the largest incidents—the Bybit hack at $1.43 billion and the attack on Kelp with damages of $292 million—fall precisely into this category.

For centralized exchanges, the primary risk factor remains the compromise of private keys. Meanwhile, decentralized applications lost $546 million due to smart contract errors. At the same time, both models demonstrate vulnerability to manipulation through oracles and market mechanisms, as confirmed by incidents involving Bitget, Binance, and Hyperliquid.

Audit Is Not a Panacea

Particular attention should be paid to the section of the report dedicated to audit effectiveness. Of the 245 incidents, 147 involved protocols that had passed audits before the hack. These platforms accumulated 88.44% of all funds withdrawn during the specified period. Only 11% of these cases were related to errors that auditors could theoretically have identified—the damage from them amounted to $396 million.

This is sobering statistics. It demonstrates that standard code reviews often create a false sense of security, failing to cover real attack vectors such as social engineering or complex multi-step exploits.

The Insurance Sector Is Shrinking

The crypto insurance market is going through tough times. Active coverage on the largest on-chain protocols has declined by 20.2%—from $163.2 million to $130.2 million. Total payouts remain at $33 million, and five of the nine insurance protocols have either ceased operations or changed their specialization as of August 2026. This is an alarming signal: the industry is losing protection mechanisms precisely when they are most needed.

As for centralized exchanges, they are increasingly resorting to creating compensation funds to cover user losses. However, measures such as Proof-of-Reserve, in my assessment, provide weak protection against social engineering and critical failures in key security. These are merely cosmetic solutions that do not address the root causes of vulnerabilities.

My conclusion: the industry needs a fundamental shift from reactive to proactive security. Audits must become continuous rather than one-off, and insurance must become a mandatory element of infrastructure rather than an option. Otherwise, we risk seeing even more devastating figures in the next reporting period.