Sell crypto Coins Why Monica FAQ API Get the app
Safety September 23, 2026 5 min read

Crypto Security Is Under Pressure as $3.63 Billion Is Stolen

A new CoinGecko report reveals how attackers are moving beyond traditional hacks, targeting private keys, infrastructure and smart contracts as crypto platforms face a growing security challenge

Crypto Security Is Under Pressure as $3.63 Billion Is Stolen

The biggest danger in crypto may not always be the price on your screen.

Sometimes, it is what happens behind it.

A new report from CoinGecko shows just how expensive that problem has become. Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, highlighting how quickly attacks are evolving across exchanges, decentralised applications and the infrastructure connecting them. 

The headline figure is enormous, but the story behind it is even more revealing.

The losses were not evenly distributed across hundreds of unrelated incidents. CoinGecko found that the 10 largest attacks accounted for more than 72.5% of the total value stolen, meaning a relatively small number of major breaches were responsible for most of the money lost. 

And attackers are not relying on just one method.

The attack is moving beyond the wallet

Supply-chain and infrastructure attacks have emerged as particularly damaging. According to CoinGecko, these attacks accounted for more than $1.8 billion in losses during the period covered by the report.

For centralised exchanges, compromised private keys remain a major vulnerability. For decentralised applications, smart contract exploits are among the most significant risks, with CoinGecko recording $546 million in losses from smart contract exploits. 

That distinction matters because the risks are different depending on where a user keeps or interacts with their crypto.

A centralised exchange can have sophisticated compliance systems and security infrastructure and still face a devastating private-key compromise. A decentralised application can undergo a security review and still be exposed through another part of its technology stack.

In other words, security is no longer simply about whether a platform has been audited.

An audit is not a magic shield

One of the report's more surprising findings concerns security audits.

Of the 245 documented incidents, 147 involved platforms that had completed independent security audits before they were compromised. Those incidents represented 88.44% of the total capital lost during the period.

That does not mean security audits are useless. Rather, CoinGecko's analysis suggests that many attacks happened outside the areas covered by conventional audits, including external infrastructure, unaudited updates and broader systems that could be manipulated. Only about 11% of the incidents involved smart-contract flaws that were within the scope of the relevant audits, resulting in approximately $396 million in losses. 

For users, the lesson is straightforward: an “audited” label should not be treated as a guarantee that funds cannot be lost.

The people behind the attacks are changing too

The threat is also becoming more organised.

CoinGecko says crypto attacks have increasingly involved organised groups and state-sponsored actors, including North Korean-linked hackers. The report notes the use of mixers, bridges and staggered withdrawals as part of efforts to make stolen funds more difficult to trace. 

That evolution makes security a shared responsibility across the industry.

Platforms need stronger infrastructure and monitoring. Developers need to consider vulnerabilities beyond the code being audited. Exchanges need robust controls around private keys. And users need to become harder targets themselves.

That last part is particularly important because sophisticated technology cannot always protect someone who willingly hands an attacker the information needed to access an account.

A fake website can look legitimate.

A phishing message can appear to come from a familiar platform.

A fraudulent airdrop can look like an opportunity.

And once a private key or recovery phrase has been exposed, the consequences can be difficult, if not impossible, to reverse.

The insurance gap

There is another problem hiding behind the hacks: what happens after the money disappears?

CoinGecko found that active coverage from crypto insurance platforms fell 20.2%, from $163.2 million to $130.2 million, even as the industry continued experiencing major exploits. The report also noted that some centralised exchanges have introduced protection funds designed to provide users with coverage in the event of an exploit. 

So while the industry is losing billions to security incidents, the pool of active insurance protection measured by CoinGecko has moved in the opposite direction.

For crypto users, that makes prevention particularly important.

What should crypto users do?

There is no single trick that makes crypto completely safe, but basic security practices can significantly reduce avoidable risks.

Use strong, unique passwords and enable two-factor authentication wherever it is available. Double-check website addresses before connecting a wallet or entering sensitive information. Be extremely cautious with unsolicited links, investment opportunities, giveaways and airdrops.

For significant long-term holdings, understand the difference between keeping assets on an exchange and controlling them through a personal wallet. If you use a self-custody wallet, protect your recovery phrase as carefully as you would protect the assets themselves and never share it with anyone claiming to offer technical support.

Most importantly, slow down when money is involved.

Many attacks depend on creating urgency: act now, claim this reward, verify your account, connect your wallet. Taking an extra minute to verify what you are being asked to do can be worth far more than the opportunity being offered.

The crypto industry is building faster, but so are the people trying to break into it. CoinGecko's latest figures make one thing clear: security cannot be an afterthought once the money is already on the blockchain. 

Your crypto journey should not end with a scammer holding the keys. Keep your guard up, verify before you click, and when it is time to turn your crypto into naira, let Monica handle the conversion while you stay focused on your next move.

Download Monica Now: https://monica.cash/app

Continue reading