Crypto platforms lost $3.63 billion across 245 documented security incidents from January 2025 through July 2026, CoinGecko’s State of Crypto Security Report published August 27, 2026 found, a figure best read as a reported loss estimate because recoveries and freezes are not clearly netted out. In the first half of 2026 alone, attackers carried out 207 separate hacks that produced $972 million in losses, less than half of the $2.3 billion stolen in the first half of 2025. The 10 largest attacks accounted for more than 72.5% of stolen value, led by the February 2025 Bybit breach of about $1.44 billion via compromised transaction-signing infrastructure, followed by KelpDAO at $292 million, Drift Protocol at $285 million and Cetus at $223 million. Infrastructure and supply-chain compromises caused more than $1.8 billion in losses, decentralized applications lost roughly $546 million to smart-contract exploits, and private-key compromise remained the leading centralized-exchange risk, with North Korea-linked operations alone draining about $577 million through social engineering and bridge infrastructure. Audited platforms represented 147 incidents and 88.44% of reported losses, yet only about 11% of incidents involved flaws inside routine smart-contract audit scope, still totaling roughly $396 million. Active onchain insurance coverage fell 20.2% to $130.2 million as five of nine tracked protocols exited or pivoted by August 2026, while the SEC submitted proposed Custody Rule amendments to OIRA on August 25, with publication expected by October 2026 though the rules are not yet effective and mandatory compliance could still take several years. Separate DefiLlama tracking showed 2026 incidents more than doubling even as total losses fell about 45% versus the same stretch of 2025.