Security remains a major priority in crypto, yet losses continue to rise, with more than $3.63 billion stolen since 2025. CEXs are most exposed by private key compromise, while DEXs suffer from smart contract exploits, increasingly compounded by fake user interfaces and malicious integrations. The actors evolved just as quickly. Outlaw individuals have given way to organized cartels and state-sponsored groups, including North Korean hackers, who now use mixers, bridges and staggered takedowns to remain untraceable. This report examines the evolving threat landscape, from auditing and assurance protocols to the security infrastructure that CEXs like Toobit deploy to protect users. We’ve summarized the key points, but be sure to check out the full 15 slides in the full report here.

Key Points
- Crypto platforms have lost more than $3.63 billion since the start of 2025, mainly due to supply chain attacks, smart contract exploits and stolen private keys
- Around 60% of exploited crypto platforms had carried out independent security audits, although most attacks go beyond the scope of conventional auditing
- Active coverage by crypto insurance platforms fell -20.2% from $163.2 million to $130.2 million despite rising exploits
- Centralized exchanges launch protection funds to ensure users are covered in the event of an exploit
1. Crypto platforms have lost over $3.63 billion since the start of 2025, mainly due to supply chain attacks, smart contract exploits and stolen private keys




The frequency of crypto-specific exploits has reached unprecedented levels in recent years. Between January 2025 and July 2026, crypto platforms suffered huge losses of $3.63 billion in 245 documented incidents. Notably, the top 10 largest attacks accounted for more than 72.5% of the total value stolen during this period.
Infrastructure and supply chain vulnerabilities have proven to be the most devastating for CEXs and DEXs, with over $1.8 billion lost to such breaches. Prominent examples include security failures at Bybit and KelpDAO.
Vulnerabilities vary significantly depending on platform architecture. For centralized exchanges (CEX), the most common point of failure remains private key compromise. In contrast, decentralized applications (dApps) suffered a $546 million drain due to sophisticated smart contract exploits.
Despite these differences, both types of platforms remain vulnerable to oracle and market manipulation. Errors in internal mechanisms have led to significant losses for prominent entities including Bitget, Binance and Hyperliquid.
2. Around 60% of mined crypto platforms had carried out independent security audits, although most attacks go beyond the scope of conventional auditing


The prevalence of security breaches remains a persistent threat, even for verified platforms. Out of 245 incidents documented since the start of 2025, 147 concerned protocols that had undergone audits before being compromised. These verified entities represented an incredible 88.44% of the total capital drained over the last 19 months.
Audit reports often do not capture the entire spectrum of risks. Most exploits on audited systems target external infrastructure, unaudited code updates, or systemic functionality manipulated through governance attacks. Surprisingly, only about 11.0% of these incidents involved smart contract breaches as part of the audit, although these still caused $396.0 million in losses.
Centralized platforms operate under different security paradigms. While CEXs typically bypass decentralized audit formats, they must navigate rigorous compliance frameworks and financial attestations, such as Proof of Reserve, to build user confidence. However, these protections offer little defense against social engineering or catastrophic failures in private key security.
3. Active coverage by crypto insurance platforms fell -20.2% from $163.2 million to $130.2 million despite the rise in exploits


Despite the increase in exploits, active coverage on major crypto insurance protocols decreased consistently by -20.2% from $163.2 million to $130.2 millionwhile cumulative payments remained broadly stagnant at $33.0 million.
This is likely due to an already high level of risk in the crypto space, which has discouraged users from providing capital as well as purchasing premiums at high prices.
Additionally, the scope of crypto-based protection can be very restrictive, limiting claims only to verified smart contract exploits or infrastructure failures. Users may not receive payment if the exploit stems from human error, compromised private keys, or general market volatility.
Thus, the demand for on-chain coverage has never really been put forward; as of August 2026, 5 of 9 on-chain insurance protocols have become inactive or pivoted to other segments.
4. Centralized exchanges launch protection funds to ensure users are covered in the event of an exploit


Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
