The crypto industry has hemorrhaged $3.63 billion to security breaches since the start of 2025, according to a new report from CoinGecko. That figure covers January 2025 through early August 2026, a stretch during which the pace of attacks has quickened considerably even as the sector tries to professionalize its defenses.
To put that number in perspective, total crypto hack losses since 2016 have now exceeded $14.27 billion. The last 19 months account for roughly a quarter of a decade’s worth of damage.
The numbers tell two different stories
The 2025 portion of CoinGecko’s data shows $2.55 billion lost across 97 incidents. That works out to about $26.3 million per incident on average, though the distribution was heavily skewed by one catastrophic event: the Bybit exchange breach, attributed to North Korean actors, which alone accounted for roughly $1.4 to $1.5 billion in losses.
Strip out Bybit, and the remaining 96 incidents from 2025 totaled around $1.1 billion.
The 2026 data, covering only the first seven-plus months of the year, shows approximately $1.2 billion lost. But the incident count has already ballooned to 164. That’s nearly 70% more individual breaches than all of 2025, packed into a shorter window.
Average loss per incident in 2026 sits around $7.3 million, a fraction of 2025’s inflated average.
One month stands out. April 2026 alone recorded over $644 million in losses, with incidents again linked to North Korean threat actors. That single month nearly matched the non-Bybit total for all of 2025.
DeFi takes collateral damage
The CoinGecko report highlights the KelpDAO exploit as a case study. That incident exploited a vulnerability in a LayerZero bridge, and its consequences extended well beyond the immediate funds stolen. Aave’s total value locked dropped from approximately $25.9 billion to $14.4 billion in the aftermath. That’s a $11.5 billion TVL decline, dwarfing the direct exploit losses.
Secondary market effects compounded the problem. Tokens like STEP, DRIFT, and BONK experienced sharp price declines following major incidents, even when those specific tokens weren’t directly involved in the exploits.
The evolving threat landscape
The types of attacks documented in the report reveal a qualitative shift alongside the quantitative surge. Operational vulnerabilities, including governance attacks and private-key compromises, remain persistent threats that no amount of smart contract auditing can fully address.
North Korean state-sponsored actors continue to loom large in the data. The Bybit breach in 2025 and the cluster of April 2026 incidents both carry attribution to groups associated with Pyongyang.
The historical comparison is sobering. The previous peak year for crypto losses was 2022, at $2.77 billion. The 2025 figure of $2.55 billion came close to matching it, and only if you exclude Bybit does the year look like an improvement. Including it, 2025 set a new record.
The acceleration in incident count, from 97 in all of 2025 to 164 in just seven months of 2026, suggests that the attack surface is expanding faster than the industry’s ability to secure it.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

4 hours ago
5





English (US) ·