Between January 2025 and July 2026, crypto platforms racked up a staggering $3.63 billion in losses across 245 documented security incidents, according to CoinGecko’s latest cybersecurity report.

Infrastructure and Supply Chain: The Biggest Attack Vector

CoinGecko flags infrastructure and supply chain vulnerabilities as the most damaging attack class during this period. The report estimates that both centralized and decentralized projects lost over $1.8 billion to these kinds of exploits.

Biggest Hits: Bybit and Kelp Lead the Pack

When it comes to the largest hacks, CoinGecko points to Bybit, which suffered $1.43 billion in losses, and Kelp, which lost $292 million. These two incidents top the list for financial impact in the timeframe.

Main Threat for CEX: Private Key Compromise

For centralized exchanges, the report singles out private key compromise as the top risk factor. CoinGecko highlights this as the key reason behind most major incidents at CEXs.

The report’s findings drive home just how massive the financial fallout can be—and how infrastructure vulnerabilities remain a prime threat to both centralized and decentralized crypto projects.