Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Crypto Insurance Coverage Shrinks 20% to $130 Million While Hacks Drain $3.63 Billion

The crypto industry has a $3.63 billion hacking problem and a shrinking safety net to match it.
According to CoinGecko's 2026 State of Crypto Security Report, released August 27, crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026. At the same time, active on-chain insurance coverage dropped 20.2%, from $163.2 million to $130.2 million, according to the same report.
Insurance payouts over that stretch held near $33 million, according to CoinGecko. That covers roughly 0.9% of total losses. Everyone else eats the loss.
Insurers Are Walking Away
Five of the nine on-chain insurance protocols CoinGecko tracks have either shut down or pivoted away from crypto coverage entirely as of August 2026, per the report. Crypto Briefing attributes the exodus to sky-high premiums and insurers' inability to attract capital willing to underwrite the risk. AmBCrypto's coverage of the same report frames it more clinically: the sector is "struggling to scale."
Either way, the outcome is the same. The market that's supposed to backstop investors when a protocol gets drained is getting smaller at the exact moment attacks are accelerating.
Tekedia's breakdown of the CoinGecko data shows incident frequency spiked hard in 2026: 164 breaches in the first seven-plus months of the year, versus 97 for all of 2025, a roughly 70% jump. AmBCrypto notes a wrinkle worth flagging: despite 207 separate hacks in the first half of 2026 alone, total dollar losses for that period were $972 million, less than half the $2.3 billion stolen in the first half of 2025. More attacks, smaller average payday per attack. This represents a shift in attacker behavior, not evidence the problem is easing.
Where the Money's Actually Going
Infrastructure and supply-chain attacks accounted for more than $1.8 billion of total losses, according to CoinGecko, making them the single biggest category. The report names the Bybit exchange breach and the KelpDAO restaking protocol hack as headline cases.
Bybit's February breach alone cost roughly $1.44 billion and involved compromised transaction-signing infrastructure, not a smart contract bug, according to Crypto.news. KelpDAO lost about $292 million, Drift Protocol $285 million, and Cetus $223 million, per Incrypted's and Crypto.news's summaries of the report.
Centralized exchanges are most exposed through private-key compromise. Decentralized apps lost around $546 million to smart-contract exploits specifically, according to CoinGecko. Crypto.news also cites two North Korea-linked operations that drained roughly $577 million combined using social engineering and bridge-infrastructure compromises, not code flaws.
Audits Aren't the Answer Either
147 of the 245 hacked platforms, about 60%, had already passed an independent security audit before getting hit, according to CoinGecko. Those audited platforms accounted for 88.44% of all money stolen.
Only about 11% of incidents actually involved vulnerabilities inside the scope of a typical audit, CoinGecko found, responsible for roughly $396 million in losses. Everything else, the bulk of the damage, came from infrastructure weaknesses, unaudited code updates, governance attacks, and human error that no code review was ever designed to catch.
A clean audit report tells you the contract logic was reviewed at one point in time. It tells you nothing about whether an employee's laptop gets phished six months later or whether a bridge operator's key gets stolen.
Big Players Self-Insure, Everyone Else Is Exposed
With the on-chain insurance market shrinking, Binance now maintains a self-funded protection reserve of roughly $1.16 billion, according to Crypto Briefing, nearly nine times the size of the entire on-chain insurance market combined. That works if you're Binance.
It doesn't work if you're a smaller exchange or DeFi protocol without a spare billion dollars sitting in reserve. For those platforms, a shrinking insurance market means operating with essentially zero financial backstop if they get hit.
Crypto.news pointed out that CoinGecko's published summary doesn't clearly state whether recovered or frozen assets were subtracted from the $3.63 billion figure. Treat that number as CoinGecko's reported loss estimate, not necessarily a final net-loss total after any recoveries.
Meanwhile, regulators are moving, slowly. AmBCrypto reports the SEC submitted proposed amendments to its Custody Rule, which governs who can safeguard customer crypto, to the Office of Information and Regulatory Affairs on August 25. Publication is expected by October 2026, followed by at least a 60-day public comment period. A second SEC vote and further analysis would still be required before any mandatory compliance, a process that could take years. Until then, the rules governing custody of billions in customer crypto assets remain unchanged, and the industry's own shrinking insurance market is what's left standing between users and the next nine-figure exploit.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.