A crypto hack by no means ends when the pockets is drained. The theft lands first, quick and visual, after which a slower collapse begins to work by the remainder of the challenge.
The token retains sliding, the treasury shrinks with it, hiring plans get in the reduction of, product deadlines transfer, companions draw back, and the corporate that was purported to recuperate spends months combating for credibility as an alternative of constructing.
That is the image Immunefi’s new “State of Onchain Safety 2026” report paints. Its argument is straightforward sufficient for any market, crypto or in any other case: the preliminary loss is just one a part of the injury.
The a lot larger downside comes from what the exploit does to a challenge’s future. Immunefi says the typical direct theft in its pattern got here to about $25 million, whereas hacked tokens noticed a median six-month decline of 61%. In that window, 84% didn’t recuperate to their hack-day worth, and groups misplaced a minimum of three months of progress to restoration work.
However these numbers include caveats. Token costs fall for a lot of causes, and hacked initiatives are sometimes fragile earlier than an exploit hits. Some are illiquid, overvalued, or already shedding momentum.
Immunefi acknowledged that it may well’t at all times totally separate hack injury from broader market weak point or project-specific troubles. Even so, the sample it lays out deserves consideration as a result of it reveals that hacks do not behave like remoted thefts anymore, and so they now appear to be long-tail company crises.
That is what offers weight to the report: it reveals how typically the post-hack interval retains inflicting injury nicely after the headline fades.
The median hack might need shrunk, however the worst ones bought extra harmful
Immunefi counted 191 hacks throughout 2024 and 2025, totaling $4.67 billion and bringing its five-year whole to 425 hacks and $11.9 billion in losses.
The yearly depend barely moved, with 94 identified hacks in 2024 and 97 in 2025, virtually similar to 2023. That tells us that the market did not do an excellent job of changing into safer. Hacks at the moment are simply a part of on a regular basis life in crypto, whereas the enormous ones go on to outline the yr.
The principle contradiction specified by the report is within the averages.
The median theft in 2024-2025 was $2.2 million, down from $4.5 million in 2021-2023. On the floor, which may appear to be progress. Nevertheless, the typical theft nonetheless got here to roughly $24.5 million, greater than 11 instances the median. Within the precedent days, that hole was 6.8 instances. The highest 5 hacks accounted for 62% of all funds stolen, and the highest 10 made up 73%.
This can be a very harmful sort of distribution. It makes the market feel and appear secure and secure till one large occasion rips by it. So, the everyday exploit is perhaps smaller than it was, however the hazard sits within the tail. That is the place a handful of big failures soak up a lot of the injury and crash the market in a day.
Simply have a look at Bybit. The alternate’s $1.5 billion exploit grew to become the defining hack of 2025 and, in Immunefi’s accounting, represented 44% of all funds stolen that yr.
It is simple to deal with that sort of occasion as a spectacle. However it reveals a a lot deeper focus downside. One failure at one main venue can distort the business’s annual loss profile and expose how a lot threat nonetheless sits in simply a few essential chokepoints.
The longer decline is the place initiatives begin to break
Whereas the report’s knowledge on theft is actually attention-grabbing, essentially the most eye-opening half is its worth injury part.
In Immunefi’s pattern of 82 hacked tokens, the preliminary shock was primarily the identical. The median two-day decline was about 10%, roughly consistent with the sooner cycle. However the greatest impact was felt later, because the median six-month decline worsened to 61%, up from 53% within the 2021-2023 examine.
On the six-month mark, 56.5% of hacked tokens have been down greater than half, and 14.5% have been down greater than 90%. Solely about 16% traded above their hack-day worth six months later.

To grasp the complete impact of a hack, we have to cease treating token costs as an remoted market function. For many crypto firms, the token acts as a treasury, financing base, and sometimes a public scorecard. A chronic drawdown cuts immediately into an organization’s runway, recruiting energy, dealmaking leverage, and inner morale.
The report famous that hacked initiatives typically lose safety management inside weeks and spend a minimum of three months in restoration mode. Even when these timelines fluctuate by challenge, the results are plain to see. An organization with a broken token and a broken model has fewer methods to purchase time.
Loads of markets can soak up a theft, or a nasty quarter, or perhaps a reputational hit. However crypto typically compresses all three into the identical occasion. The exploit drains funds, the token reprices the enterprise in public, and counterparties react earlier than the inner cleanup is completed. That is a tough surroundings wherein to recuperate, particularly for groups that have been by no means overcapitalized within the first place.
Dependency threat makes it even worse. Immunefi argues {that a} extra interconnected DeFi stack has created longer chains of vulnerability throughout bridges, stablecoins, liquid staking, restaking, and lending markets.
That time ought to be dealt with rigorously, particularly when the report makes use of case research that deserve exterior verification. Nonetheless, the broader course is difficult to dismiss. Crypto techniques are extra layered than they have been a couple of years in the past, and meaning a hack can journey a lot farther than the protocol the place it began.
Centralized venues nonetheless sit close to the middle of the blast zone.
The report says solely 20 of the 191 hacks in 2024-2025 concerned centralized exchanges, but these incidents accounted for $2.55 billion, or 54.6% of all stolen funds.
That pushes the problem past simply smart-contract bugs and again towards custody, key administration, and infrastructure focus. For a market that usually sells decentralization as a remedy for fragility, a few of the largest losses nonetheless emerge from locations the place belief is concentrated.
However it doesn’t suggest each hacked challenge is doomed. The business has now entered a section the place survival does not depend upon whether or not a workforce can endure a hack, however whether or not it may well endure the six months that come subsequent.
The theft begins the disaster, however the slower injury decides whether or not the challenge nonetheless has a future as soon as the market strikes on.









