Cryptocurrency hacks are becoming rarer. Grayscale's latest research pegs 2026 cybersecurity losses at roughly $1.7 billion, the smallest annual haul for thieves in nine years. That sounds large until you do the math: it represents just 0.1% of the total crypto market cap. For every thousand dollars locked in crypto, about a dollar walked away.
The actual numbers behind the Coldcard blow
The year's biggest self-custody incident came from a hardware wallet vulnerability. Coldcard, made by Coinkite, had a flaw in its random number generator that exposed somewhere between 1,367 and 1,400 Bitcoin. At current prices, that's roughly $88 to $90 million gone. It ranked third among all crypto exploits in 2026.
Here's what matters for the bigger picture: Bitcoin's blockchain itself never broke. The protocol hummed along untouched. Every coin lost sat in user-controlled wallets, not in any fundamental weakness of the network. Grayscale treated the Coldcard incident as an isolated mishap rather than a sign the whole system was cracking.
Why theft keeps getting harder
The decline tracks concrete changes in how the industry operates. Code audits shifted from nice-to-have to standard practice. Bug bounty programs now pay hackers to find holes before criminals do. These aren't revolutionary ideas, but they work.
The bigger shift is happening in custody itself. Institutional-grade solutions, especially through Bitcoin ETPs and ETFs, now bundle insurance coverage with multisignature security and asset segregation. That's the kind of setup that moves money away from self-custody risk. Grayscale obviously has skin in the game here, managing billions in crypto investment products, so take the framing with appropriate skepticism. Still, the trend is real: institutions increasingly prefer insured custody over holding keys themselves.

