Crypto platforms lost more than $3.63 billion across 245 security incidents between January 2025 and July 2026, exposing a dangerous weakness in one of the industry’s most trusted safeguards: the independent security audit.
Billions Stolen Despite Extensive Security Reviews
A new CoinGecko report found that hackers stole more than $3.63 billion from cryptocurrency exchanges, decentralized finance protocols and other digital-asset platforms during the 19-month period.
The largest 10 attacks accounted for more than 72.5% of the total value stolen, showing how a small number of catastrophic security failures can overwhelm the industry’s broader defenses.
The most alarming finding involved the platforms’ security credentials.
Of the 245 affected platforms, 147 had completed an independent security audit before they were compromised. Those audited projects represented 60% of the affected platforms and 88.44% of all capital stolen.
That distinction matters. The data does not show that security audits are worthless. It shows that the largest losses increasingly originate from vulnerabilities outside the traditional scope of those audits.
Only around 11% of the attacks on audited platforms involved smart contract vulnerabilities that auditors had been asked to examine. Those incidents still caused approximately $396 million in losses, but infrastructure failures, private-key compromises, supply-chain attacks, malicious interfaces and unauthorized code changes created substantially more damage.
The biggest example was the February 2025 attack on Bybit, which resulted in the theft of approximately $1.46 billion in crypto assets. Elliptic attributed the attack to North Korea, an assessment later confirmed by the FBI.
According to Elliptic, malware was reportedly used to deceive the exchange into approving transactions that transferred the assets to the attackers. The stolen funds were quickly divided among numerous wallets and moved through decentralized exchanges, cross-chain bridges, centralized exchanges and cryptocurrency mixers.
CoinGecko identified KelpDAO as the second-largest affected platform, with reported losses of $292 million, followed by Drift Protocol at $285 million.
The Audit Badge Is Losing Its Power
For years, crypto platforms have used independent audits as a shorthand for safety.
Projects promote their audit providers on websites, fundraising materials and social media. Investors often treat the presence of a respected security firm as evidence that a protocol has been thoroughly examined.
That assumption has become increasingly dangerous.
A conventional smart contract audit typically reviews a defined body of code at a particular moment. It may discover programming errors, faulty permissions, economic vulnerabilities or exploitable contract logic. It cannot guarantee the security of every employee, device, software update, website interface, private key or third-party integration connected to the platform.
The result is a widening gap between audited code and real-world security.
A platform can have flawless smart contracts and still lose customer funds because an attacker compromises a developer’s computer. A transaction-signing interface can display one destination while approving another. An employee can be manipulated through social engineering. A software supplier can unknowingly deliver malicious code. A governance process can be captured. A private key can be stolen.
Each layer creates another potential entry point.
Infrastructure and supply-chain attacks caused more than $1.8 billion in losses during the period studied by CoinGecko. Decentralized applications also lost approximately $546 million through smart contract exploits, while centralized exchanges remained especially vulnerable to private-key compromises.
This changes how investors should interpret the phrase “audited platform.” An audit confirms that a specific review occurred. It does not establish that every component surrounding the reviewed code is secure.
The Financial Risks Extend Beyond the Stolen Assets
Exchanges Face a Growing Trust Discount
Centralized exchanges depend on confidence. Customers deposit assets because they believe the exchange can protect private keys, process withdrawals and absorb unexpected losses.
A major breach can trigger withdrawals, reduce trading activity and force the platform to use corporate reserves to reimburse customers. Even when users are made whole, the exchange may suffer higher insurance costs, greater regulatory scrutiny and lasting reputational damage.
Large platforms can sometimes survive these events because they possess substantial reserves, diversified revenue and access to outside capital. Smaller exchanges may have far less room for error.
Investors evaluating exchange tokens, crypto-related equities or private-market platforms should pay attention to the financial resources available after an attack. A protection fund is valuable only when its assets are liquid, accessible and large enough to cover a realistic loss scenario.
DeFi Investors Carry an Extra Layer of Risk
Decentralized finance introduces a different problem. Investors may simultaneously face smart contract risk, governance risk, oracle manipulation, unstable collateral and weaknesses in the platform’s front-end website.
Even if the underlying blockchain continues operating exactly as designed, users can still be directed toward a malicious transaction through a compromised interface.
The ability to move assets instantly makes the damage particularly difficult to contain. Once funds have been transferred, attackers can divide them among hundreds of wallets, exchange them for other tokens and move them across multiple blockchains within minutes.
Blockchain transparency can help investigators trace the money, but tracing does not guarantee recovery.
Security Spending Could Become a Competitive Advantage
The report strengthens the investment case for companies providing crypto custody, transaction monitoring, wallet screening, private-key management and real-time threat detection.
Traditional audit firms will remain important, but demand is likely to expand toward continuous monitoring and broader operational security.
The strongest platforms may eventually distinguish themselves through multiple layers of protection, including:
- Independent code audits
- Hardware-based transaction signing
- Strict private-key controls
- Real-time withdrawal monitoring
- Segregated customer assets
- Employee security training
- Third-party software testing
- Emergency transaction limits
- Transparent customer protection funds
Security spending can pressure margins in the short term. Over time, platforms that can demonstrate stronger controls may gain market share from competitors with weaker defenses.
The Audit Statistics Require Some Perspective
The finding that 88.44% of stolen funds came from audited platforms appears devastating for the security-audit industry. The concentration of losses adds important context.
The Bybit incident alone represented roughly 40% of the $3.63 billion total. Several other major losses were also concentrated among large, established platforms that were more likely to have paid for audits in the first place.
Audited platforms may control more capital, process more transactions and present more valuable targets. Their greater share of stolen funds does not prove that audits increase the probability of an attack.
The more useful conclusion is that audits address only one category of risk.
A comprehensive audit may reduce the likelihood of an exploitable smart contract flaw. It provides little defense when an attacker steals signing credentials, compromises a developer’s machine or manipulates a transaction interface.
Investors should continue valuing credible audits while demanding evidence of security across the rest of the organization.
Crypto Insurance Is Shrinking as Threats Grow
The industry’s financial safety net is also moving in the wrong direction.
CoinGecko found that active coverage offered by leading crypto insurance protocols fell 20.2%, declining from $163.2 million to $130.2 million. Cumulative payouts remained around $33 million.
Five of the nine on-chain insurance protocols examined had become inactive or shifted into other businesses by August 2026.
Even the remaining coverage can contain significant exclusions. Policies may protect against narrowly defined smart contract or infrastructure failures while excluding private-key theft, human error, market volatility or incidents outside the precise terms of the contract.
The mismatch is striking. Crypto platforms lost $3.63 billion during the period studied, while active on-chain insurance coverage stood at a small fraction of that amount.
That leaves users heavily dependent on the platform’s own balance sheet and willingness to provide reimbursement.
The Investor Takeaway
Crypto’s security problem has moved beyond faulty code.
The industry now faces organized and state-sponsored attackers capable of targeting employees, private keys, software suppliers and transaction interfaces. A one-time audit cannot cover that entire threat surface.
Investors should treat an audit as the beginning of their security review. The platforms best positioned to win long term will combine audited code with rigorous custody, continuous monitoring, strong operational controls and enough capital to protect customers when defenses fail.
The $3.63 billion already stolen is a warning about more than cybercrime. It reveals which crypto businesses have built durable financial infrastructure and which ones are still relying on a badge.

