Cryptocurrency platforms lost more than $3.63 billion to cyberattacks and stolen credentials between January 2025 and July 2026, with security audits failing to prevent many of the largest losses, according to a CoinGecko report.
The crypto market data provider said about 88% of the stolen funds came from platforms that had completed independent security audits. Roughly 60% of the affected platforms had also undergone such audits.
The findings raise questions about the effectiveness of relying on conventional security audits as a primary defense against attacks in an industry where control over private keys, administrative credentials and transaction-signing systems can determine whether billions of dollars remain secure.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
CoinGecko said many of the attacks exploited areas that standard security checks do not typically cover.
An audit generally assesses a defined set of systems, controls or code at a particular point in time. It does not necessarily demonstrate that an exchange or decentralized protocol can withstand sophisticated social engineering, compromised credentials, insider threats, supply-chain attacks, or the theft of cryptographic keys used to authorize transactions.
The scale of the losses illustrates the consequences.
Bybit suffered the largest reported loss, with about $1.4 billion stolen in a February 2025 attack. Blockchain intelligence firm Elliptic attributed the theft to North Korea.
KelpDAO was the second-most affected platform, with losses of about $292 million, followed by Drift Protocol at $285 million, according to CoinGecko.
The concentration of losses among a relatively small number of major incidents also reveals the asymmetric nature of cryptocurrency security. A platform can maintain extensive security controls for years and still face a single successful compromise capable of producing losses far larger than the cost of routine security testing.
The problem is particularly acute in systems where large amounts of assets can be moved rapidly once an attacker gains access to the mechanisms that authorize transactions.
The CoinGecko findings therefore point to a broader shift in how crypto security may need to be evaluated. Code reviews and independent audits remain necessary, particularly for decentralized protocols, but they address only part of the threats.
Operational security equally matters. Protecting signing keys, restricting administrative privileges, separating transaction approval from transaction execution, monitoring unusual transfers, and maintaining robust incident-response procedures can determine whether a compromised account becomes a limited security event or a nine-figure loss.
The findings also expose a potential weakness in how security is communicated to investors and users. The presence of an independent audit can create an impression of comprehensive protection even when the audit covers only specific components or vulnerabilities.
For crypto platforms holding or controlling large pools of customer assets, that gap has financial and reputational consequences. A successful exploit can drain funds directly, trigger withdrawals, disrupt trading and undermine confidence in the platform’s broader security architecture.
The industry is also facing increasingly sophisticated attackers. State-linked groups, organized cybercriminals and highly specialized hackers have strong financial incentives to target cryptocurrency because transactions can move large sums across borders without the same intermediaries used in traditional finance.
The $3.63 billion in reported losses through July 2026 is seen as an indication that security spending is not necessarily translating into proportionate protection. The fact that audited platforms accounted for the majority of stolen funds does not mean audits caused the breaches, but it does show that passing an audit should not be treated as evidence that a platform is immune to major attacks.
The situation has sustained a question for crypto investors and institutions: do platforms have layered defenses that remain effective after an attacker bypasses its formal controls?
As the value locked in exchanges, decentralized finance protocols, and other digital-asset infrastructure continues to grow, security is becoming less a matter of passing a technical inspection and more a question of whether platforms can continuously protect the mechanisms that ultimately control billions of dollars.



