Despite the widespread adoption of security audits across the cryptocurrency industry, platforms remain vulnerable to cyberattacks. According to CoinGecko data, more than $3.63 billion in funds were lost between January 2025 and July 2026 due to attacks on crypto platforms and compromised credentials.
The most striking point in the report is that a significant portion of the platforms that were attacked had previously undergone independent security audits.
Why Are Security Audits Falling Short?
According to CoinGecko’s report dated August 27, approximately 88% of the stolen funds and around 60% of the attacked platforms had undergone independent security audits.
This suggests that traditional security audits alone may not be sufficient.
The report notes that attackers often target vulnerabilities that fall outside the scope of standard audit processes. In other words, having a platform audited does not mean it is completely protected against real-time attacks or more sophisticated security vulnerabilities.
In the crypto sector, access permissions, private keys, employee accounts, and operational processes are also among the major targets of attacks, alongside smart contract security.
Bybit Suffered the Largest Loss
The largest attack during the period covered by the report was the Bybit incident.
In February 2025, approximately $1.4 billion worth of assets were stolen. Blockchain analytics firm Elliptic assessed that the attack was linked to North Korean actors.
KelpDAO ranked second with losses of $292 million, while Drift Protocol ranked third with losses of $285 million.
The report stated that all three platforms had not immediately responded to CNBC’s requests for comment regarding the assessment.
Passing an Audit Is Not a Guarantee of Security
Security audits are considered an important control mechanism in the crypto market, particularly for DeFi protocols and smart contracts. However, recent attacks show that there can be a significant gap between the scope of an audit and the attack methods used in the real world.
Considering that billions of dollars in assets are held across decentralized or semi-centralized systems, relying solely on code audits as a security strategy carries significant risks.
The $3.63 billion in losses demonstrates that security in the crypto industry cannot be built solely around “passing an audit.”
Going forward, platforms will need to focus not only on smart contract vulnerabilities but also more heavily on private key management, access controls, employee accounts, and incident-response mechanisms.
