# Crypto Platforms Under Security Alarm: 3.63 Billion $ Lost in Cyberattacks Despite widespread security audits, crypto platforms remain vulnerable to cyberattacks. According to CoinGecko, **more than 3.63 billion $ was lost through attacks and compromised credentials between January 2025 and July 2026.** Notably, many attacked platforms had previously undergone independent security audits. ## Why Are Security Audits Falling Short? CoinGecko’s August 27 report found that approximately **88% of stolen funds** and **60% of attacked platforms** had undergone independent security audits. Attackers often target vulnerabilities outside standard audit scopes. Passing an audit does not guarantee protection against real-time attacks or complex vulnerabilities. Beyond smart contracts, access permissions, private keys, employee accounts are also major targets. ## Bybit Suffered the Largest Loss **Bybit** is identified as the largest attack during the period. In February 2025, approximately **1.4 billion $** in assets were stolen. Elliptic assessed that the attack was linked to North Korean actors. **KelpDAO**, with a loss of **292 million $**, ranked second, followed by **Drift Protocol**, with a loss of **285 million $**. None of the three platforms had immediately responded to CNBC’s requests for comment. ## Passing an Audit Is Not a Security Guarantee Security audits remain important for DeFi and smart contracts. Recent attacks show a gap between audit scope and real-world attack methods. With billions held in decentralized or semi-centralized systems, relying solely on code audits creates serious risks. **The 3.63 billion $ loss shows that crypto security cannot be built solely around “passing an audit.”** Going forward, platforms will need to focus not only on smart contract vulnerabilities but also on **private key management, access controls, employee accounts, and incident response mechanisms.** $BTC $XRP
