Home / News / Breaking / Crypto Hacks Drain $3.63B — But the Biggest Security Red Flag Is What Happened After Audits
Breaking 3 min read

Crypto Hacks Drain $3.63B — But the Biggest Security Red Flag Is What Happened After Audits

Key Takeaways

  • Crypto platforms lost $3.63 billion across 245 security incidents between January 2025 and July 2026.
  • Around 60% of compromised platforms had undergone independent audits, yet they accounted for 88.44% of total losses.
  • Just 11% of incidents involving audited platforms exploited vulnerabilities within the conventional audit scope.

Crypto’s security problem is getting more expensive, and traditional smart contract audits are proving insufficient against an increasingly diverse range of attacks.

Crypto platforms lost $3.63 billion across 245 documented security incidents between January 2025 and July 2026, according to CoinGecko’s 2026 State of Crypto Security report.

Losses were heavily concentrated. The 10 largest attacks accounted for more than 72.5% of all stolen funds, while infrastructure and supply-chain compromises alone caused more than $1.8 billion in losses.

More strikingly, 147 of the 245 compromised platforms had undergone independent security audits. Those audited projects were responsible for 88.44% of the total capital stolen.

However, the numbers point more to ineffective audits than to attackers increasingly targeting weaknesses they were never designed to examine.

Why Audits Failed to Prevent Billions in Crypto Losses

CoinGecko found that only around 11% of incidents affecting audited platforms involved vulnerabilities that were actually within the scope of conventional smart contract audits.

Those in-scope vulnerabilities still resulted in approximately $396 million in losses, but most attacks exploited other weaknesses.

Attackers increasingly targeted external infrastructure, unaudited code changes, governance mechanisms, and operational systems.

Crypto platform losses
Crypto platforms have lost over $3.63B since the start of 2025. | Credit: CoinGecko

The vulnerabilities also differed significantly between centralized and decentralized platforms.

Private-key compromises remained a major weakness for centralized exchanges, while decentralized applications suffered roughly $546 million in losses from smart contract exploits.

The findings suggest that an audit certificate cannot be treated as a blanket security guarantee. An audit may verify a particular version of smart contract code without covering the infrastructure and human processes surrounding it.

Crypto Insurance Coverage Falls 20% Despite Rising Hacks

At the same time, the industry’s financial safety net is shrinking.

Active coverage across major on-chain insurance protocols dropped 20.2%, falling from $163.2 million to $130.2 million. Cumulative payouts, meanwhile, remained at approximately $33 million.

Active coverage by crypto insurance platforms
Active coverage by crypto insurance platforms has fallen by 20%. | Credit: CoinGecko

CoinGecko attributed the weakness partly to crypto’s elevated risk profile, which can make providing insurance capital less attractive while simultaneously pushing premiums higher.

Coverage can also be highly restrictive. Some policies protect against narrowly defined smart contract or infrastructure exploits but exclude losses caused by private-key compromises, human errors or other operational failures.

Those limitations have hindered adoption. By August 2026, five of the nine on-chain insurance protocols examined by CoinGecko had either become inactive or pivoted toward other businesses.

Exchanges Build Protection Funds as Attackers Change Tactics

With decentralized insurance struggling to scale, centralized exchanges are increasingly turning to their own protection funds to compensate customers following security breaches.

The shift highlights a larger change in the industry’s approach to security.

Smart contract audits remain useful for finding code vulnerabilities, but CoinGecko’s data indicates that some of the most damaging attacks now originate outside that traditional perimeter.

CEXs protection funds
Centralized exchanges launch protection funds to guarantee user coverage in the event of an exploit. | Credit: CoinGecko

Supply chain compromises, stolen credentials, social engineering, and private key attacks can circumvent even thoroughly audited code.

For crypto platforms, that means security increasingly requires multiple overlapping defenses, from code audits and key-management systems to infrastructure monitoring and emergency reserves.

The $3.63 billion stolen since 2025 provides a stark reminder: passing an audit may reduce one category of risk, but it does not mean a crypto platform is secure.

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%