Crypto Platforms Lose $3.63 Billion to Hacks Despite Security Audits: CoinGecko Report Reveals Major Gaps
September 8, 2026
A CoinGecko report, cited by CNBC, shows cryptocurrency platforms lost more than $3.63 billion to hacks and cyberattacks from January 2025 through July 2026, despite many platforms undergoing security audits.
Even with independent security audits, many attacks hit areas not typically covered by standard checks, revealing gaps in audit scope and practice.
Audit reports often fail to capture the full spectrum of risk, including external infrastructure, unaudited code updates, and governance-related exploits.
Only about 11% of incidents involved in-scope smart contract flaws, yet those flaws accounted for roughly $396 million in losses.
Approximately 88% of the stolen funds and about 60% of affected platforms came from incidents involving entities that had completed independent security audits.
Responses from implicated platforms (Bybit, KelpDao, Drift Protocol) were not provided at the time CNBC pressed for comment.
The piece situates crypto security within a broader cyber context, noting banks’ advantages in detecting and preventing crypto payment scams and the evolving fraud landscape in crypto ecosystems.
Notable incidents cited include the February 2025 Bybit theft of $1.4 billion, the KelpDAO loss of $292 million, the Drift Protocol loss of $285 million, and a later $320 million Liquid Network hack described as a white-hat action.
There is a concentration of losses around a few major platforms, and audit coverage did not prevent high-value attacks.
KelpDao was the second-largest victim with $292 million, followed by Drift Protocol at $285 million, per the CoinGecko report.
Bybit emerged as the most affected exchange, suffering a $1.4 billion heist in February 2025 attributed to North Korea in analysis by Elliptic.
The report cautions that security breaches remain a persistent threat even for audited platforms, highlighting gaps between audits and real-world risk.
Summary based on 2 sources

