Independent security audits are supposed to signal that a cryptocurrency platform is safe. But a new report suggests they have done little to prevent a wave of costly hacks across the industry.
Between January 2025 and July 2026, crypto platforms lost more than $3.63 billion to a mix of cyberattacks and stolen passkeys, according to a report from CoinGecko, a crypto market data site, dated Aug. 27.
The report found that roughly 88% of the stolen funds — and about 60% of the platforms affected — had completed independent security audits before the incidents. That points to a gap between what audits typically cover and the vulnerabilities attackers actually exploit, CoinGecko said, noting that most attacks targeted areas not covered by standard checks.
Biggest victims
The largest single loss cited in the report was the $1.4 billion heist at Bybit in February 2025, an attack that blockchain analytics firm Elliptic attributed to North Korea. Bybit was the most affected platform by total losses, according to CoinGecko.
Next on the list was KelpDao, which lost $292 million, followed by Drift Protocol, which lost $285 million.
Bybit, KelpDao, and Drift Protocol did not immediately respond to CNBC’s request for comment.
The report underscores a persistent problem for crypto investors and exchanges: even platforms that invest in audits and security reviews remain vulnerable to sophisticated attacks, particularly those targeting operational weaknesses or key management rather than code flaws that audits are designed to catch.
For the broader market, the losses highlight the ongoing risk of holding assets on centralized platforms, where a single breach can wipe out billions in customer funds.
Source: www.cnbc.com — https://www.cnbc.com/2026/09/08/crypto-platforms-lost-billions-to-cyberattacks-many-even-after-audits.html
This article is for informational purposes only and does not constitute financial, investment, tax, or legal advice. Do your own research and consult a licensed professional before making financial decisions.



