Crypto platforms lost more than $3.63 billion to cyberattacks and stolen credentials between January 2025 and July 2026, according to CoinGecko's State of Crypto Security Report, dated August 27 and picked up this month by CNBC and PYMNTS. The number that should reframe how the industry reads audit reports: roughly 88% of the stolen funds — and about 60% of the affected platforms — had completed independent security audits beforehand.
The report counts 245 documented incidents since early 2025, of which 147 involved protocols that had been audited before being compromised. Those vetted entities represented 88.44% of total capital drained over the period.
What Audits Don't Cover
The report's central finding is not that audits are useless. It is that attacks mostly land outside their scope. Per CoinGecko, most exploits on audited systems targeted external infrastructure, unaudited code updates, or systemic features manipulated through governance attacks. Only about 11% of the incidents involved in-scope smart contract flaws — though those still resulted in $396 million in losses.
That breakdown matches what this publication has documented all year in incident after incident: the Coldcard wallet compromise, where a firmware change replaced hardware entropy with a predictable fallback; the XRPH Wallet keyspace collapse, where 16 effective characters of entropy drained 4,000 users; and the Bybit heist itself, which began with a compromised signing workflow, not a contract bug. None of those failure points sit inside the perimeter a smart contract audit inspects.
The Leaderboard Nobody Wants to Top
Bybit was the most affected platform, primarily through the $1.4 billion February 2025 theft that blockchain-analytics firm Elliptic attributed to North Korea-linked actors. Kelp DAO followed at $292 million, then Drift Protocol at $285 million. All three either declined or did not respond to CNBC's requests for comment.
Notably, the report's cutoff in July means its totals do not include two of the largest incidents of the past month: the ~$320 million Liquid Network federation drain in early September and the Coldcard losses, which have surpassed $115 million. The true current figure is meaningfully higher than $3.63 billion.
The Uncomfortable Conclusion
"The prevalence of security breaches remains a persistent threat, even for vetted platforms," the report concludes. The uncomfortable reading is that an audit stamp functions as a point-in-time statement about specific code, while attackers operate continuously across infrastructure, personnel and process — the exact surfaces where the year's biggest losses actually occurred.
For readers tracking platform risk, the practical takeaway is to treat audit coverage as one signal among several: what is actually in scope, when the engagement was performed relative to the latest deploy, and how the operator secures keys, signers and operational workflows — the layers where 89% of the money walked out the door. Continuous verification regimes and independently maintained trust scores exist precisely because static reports age badly; TrustGrade's registry is one attempt to make that risk legible over time.