Sign up
Subscribe
Home / news / Crypto Platforms Lost $3.6 Billion to Hacks in 18 Months, Even When Security Audits Were in Place
news

Crypto Platforms Lost $3.6 Billion to Hacks in 18 Months, Even When Security Audits Were in Place

Crypto Platforms Lost $3.6 Billion to Hacks in 18 Months, Even When Security Audits Were in Place

Crypto platforms have lost more than $3.6 billion to hacks and theft in the last 18 months, and the uncomfortable part for operators is that most of the damage hit firms that had already done independent security audits. For PSPs and acquiring teams looking at high-risk crypto exposure, the message is blunt: an audit checkbox does not map neatly to actual operational risk.

  1. According to CoinGecko findings cited by CNBC on Tuesday, most of the incidents in the January 2025 to July 2026 window were driven by cyberattacks and stolen passkeys, not by some exotic failure mode that auditors could easily spot after the fact. Roughly 88% of the stolen funds and about 60% of the affected platforms had completed independent security audits.
  2. The problem, as the report puts it, is that attacks often land in places audits do not usually cover. CoinGecko said that out of 245 documented incidents since early 2025, 147 involved protocols that had been audited before being compromised, and those vetted entities accounted for 88.44% of the total capital drained over the last 19 months.
  3. The biggest single loss in the period was the $1.4 billion theft from Bybit in February 2025. Behind it were KelpDao, which lost $292 million, and Drift Protocol, which lost $285 million.
  4. Those two were later overtaken by the $320 million hack on the Liquid Network blockchain, described as a supposed “white hat” attack and reported on Sunday, Sept. 6. The report’s cutoff also came before another high-profile breach, where crypto wallets used by a Coldcard customer led to the theft of at least $115 million in bitcoin.
  5. CoinGecko said audit reports often miss external infrastructure, unaudited code updates, and systemic features that can be manipulated through governance attacks. Only about 11.0% of the incidents involved in-scope smart contract flaws, but those still caused $396.0 million in losses.

For high-risk payment providers, this is the useful part: if a crypto merchant says it has been audited, that tells you something, but not enough. The loss profile here is being driven by attack surfaces around the code rather than only inside it, which is exactly where card, bank, and PSP controls tend to meet messy reality.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!