Cybersecurity & Exchange Risk

CoinGecko Report Highlights Billions Lost in Crypto Hacks Despite Prior Audits

According to CNBC reporting on a CoinGecko study, cryptocurrency platforms lost more than $3.63 billion to cyberattacks between January 2025 and July 2026, with a majority of affected platforms having completed independent security audits, though these claims are not officially confirmed.

Abstract digital cyber security visualization representing crypto audit challenges
Image: CNBC Top News

Overview of Reported Cyber Losses

Recent investigative reporting published by CNBC highlights significant financial losses across the digital asset sector resulting from various cyber intrusions and compromised passkeys. According to market data cited in the coverage, digital asset service providers experienced massive financial outflows over an extended period spanning from the beginning of 2025 through the middle of 2026. These occurrences underscore an ongoing challenge within the decentralized finance and centralized exchange ecosystems regarding the protection of user deposits and treasury assets against persistent malicious actors.

The reported figures indicate that billions of dollars have been extracted from the broader cryptocurrency market through sophisticated exploitation vectors. Analysts examining the data point out that the sheer magnitude of these incidents reveals structural weaknesses in how digital platforms defend their digital infrastructure. While industry participants have continuously increased expenditure on defensive measures, malicious actors continue to discover and exploit novel vulnerabilities faster than traditional defensive frameworks can adapt to them.

The Limitations of Independent Audits

A particularly striking element of the published material involves the prevalence of security checks among the compromised entities. Statistical findings referenced in the CNBC coverage reveal that approximately sixty percent of the platforms that suffered financial breaches had successfully completed independent security evaluations prior to the incidents. Furthermore, an even higher proportion of the total stolen capital was associated with organizations that held these credentialed compliance markers, calling into question the traditional assurance models relied upon by retail and institutional participants.

Industry experts note that standard code reviews and external assessments typically focus on specific smart contract logic or architectural components while missing systemic risks outside their prescribed scopes. Many of the successful intrusions targeted operational environments, administrative credentials, or integration layers that standard evaluations do not comprehensively investigate. This discrepancy explains why holding formal review certificates does not guarantee absolute immunity against sophisticated, multi-stage cyber campaigns conducted by determined threat groups.

Specific Platforms and Notable Incidents

The published coverage explicitly identifies several prominent entities that experienced substantial financial damage during the referenced timeline. Among these, the trading platform Bybit was cited as suffering the largest single disruption, stemming from a massive February 2025 security breach that attribution analysts linked to state-sponsored actors from North Korea. Such high-profile heists demonstrate that even heavily capitalized entities with extensive operational experience remain vulnerable to advanced persistent threat techniques targeting their reserve management systems.

Other notable organizations mentioned in the reporting include KelpDao and Drift Protocol, which also recorded significant financial losses from unauthorized outflows during the evaluated period. According to the published details, these platforms sustained hundreds of millions of dollars in damages, prompting widespread discussion across market forums regarding risk management and emergency response protocols. Representatives for the named organizations did not immediately provide public statements or responses when contacted by the original publisher for comment regarding the specific allegations.

Market Implications and Investor Awareness

The revelation that a majority of compromised protocols possessed up-to-date compliance audits creates an urgent need for re-evaluating risk assessment methodologies across the entire digital asset ecosystem. Investors, liquidity providers, and institutional allocators can no longer rely solely on compliance badges or marketing claims of rigorous security testing when evaluating the safety of a platform. Developing a more holistic due diligence framework that accounts for operational security, administrative key management, and real-time monitoring has become an absolute necessity for market participants.

Furthermore, regulatory bodies and advisory institutions are expected to scrutinize how platforms communicate their security posture to the public, potentially driving higher standards for transparency and accountability. As cyber criminals continue to refine their methodologies and target peripheral infrastructure, the threshold for establishing institutional trust within the cryptocurrency sector is rising significantly. Market participants must adopt heightened vigilance, recognizing that technical compliance is only a baseline rather than an absolute shield against sophisticated financial crime.

Conclusion and Verification Status

In summary, the risk intelligence analysis concludes that while independent security audits remain a valuable component of digital asset engineering, they are demonstrably insufficient to prevent all major breaches. The affected entity and user group encompass multiple decentralized and centralized cryptocurrency platforms alongside their global customer bases, which have collectively faced billions in reported losses between January 2025 and July 2026. What changes now is that industry stakeholders must transition away from audit-centric complacency toward comprehensive operational security architectures, though readers should note that these statistics are reported by media sources and remain not officially confirmed.

The next action for all participants is to conduct thorough independent risk reviews of every protocol they utilize, ensuring that no single security credential is treated as a guarantee of safety. Because the core findings derive from third-party media investigations rather than official statements from the involved protocols, users must treat these reported metrics as unverified estimates while continuing to monitor for formal disclosures. Cexvia will maintain its current evaluation score while tracking any subsequent regulatory filings or official incident reports.

Cexvia conclusion

Analytical Conclusion and Verification Status

Cexvia risk intelligence has evaluated media coverage regarding recent crypto platform vulnerabilities and identified that over 60 percent of breached platforms previously completed independent security audits, a finding that is not officially confirmed.

Risk meaning
The reported statistics demonstrate that standard security audits alone cannot fully protect digital asset platforms from sophisticated threats, particularly when vulnerabilities exist outside traditional review scopes.
User action
Digital asset users should diversify their platform usage, maintain personal operational security standards, and avoid assuming that a platform is completely safe solely because it displays audit credentials.
Bybit