Crypto platforms lost more than $3.63 billion to cyberattacks despite most having independent audits, CoinGecko says

Cryptocurrency platforms have suffered over $3.63 billion in losses from cyberattacks, and more than 60% of those hit had undergone independent security audits, according to an analysis by CoinGecko.

CoinGecko, the cryptocurrency market data provider, said that platforms have lost in excess of $3.63 billion to cyberattacks, and that a majority of the affected services had previously commissioned independent security audits. The disclosure underscores the continued vulnerability of parts of the crypto industry to hacking despite growing investment in formal security reviews.

Audit findings

According to CoinGecko’s analysis, more than 60% of platforms that experienced financial losses had undergone independent security checks. The firm’s findings suggest that an audit — while increasingly common — does not guarantee immunity from breaches or operational failures that can lead to significant thefts.

Limitations of audits

Security experts frequently note that audits are only one component of a broader defensive posture. Audits typically review code and architecture at a point in time; attackers can exploit undiscovered flaws, configuration errors, compromised keys, or weaknesses in operational practices. CoinGecko’s numbers illustrate that these gaps can translate into substantial financial damage even when formal reviews have taken place.

Implications for the industry

The data is likely to intensify scrutiny of how exchanges, custodians and decentralized platforms implement and maintain security measures beyond standalone audits, including continuous monitoring, incident response planning and controls over private keys and upgrade processes. For users and investors, the findings may reinforce calls for transparency around security practices and post-audit remediation.

The report adds to an ongoing industry conversation about the adequacy of current security standards as crypto ecosystems grow in size and complexity. CoinGecko’s analysis highlights that while audits are an important tool, they are not a substitute for comprehensive and continuously updated security programs.