CoinGecko, the cryptocurrency market data provider, said that platforms have lost in excess of $3.63 billion to cyberattacks, and that a majority of the affected services had previously commissioned independent security audits. The disclosure underscores the continued vulnerability of parts of the crypto industry to hacking despite growing investment in formal security reviews.
Audit findings
According to CoinGecko’s analysis, more than 60% of platforms that experienced financial losses had undergone independent security checks. The firm’s findings suggest that an audit — while increasingly common — does not guarantee immunity from breaches or operational failures that can lead to significant thefts.
Limitations of audits
Security experts frequently note that audits are only one component of a broader defensive posture. Audits typically review code and architecture at a point in time; attackers can exploit undiscovered flaws, configuration errors, compromised keys, or weaknesses in operational practices. CoinGecko’s numbers illustrate that these gaps can translate into substantial financial damage even when formal reviews have taken place.
Implications for the industry
The data is likely to intensify scrutiny of how exchanges, custodians and decentralized platforms implement and maintain security measures beyond standalone audits, including continuous monitoring, incident response planning and controls over private keys and upgrade processes. For users and investors, the findings may reinforce calls for transparency around security practices and post-audit remediation.
The report adds to an ongoing industry conversation about the adequacy of current security standards as crypto ecosystems grow in size and complexity. CoinGecko’s analysis highlights that while audits are an important tool, they are not a substitute for comprehensive and continuously updated security programs.