Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

CoinGecko's 2026 security report finds the industry's biggest losses now come from infrastructure and supply-chain breaches that audits were never built to catch

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 27, 2026
in Security & Hacks
0 0
Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

Photo by cottonbro studio from Pexels/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Crypto platforms that had already passed independent security audits still accounted for 88.44% of the $3.63 billion stolen in hacks between January 2025 and July 2026, according to CoinGecko’s newly published State of Crypto Security Report.

The reason is not that the audits failed at their job. It is that the attacks moved somewhere audits don’t look. Only 11% of incidents in the period involved a flaw inside audited smart-contract code, worth $396 million. The remaining losses, over $1.8 billion, came through infrastructure and supply-chain compromises: stolen private keys, hijacked front-ends, and breached admin systems that a code audit never inspects.

The same gap between a claimed fix and the real exposure shows up elsewhere too. Three Cosmos chains halted this month after an exploit reused an already-remediated vulnerability, months after the patch was supposed to have closed it.

Source: Coingecko
Source: Coingecko

Bybit’s hack fits the pattern exactly

Bybit’s $1.46 billion loss in February 2025, the single largest incident in the dataset, is a direct example. The exchange has said the breach traced to malicious code injected into the interface of Safe Wallet, a third-party wallet service its team used to sign transactions, and not to any flaw in Bybit’s own audited systems, according to Bybit’s own incident timeline.

Security researchers linked the intrusion to North Korea’s Lazarus Group. The FBI’s Internet Crime Complaint Center attributed the theft to North Korea in a public advisory days later.

The same trick keeps resurfacing at smaller scale. A signing bug in Ledger’s Ethereum app, patched this month, let a malicious application swap in a different transaction while the original one was still on screen for approval, the same disconnect between what a user sees and what they actually sign.

Insurance is retreating just as the risk shifts

Active coverage from on-chain insurance protocols fell 20.2%, from $163.2 million to $130.2 million, the report found. Five of the nine protocols it tracked had gone inactive or pivoted away from insurance by August 2026. Cumulative payouts across the sector have stayed flat at $33 million.

Exchanges are filling that gap themselves rather than waiting on a payout. Bybit did not rely on insurance after its hack. It closed the shortfall within 72 hours through bridge loans and partner deposits from firms including Galaxy Digital and Wintermute, then recovered a further $42.89 million by working with Tether and Circle to freeze stolen funds.

Not every platform has that cushion. BounceBit shut down its blockchain entirely after an exploit drained a quarter of BB’s circulating supply, migrating holders onto a pre-attack snapshot that left the stolen tokens uncompensated.

That leaves a widening gap between where the money is actually being stolen and where the industry’s defenses are pointed. As long as audits keep covering code that isn’t where losses are concentrated, and outside insurers keep retreating, the burden of covering the next large exploit looks likely to fall on exchanges’ own balance sheets, the same way it did for Bybit.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch
Security & Hacks

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

by Saravana Kumar Mahendran
August 27, 2026

Core Lightning has confirmed real security flaws among a wave of AI-generated vulnerability reports it received over the past ten...

Read moreDetails
Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

August 20, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

August 18, 2026
Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

August 11, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026
RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

August 7, 2026

Recommended

  • All
  • Crypto News Today
UK Writes Bank of England's Stablecoin Softening Into Law With New Innovation Duty

UK Writes Bank of England’s Stablecoin Softening Into Law With New Innovation Duty

August 27, 2026
Bitfinex Securities Raises Record $50M for Nickel-Backed ALKN Tokens

Bitfinex Securities Raises Record $50M for Nickel-Backed ALKN Tokens

August 27, 2026
Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

Moonwell Hit by Third Exploit in Nine Months After Attacker Drains Millions in cbBTC

August 27, 2026
Pump.fun Leads Hyperliquid in Daily and Monthly Revenue. Hyperliquid's Own Fee Rules Are Why

Pump.fun Leads Hyperliquid in Daily and Monthly Revenue. Hyperliquid’s Own Fee Rules Are Why

August 27, 2026
CZ Says Hong Kong and Web3 Are a Powerful Combination as RWA Gains Momentum

CZ Says Hong Kong and Web3 Are a Powerful Combination as RWA Gains Momentum

August 27, 2026
Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

August 27, 2026

Bithumb Wins First Lawsuit Over 194 Million Won Bitcoin Overpayment

August 27, 2026
CFTC Warns of Rising Crypto ATM Fraud as Losses Hit $388 Million in 2025

CFTC Warns of Rising Crypto ATM Fraud as Losses Hit $388 Million in 2025

August 27, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows
  • UK Writes Bank of England’s Stablecoin Softening Into Law With New Innovation Duty
  • Bitfinex Securities Raises Record $50M for Nickel-Backed ALKN Tokens

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.