Crypto platforms that had already passed independent security audits still accounted for 88.44% of the $3.63 billion stolen in hacks between January 2025 and July 2026, according to CoinGecko’s newly published State of Crypto Security Report.
The reason is not that the audits failed at their job. It is that the attacks moved somewhere audits don’t look. Only 11% of incidents in the period involved a flaw inside audited smart-contract code, worth $396 million. The remaining losses, over $1.8 billion, came through infrastructure and supply-chain compromises: stolen private keys, hijacked front-ends, and breached admin systems that a code audit never inspects.
The same gap between a claimed fix and the real exposure shows up elsewhere too. Three Cosmos chains halted this month after an exploit reused an already-remediated vulnerability, months after the patch was supposed to have closed it.

Bybit’s hack fits the pattern exactly
Bybit’s $1.46 billion loss in February 2025, the single largest incident in the dataset, is a direct example. The exchange has said the breach traced to malicious code injected into the interface of Safe Wallet, a third-party wallet service its team used to sign transactions, and not to any flaw in Bybit’s own audited systems, according to Bybit’s own incident timeline.
Security researchers linked the intrusion to North Korea’s Lazarus Group. The FBI’s Internet Crime Complaint Center attributed the theft to North Korea in a public advisory days later.
The same trick keeps resurfacing at smaller scale. A signing bug in Ledger’s Ethereum app, patched this month, let a malicious application swap in a different transaction while the original one was still on screen for approval, the same disconnect between what a user sees and what they actually sign.
Insurance is retreating just as the risk shifts
Active coverage from on-chain insurance protocols fell 20.2%, from $163.2 million to $130.2 million, the report found. Five of the nine protocols it tracked had gone inactive or pivoted away from insurance by August 2026. Cumulative payouts across the sector have stayed flat at $33 million.
Exchanges are filling that gap themselves rather than waiting on a payout. Bybit did not rely on insurance after its hack. It closed the shortfall within 72 hours through bridge loans and partner deposits from firms including Galaxy Digital and Wintermute, then recovered a further $42.89 million by working with Tether and Circle to freeze stolen funds.
Not every platform has that cushion. BounceBit shut down its blockchain entirely after an exploit drained a quarter of BB’s circulating supply, migrating holders onto a pre-attack snapshot that left the stolen tokens uncompensated.
That leaves a widening gap between where the money is actually being stolen and where the industry’s defenses are pointed. As long as audits keep covering code that isn’t where losses are concentrated, and outside insurers keep retreating, the burden of covering the next large exploit looks likely to fall on exchanges’ own balance sheets, the same way it did for Bybit.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.















