Audited and hacked: crypto platforms lost over $3.63 billion despite security checks
The security audit has become the digital asset sector's primary credential of institutional trust. Against that backdrop, CoinGecko reports that more than 60% of cryptocurrency platforms that lost money to cyberattacks had…
Key takeaways
- CoinGecko reports that more than 60% of cryptocurrency platforms that lost money to cyberattacks had already completed independent security reviews.
- Total losses across these audited platforms exceeded $3.63 billion.
- A security audit is a point-in-time assessment that measures a codebase as it stands when the review closes and cannot capture exposure introduced by later code updates.
- The $3.63 billion in losses is distributed across the sector rather than concentrated in a single event.
- The findings suggest risk frameworks that rely on audits as a primary screen for crypto platform selection are mispriced and understate residual risk.
The security audit has become the digital asset sector's primary credential of institutional trust. Against that backdrop, CoinGecko reports that more than 60% of cryptocurrency platforms that lost money to cyberattacks had already completed independent security reviews, with total losses exceeding $3.63 billion.
The finding reframes how the sector prices its own risk. The audit has functioned, across the broader cycle, as the closest thing digital asset infrastructure has to a credit-quality marker. Platforms publish completed reviews. Cross-border capital allocators and institutional counterparties treat those disclosures as a qualifying screen before committing funds. CoinGecko's data does not support that confidence.
The statistic is the structural problem in plain sight. A security audit is not a guarantee of continued security. Sector-wide, the credential has been treated as roughly equivalent to one. The gap between what an audit certifies and what the market has expected it to prevent is now documented in loss data.
The audit gap
A completed audit is a point-in-time assessment. It measures a codebase as it stands on the day the review closes. That snapshot diverges from reality the moment code is updated, and the gap that opens is exposure the audit cannot capture. CoinGecko identifies the outcome without isolating the mechanism.
The read-through for the broader sector is direct. If a third-party security review does not reliably reduce attack exposure, the risk frameworks applied to crypto platform selection are mispriced. Capital allocation and custody decisions that lean on the audit as a primary screen are not fully accounting for residual risk.
On balance, the $3.63 billion in losses CoinGecko has documented is distributed across the sector, not concentrated in a single event. The majority of the platforms that contributed to that total had passed an independent security review.
Related reading
Source · 來源