Between January 2025 and July 2026, cryptocurrency platforms have suffered losses exceeding $3.63 billion due to various cyberattacks and stolen passkeys, according to a CoinGecko report dated August 27, 2026 [1]. The report highlights that traditional security reviews and independent audits have not been sufficient to prevent these breaches, with approximately 88% of the stolen funds and about 60% of the affected platforms having completed such audits prior to the attacks [1]. Most of the attacks targeted vulnerabilities that are not typically covered by standard security checks [1].
Bybit was identified as the most affected platform, experiencing a $1.4 billion heist in February 2025, which Elliptic attributed to North Korea [1]. KelpDao and Drift Protocol were also significantly impacted, losing $292 million and $285 million respectively [1]. Despite the scale of these losses, Bybit, KelpDao, and Drift Protocol did not immediately respond to CNBC's request for comment [1].
The findings underscore the limitations of current security practices within the crypto industry and suggest that even platforms with completed independent audits remain vulnerable to sophisticated cyber threats [1]. The report did not provide forward-looking statements or analyst opinions regarding potential improvements or future risks [1].
CONCLUSION
The CoinGecko report reveals that cryptocurrency platforms remain highly vulnerable to cyberattacks, even after undergoing independent security audits. With losses surpassing $3.63 billion and major platforms like Bybit, KelpDao, and Drift Protocol among the most affected, the market faces significant security challenges. This event signals a high-impact risk for the crypto sector, emphasizing the need for more robust and comprehensive security measures.
