Audited Protocols Lost 88% of Crypto Funds in Hacks Since 2025

CoinGecko's 2026 report shows $3.63B stolen across 245 incidents, with audited protocols accounting for 88% of losses. Supply chain attacks dominated.
Crypto protocols that had completed independent security audits accounted for 88.44% of all funds stolen since January 2025, according to CoinGecko's 2026 state of crypto security report. The study tracked 245 incidents and $3.63 billion in losses through July 2026. Independent auditors had cleared 147 of the breached platforms before attackers reached them.
Attackers exploited infrastructure and supply chain vulnerabilities for more than $1.8 billion, the largest single category in the report. Only 11% of exploits involved in-scope smart contract flaws, though those cases still drained $396 million. The damage came from external infrastructure and code deployed after the audit closed.
The losses concentrated heavily. The 10 largest attacks produced 72.5% of everything taken across the 19-month window. The $1.5 billion Bybit theft inflated the 2025 total. In 2026, Kelp DAO lost $292 million and Drift Protocol lost $285 million, ranking among the top three hacks since 2025.
On-chain insurance coverage shrank. Active policies fell 20.2% to $130.2 million, and five of nine insurance protocols went inactive or changed direction, the report said.
The incident rate accelerated. DefiLlama data shows 233 separate incidents so far in 2026, worth roughly $1.31 billion. The same stretch of 2025 saw 92 incidents and $2.37 billion in losses. Total losses fell about 45% while incident volume more than doubled. Average loss per incident dropped from $25.8 million to $5.6 million.
“Infrastructure and supply chain vulnerabilities have proven to be the most devastating for both CEXes and DEXes,” the report read.
The report argues that the issue is audit scope, not audit quality. Most audits focus on smart contract logic, while attackers are increasingly targeting deployment keys and governance parameters. Contract reviews remain narrow even as the value at risk shifts to areas traditional code reviews do not cover.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.