CoinGecko Report Questions Security Audit Limits After $3.63 Billion in Losses

CoinGecko Report Questions Security Audit Limits After $3.63 Billion in Losses

By: WEEX|2026/09/08 09:52:07

WEEX View

  1. The main follow-up issue is where the losses actually came from. The report says only about 11% of incidents were directly tied to flaws in audited smart contracts, suggesting investors and venues may focus more on operational security, key management, and access controls than on audits alone.
  2. Loss concentration also matters. The top 10 attacks accounted for 72.5% of total losses, so future security assessments may hinge on whether large centralized failures continue to dominate aggregate damage.
  3. The reported 20.2% drop in crypto insurance coverage and the retreat of several on-chain insurance protocols point to a second-order risk: reduced protection after attacks could make recovery and confidence harder for affected platforms.

Crypto platforms lost $3.63 billion to cyberattacks between January 2025 and July 2026, according to a CoinGecko report, which said roughly 60% of the affected platforms had completed independent security audits before the attacks.

CoinGecko said there were 245 attacks during the period, and that the top 10 incidents made up 72.5% of total losses. Among platforms that had already undergone audits, 147 protocols were later attacked, representing 88.44% of total losses in the dataset.

The report draws a distinction between audited code and broader security failures. Only about 11% of incidents were directly caused by flaws in audited smart contracts, with those losses totaling $396 million. That leaves most losses linked to other attack vectors not prevented by a standard code review.

Bybit was identified as the single largest case in the period after suffering a $1.4 billion theft in February 2025. CoinGecko also said centralized exchanges showed private key theft as a major weakness, while decentralized applications posted heavy losses from smart contract flaws.

The report also pointed to weaker insurance support during the period of continued attacks. It said crypto insurance coverage fell 20.2%, and that by August 2026, five of nine on-chain insurance protocols had either shut down or shifted to other sectors.

Why It Matters

The findings matter because they challenge a common market assumption that an audit meaningfully lowers overall breach risk on its own. The data suggests that crypto security remains heavily exposed to failures outside audited code, especially in areas such as private key protection and operational controls.

The insurance figures add a broader market-structure concern. If coverage continues to shrink while losses remain concentrated in a small number of very large incidents, projects, exchanges, and users could face a thinner backstop after security failures, increasing pressure on prevention rather than post-incident protection.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

About WEEX View

WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.

-- Price

--
--
--
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com