AI Agents Engineering: AI-агенти на Google ADK 2.0 + Go SDK ➡️

Crypto platforms lost $3.63 billion due to cyberattacks, even though most underwent security audits. Why didn't the audits save them?

Crypto platforms lost more than $3.63 billion to hacking attacks in 19 months. Most of the stolen money fell on projects that had previously undergone independent security audits. Just nine infrastructure and supply chain breaches gave attackers more than $1.8 billion — almost half of the total stolen amount.

Leave a comment
Crypto platforms lost $3.63 billion due to cyberattacks, even though most underwent security audits. Why didn't the audits save them?

Crypto platforms lost more than $3.63 billion to hackers in 19 months. Most of the stolen money came from projects that had previously undergone independent security audits. Just nine infrastructure and supply chain breaches gave attackers more than $1.8 billion — almost half of the total stolen.

These are the conclusions of a CoinGecko report covering 245 attacks from January 2025 to July 2026.

Hackers most often attacked smart contracts — blockchain programs that automatically execute set rules, such as transferring funds after certain conditions are met. CoinGecko counted 135 such attacks. In total, they caused about $777 million in losses.

In contrast, there were only nine attacks on the supply chain and infrastructure, but the losses from them exceeded $1.81 billion. A supply chain attack refers to a situation where hackers break not the crypto service itself, but something on which it depends. For example, a third-party application, server, transaction signing tool, or other component that the platform trusts.

This is how the largest breach in the sample occurred, the attack on Bybit in February 2025, during which hackers stole about $1.4 billion. The attackers compromised the Safe environment, a service that Bybit used to sign transactions. As a result, exchange employees saw one transaction on their screen, but actually signed another, which gave the hackers control of the funds.

The second largest was the $292 million KelpDAO hack in April 2026. There, attackers used social engineering to gain access to a developer session and then penetrated the project's infrastructure.

Of the 245 projects attacked, 147 had previously undergone independent security audits. They accounted for over 88% of all stolen funds. However, in most cases, the hackers attacked something that the auditors had not checked at all.

Only about 11% of attacks on audited projects exploited a vulnerability in a part of the system that the auditors had previously tested. In other cases, the weak point was third-party infrastructure, social engineering, new code added after the audit, or standard system functions that hackers learned to abuse.

Previously, dev.ua wrote that in February 2025, hackers attacked the Bybit crypto exchange and withdrew almost $1.5 billion in tokens. This breach was the largest among the incidents that CoinGecko has now analyzed.

Hackers attacked Polymarket users and stole $3 million in crypto
Hackers attacked Polymarket users and stole $3 million in crypto
On the topic
Hackers attacked Polymarket users and stole $3 million in crypto
Ukrainian Web3 security auditing company Hacken suffered an attack that allowed a hacker to create 900 million HAI tokens
Ukrainian Web3 security auditing company Hacken suffered an attack that allowed a hacker to create 900 million HAI tokens
On the topic
Ukrainian Web3 security auditing company Hacken suffered an attack that allowed a hacker to create 900 million HAI tokens
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».
6
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
Шахраї грабують українців від імені «Дії» та Зеленського: перелік сайтів
4 comments
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
Кіберполіцейські розробили онлайн-гру, що допоможе дітям виробити навички безпечної поведінки в інтернеті: як скачати
4 comments
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
Пишуть, що Signal зламали. Насправді - ні. Як захистити дані в месенджері - поради експерта з кібербезпеки
3 comments

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.