Crypto Platforms Lose More Than $3.63 Billion to Cyberattacks
A CoinGecko report said cryptocurrency platforms lost more than $3.63 billion to cyberattacks and stolen passkeys from January 2025 through July 2026.
What are the key facts?
- 1Crypto platforms lost more than $3.63 billion
- 2About 88% of stolen funds came from platforms with independent security audits
- 3About 60% of affected platforms had undergone independent security audits
- 4Bybit lost $1.4 billion, the largest reported loss
What happened?
CoinGecko said in a report dated August 27 that security audits were not enough to protect many cryptocurrency platforms from hacks that caused financial losses. The report said cryptocurrency platforms lost more than $3.63 billion to various cyberattacks and stolen passkeys from January 2025 through July 2026. About 88% of the stolen funds and approximately 60% of the affected platforms had previously undergone independent security audits. The report said most attacks targeted areas that security checks typically do not cover. Bybit was affected the most, with the report citing a $1.4 billion theft in February 2025; Elliptic attributed the incident to North Korea. KelpDao lost $292 million, ranking second, while Drift Protocol lost $285 million. Bybit, KelpDao and Drift Protocol did not immediately respond to requests for comment.
What does this mean for cross-border sellers?
Crypto platforms can suffer financial losses from areas not covered by audits or from stolen passkeys even after completing independent security audits. Sellers using digital-asset platforms, on-chain wallets or related collection accounts should not judge security solely by an “audited” status; also review account permissions and key management.
What should sellers do now?
- 1List all accounts involved in digital assets, collections and withdrawals this week, and remove access for former employees or nonessential personnel.
- 2Recheck passkeys, login credentials and withdrawal permissions for these accounts, disable unused keys and require multiple-person review for high-risk operations.
- 3Ask the platforms you use for the scope of their latest security audit and their major-incident response procedures, focusing on whether the audit covers keys, permissions and withdrawal processes.Industry News