A security audit was supposed to be the gold standard. Get your code reviewed by professionals, publish the report, and signal to users that your platform is safe. According to CoinGecko’s 2026 State of Crypto Security Report, that signal is worth considerably less than advertised.
The report, released on August 27, 2026, found that 147 of 245 exploited platforms, roughly 60%, had completed independent security audits before they were hacked. Those audited platforms accounted for 88.44% of all stolen funds across the study period.
The numbers behind the headline
CoinGecko tracked losses from January 2025 through July 2026, documenting $3.63 billion stolen across 245 separate incidents. The damage was heavily concentrated: the ten largest attacks alone represented more than 72.5% of total losses.
Infrastructure and supply-chain vulnerabilities were the single biggest driver of losses, responsible for more than $1.8 billion of the total. Smart-contract exploits at decentralized applications cost another $546 million, while centralized exchanges were hit primarily through private-key compromises.
Perhaps the most pointed finding: only about 11% of all incidents involved vulnerabilities that fell within the actual scope of a completed audit, accounting for $396 million in losses. The overwhelming majority of successful attacks targeted infrastructure, key management, and governance layers that typical smart-contract audits simply do not cover.
Why audits keep failing to prevent losses
The CoinGecko data makes this structural gap concrete. More than 89% of losses came from attack surfaces that auditors were never asked to evaluate. The audit passed. The platform got hacked anyway. Both of those things are true simultaneously, and neither one contradicts the other.
The insurance gap compounds the risk
The report also flagged a deterioration in the industry’s insurance landscape. Active crypto insurance coverage fell 20.2% to $130.2 million over the period, even as cumulative industry payouts held roughly stable at around $33 million.
To put that coverage figure in context: $130.2 million in total active coverage against $3.63 billion in documented losses is a coverage ratio that would make a traditional insurer uncomfortable.
What this means for platforms and their users
The concentration of losses among a small number of large incidents also matters. More than 72.5% of all losses came from the ten biggest attacks. A single catastrophic infrastructure failure or key compromise at a major platform can represent a loss event larger than dozens of smaller exploits combined.

