Crypto Hacks Reveal Blind Spot in Code Audits
The crypto industry's reliance on code audits has been put to the test. Despite passing security audits, platforms lost over $3.2 billion in hacks between January 2025 and July 2026. According to CoinGecko's State of Crypto Security Report, audited platforms accounted for 88.44% of total losses during this period.
The reason behind these losses lies not in the audits' failure but rather in their narrow focus on code vulnerabilities. Only 11% of incidents involved flaws within audited smart-contract code, totaling $396 million in losses. The remaining $1.8 billion was due to infrastructure and supply-chain compromises.
The Bybit hack in February 2025 serves as a prime example. The exchange suffered a $1.46 billion loss after malicious code was injected into the interface of Safe Wallet, a third-party wallet service used by Bybit's team. This breach highlights the disconnect between what users see and what they actually sign.
Insurance coverage has also retreated in tandem with these shifting risks. On-chain insurance protocols saw active coverage fall 20.2% from $163.2 million to $130.2 million, while cumulative payouts remained flat at $33 million. In contrast, exchanges like Bybit have taken matters into their own hands, using bridge loans and partner deposits to recover stolen funds.
The report raises concerns about the industry's defenses being misdirected towards code vulnerabilities while overlooking infrastructure and supply-chain weaknesses. As long as this gap persists, the burden of covering future large exploits may fall on exchanges' balance sheets.