Crypto has lost about $3.63 billion to exploits since the start of 2025, and the uncomfortable detail for traders is that 60% of the hit platforms had already been audited. A security review, in other words, is not a guarantee. As active insurance coverage across the market shrinks, the burden of due diligence is shifting back onto users — and understanding where the real risk sits is now part of trading, not just a footnote to it.
What Happened
New data puts cumulative losses from crypto exploits at roughly $3.63 billion since 2025 began. Strikingly, about 60% of the platforms that were exploited had undergone audits before the incidents, undercutting the assumption that an audit badge equals safety.
At the same time, active crypto insurance coverage fell from around $163.2 million to $130.2 million, even as exploits grew more frequent. That combination — rising losses and shrinking coverage — means a larger share of any given hack now lands on users and platforms directly, with less of a backstop to absorb it.
What It Means for Traders
Security risk is a real cost of doing business in crypto, and it should factor into where traders keep capital, not just which assets they hold. An audit reduces certain risks but does not eliminate them; exploits often exploit logic, governance, or integration flaws that a point-in-time review can miss. Treating “audited” as a green light is exactly the mistake this data warns against.
- Read audits critically — check what was in scope, when it was done, and whether the code has changed since.
- Assume insurance coverage is thin; do not count on a backstop that is shrinking market-wide.
- Spread counterparty and smart-contract exposure rather than concentrating funds on a single platform or protocol.
The pace has been relentless. Losses reached $1.1 billion in the first half of 2026 across 212 incidents, and one stretch made Q2 2026 crypto’s worst quarter ever for hacks. For active traders, that frequency is the point: exploits are a base-rate event, not a tail risk to be waved away.
The Bigger Picture
The threat is also getting more sophisticated. State-linked and professionalized attackers now run operations that resemble intelligence work more than opportunistic theft, as seen when a US court backed Bybit’s bid to trace $1.5B in North Korea hack funds. Recovery is possible but rare, slow, and never guaranteed.
For the market to mature, security has to move from a marketing checkbox to a continuous discipline: ongoing monitoring, real bug-bounty programs, and honest disclosure. Until that becomes the norm, the audited-yet-exploited statistic will keep repeating, and users will keep absorbing the cost.
Conclusion
The $3.63 billion figure is less a scare number than a prompt to treat security as part of the trade. Diversifying where funds sit, reading audits with a skeptical eye, and assuming limited insurance are practical habits that cost little and protect a lot. In a market where even audited platforms get hit, self-custody discipline and counterparty awareness are edges in their own right.
This article is informational only and does not constitute financial advice.

















