Why did audited protocols account for 88% of crypto hack losses since 2025?

A CoinGecko report reveals that 88.44% of funds stolen since early 2025 came from protocols that had already undergone independent security audits. This suggests that traditional audits are no longer sufficient to stop sophisticated exploits, highlighting a growing security gap in the DeFi ecosystem.
Why did audited protocols account for 88% of crypto hack losses since 2025?

According to CoinGecko’s 2026 state of crypto security report, audited protocols accounted for 88.44% of all stolen funds since January 2025. The study, which tracked 245 security incidents, found that $3.63 billion was lost through July 2026 despite 147 of the breached platforms having been cleared by independent security firms. This data indicates that while audits remain a baseline requirement for DeFi projects, they are increasingly failing to detect the complex logic errors and cross-chain vulnerabilities currently being exploited by high-level attackers.

The scale of these losses—exceeding $3.6 billion in just 19 months—signals a shift in the threat landscape where hackers specifically target high-liquidity protocols that have gained user trust through successful audits. For US investors, this trend undermines the 'audit badge' as a gold standard for safety. The report suggests that attackers are finding ways to bypass reviewed code, often through flash loan attacks or by exploiting third-party integrations that were not included in the original audit scope.

From a regulatory perspective, these findings may prompt US agencies like the SEC to take a closer look at the liability of security firms and the standardization of smart contract reviews. If independent audits are proving insufficient to protect consumer capital, regulators might demand more frequent, real-time monitoring or mandated insurance layers for decentralized platforms operating in the US market. The failure of audited systems to prevent such significant losses provides ammunition for those advocating for stricter oversight of the DeFi sector.

Moving forward, investors and developers should watch for a transition from static point-in-time audits toward continuous security models, including bug bounties and automated threat detection. The industry's reliance on a single 'passed' audit is likely to fade, replaced by a multi-layered approach to risk management. As we head into the latter half of 2026, the success of protocols in adopting these dynamic security measures will be a key indicator of their long-term viability and market sentiment.