Security Audits Missed 94% of It

Author

Ahmed Barakat

Author

Ahmed Barakat

Part of the Team Since

Aug 2025

About Author

Ahmed Barakat is a journalist and copywriter based in Georgia with a growing focus on blockchain technology, DeFi, AI, privacy, digital assets, and fintech innovation.

Last updated: 

Crypto investors were fleeced of almost a billion dollars in the first half of 2026, and the industry’s favorite comfort blanket did little to stop it.

Security research house ack3 has verified 135 exploits between January and June, with $939.86m in attributed losses, averaging $6.96m each time the alarm sounded. The firm has published its full incident dataset openly, so every number can be checked line by line.

Here’s the stat that should chill every retail holder: of the money stolen from audited projects, 94.4% walked out through code or infrastructure the auditors never examined. The green tick covered the front door. The thieves came through the loading bay.

Read More:  AI Agents Expose Ethereum Gossipsub Flaw

The Mega Heists Major Crypto Audits Missed

Two mega-heists account for the bulk of the carnage, and neither was a bug that an auditor missed.

Kelp DAO’s rsETH hemorrhaged $292m in April after attackers forged a LayerZero cross-chain message by compromising the protocol’s single message verifier – one checkpoint, no backup.

Two weeks earlier, Solana perps giant Drift lost $285m when operatives – linked by researchers to North Korea – spent months socially engineering their way to admin keys. Between them: $577m, roughly 61% of everything stolen all half. Not broken maths. Broken keys and broken trust.

The pattern repeats down the ledger. Step Finance ($40m), Humanity Protocol ($32m), and Resolv’s USR stablecoin ($24.5m) were all drained through compromised private keys and signing infrastructure, the humans, not the smart contracts. Cross-chain bridges were the other killing field, from Verus ($11.5m) to Syscoin ($8m) to Taiko ($1.7m).

Read More:  What MiCA Means for Europe

Nowhere was safe, not even the blue chips. Polymarket was hit twice: a $700k internal wallet drain in May, then a $3.1m front-end supply-chain attack in June that turned its own website into a wallet drainer.

CoW Swap had its domain hijacked from under it. And in the half’s most poetic entry, feared MEV bot jaredfromsubway.eth, which spent years farming retail traders, was itself fleeced for $7.5m by a honeypot token.

The unaudited crowd fared no better. Truebit coughed up $26.4m to a schoolboy integer-overflow error in its mint pricing.

DISCOVER: The Biggest Crypto Hacks of 2025

One Crypto Audit Isn’t Enough: Good Projects Are Checked Regularly

And on the rare occasions, had auditors reviewed the exploited code? The reports were mostly stale; 17 of the 20 nearest relevant audits were at least six months old by the time the hackers struck.

Read More:  Does Iran Tension Signals Market Shift For PEPE Price Prediction?

In a worrying prediction about the rise of AI tooling, Ack3 CEO and Founder Josef Gattermayer said:

Our research shows that audited projects lost $681 million through attack paths outside the identified audit scope, representing 94% of their losses. Smart contract reviews remain essential, but AI makes it easier to find weaknesses across integrations and combine them into cross-component attacks, so security reviews must now cover the whole system.

Josef Gattermayer, Founder and CEO Ack3

The takeaway is brutal in its simplicity. “Audited” is a marketing word until you ask three questions: what exactly was reviewed, how long ago, and who controls the keys today. In H1 2026, the honest answers were too often: not this bit, over a year ago, and one compromised key from a catastrophe.

The auditors can read every line of the code. They can’t read the developer’s mind when clicking a link from “HR”.

Discover: The Best Crypto to Diversify Your Portfolio


Facebook Comments Box
spot_img

Explore more

spot_img

Another crypto wallet pulls the plug tomorrow with no exact cutoff,...

Ctrl Wallet users have reached the app's last scheduled day of full service. On Aug. 3, sending, receiving, swaps, and dApp connections are due...

XRP extends the longest active ETF inflow streak in crypto as...

XRP funds led altcoin inflows in July, extending a four-month streak that increasingly separates them from most rival products.The US-listed funds attracted $27.29 million...

Coldcard’s $89M wallet bug triggers the biggest Bitcoin movement since FTX...

Coldcard’s wallet crisis has shaken Bitcoin sentiment, blurred on-chain signals and exposed a recurring weakness in AI-assisted cyber defenses.On July 30, hardware maker Coinkite...

The US just blacklisted the Iranian maritime scheme forcing commercial ships...

The U.S. Office of Foreign Assets Control added two Iranian maritime insurance firms to its Specially Designated Nationals list on July 29, designating HormuzSafe...

How XRPL validators quietly killed a silent exploit that could have...

RippleX expects the next version of the XRP Ledger's core server software, xrpld 3.3.0, as soon as next week. The release would put rewritten...

Government Hires Law Firm in Dubai to Cancel Benazir’s Bail: Home...

2 The government has initiated steps to cancel the bail of former Inspector General of Police (IGP) Benazir Ahmed. For this purpose, a law firm...

Trump’s legal loophole around the Supreme Court is keeping inflation alive

The Supreme Court gave Donald Trump a pretty direct answer in February: the emergency law he had used to tax imports from nearly everywhere...

New York asks judge to force Kalshi to hand over the...

New York has asked a Manhattan state court to permanently block prediction-market exchange Kalshi from offering what the state calls unlicensed sports wagering to...