Audits are not saving crypto protocols — and the $3.63 billion in 2025 exploit losses prove it.
A new CoinGecko report has confirmed the number that should be making every DeFi user rethink their risk exposure: six out of every ten platforms that got exploited this year had already passed a security audit. The certificate of safety that projects plaster across their websites and Discord servers? It may be closer to a participation trophy than a shield.
But here is where it gets worse.
While exploits are accelerating, crypto insurance coverage is moving in the opposite direction. Active coverage has quietly dropped from $163.2 million to $130.2 million, a contraction happening in real time as the attack surface grows larger. The industry is becoming simultaneously more dangerous and less protected. Whoever is pricing crypto insurance right now is either very smart or very early to an exit.
The Audit Illusion
The 60% figure is the headline, but the implication runs deeper. Audits have functioned as a trust signal for retail investors since the DeFi explosion of 2020. Projects advertise them in launch announcements. Influencers cite them as green lights. Launchpads use them as listing criteria.
What the CoinGecko data is quietly telling you is that this signal has been significantly degraded. Auditors can only assess code as it exists at the moment of review. Upgradeable contracts, new integrations, economic design flaws, and oracle manipulation vectors often fall outside the scope of what a standard audit catches. Hackers are not reading audit reports for reassurance. They are reading them for the footnotes.
Who Is Absorbing the Losses
With insurance coverage shrinking to $130.2 million against a backdrop of billions in annual losses, the math is brutal. If a major protocol gets hit, users are not getting made whole through an insurance payout. They are getting made whole through community rescue packages, token dilution, or simply not getting made whole at all.
The drop in coverage suggests that underwriters are either pulling back from the sector or struggling to price the risk accurately. Neither interpretation is comforting.
What Holders Should Watch
This report is not a reason to exit crypto. It is a reason to be selective about where you put capital to work. Before depositing into any protocol, check whether it holds active, verifiable insurance coverage, not just an audit badge. Look for platforms with bug bounty programs still running post-launch. Treat upgradeable contracts with extra scrutiny.
The projects that survive the next wave of exploits will be the ones that treated security as an ongoing operational cost, not a one-time checkbox. Find those projects before the next $3.63 billion disappears.