Skip to Content
Join the Network with Us — Join Membership


Crypto Vaults Breached: ₹34,485 Crore Stolen in 19 Months Despite Security Audits

September 10, 2026

More than 3.63 billion dollars worth of digital assets, amounting to nearly ₹34,485 crore at an assumed exchange rate of ₹95 per dollar, was stolen across the cryptocurrency sector between January 2025 and July 2026. The findings indicate an average daily loss of approximately ₹60 crore over this 19-month window, driven largely by breaches targeting platforms that had already passed independent third-party security audits.

Audited Systems Breached Beyond Core Code

Data from 245 examined cyber incidents shows that 147 affected entities, representing nearly 60% of targeted platforms, had previously completed formal security assessments. Even more striking, around 88% of the total stolen funds were siphoned from these already-audited environments. Despite these figures, technical evaluations reveal that conventional code vulnerabilities accounted for only about 11% of intrusions among audited services, a genuinely counterintuitive finding, given that audits are traditionally focused on exactly that kind of code review.

Instead of breaking reviewed smart contracts directly, attackers bypassed central defenses by targeting broader operational infrastructure. Cybercriminals consistently exploited peripheral components, focusing their intrusions on employee workstations, enterprise cloud environments, supply chains, freshly introduced unaudited code, and exposed private keys, essentially finding the gaps that formal, one-time auditing services in India-style reviews may not have covered in the first place, since attackers were exploiting the operational periphery rather than the core code that gets scrutinised.

Major Exchange Heists and Private Key Compromises

The scale of this problem is reflected in several high-profile attacks, led by the February 2025 intrusion at Bybit, where North Korean-linked actors reportedly stole roughly 1.4 billion dollars, or around ₹13,300 crore. Other notable compromises included approximately 292 million dollars taken from Kelp DAO and about 285 million dollars swiftly drained from Drift Protocol.

Security specialists note that modern adversaries prioritise seizing administrative access credentials over cracking underlying blockchains. Because private cryptographic keys grant full control over wallet holdings, securing them allows intruders to authorise legitimate-looking outbound transfers, without needing to breach core ledger architecture at all.

Human Vulnerabilities and Blockchain Recovery Hurdles

Social engineering remains a primary route for key theft, with threat actors deploying deceptive emails, credential harvesting websites, malicious URLs, and executive impersonation to compromise staff credentials. A researcher at Algoritha Security emphasised that digital asset protection must extend well beyond source-code evaluations, to encompass strict identity verification, cloud perimeter monitoring, behavioural analysis, and defensive key custody, a far more holistic approach than a single formal audit cycle.

Mitigating these breaches remains exceptionally difficult due to the irreversible nature of distributed networks, where completed transfers cannot simply be rolled back or frozen the way traditional financial institutions might handle a fraudulent transaction. Stolen assets are rapidly distributed through multi-wallet networks and across separate chains, leaving platform investors dependent on proactive safeguards such as multi-factor authentication, rigorous post-audit change verification, and absolute secrecy around wallet seed phrases.

FAQs

Q1. How much cryptocurrency was stolen between January 2025 and July 2026?

More than 3.63 billion dollars, roughly ₹34,485 crore, was stolen across the crypto sector during this 19-month period.

Q2. Why did security audits fail to prevent most of these breaches?

Around 88% of stolen funds came from previously audited platforms because attackers targeted operational infrastructure like employee credentials, cloud environments, and private keys, rather than the reviewed smart contract code itself.

Q3. What was the largest single cryptocurrency theft during this period?

The February 2025 intrusion at Bybit, allegedly carried out by North Korean-linked actors, resulted in the theft of roughly 1.4 billion dollars, around ₹13,300 crore.

in News
Share this post
Archive