Crypto Vaults Breached: ₹34,485 Crore Stolen in 19 Months Despite Security Audits

Rinky Rai
By Rinky Rai - A freelance journalist
3 Min Read

More than 3.63 billion dollars worth of digital assets, amounting to nearly 34,485 crore rupees at an assumed exchange rate of 95 rupees per dollar, was stolen across the cryptocurrency sector between January 2025 and July 2026. The findings indicate an average daily loss of approximately 60 crore rupees over the 19-month window, driven largely by breaches targeting platforms that had already passed independent third-party security audits.

Audited Systems Breached Beyond Core Code

​Data from 245 examined cyber incidents shows that 147 affected entities, representing nearly 60 percent of targeted platforms, had previously completed formal security assessments. Furthermore, around 88 percent of the total stolen funds were siphoned from audited environments. Despite these figures, technical evaluations reveal that conventional code vulnerabilities accounted for only about 11 percent of intrusions among audited services.

​Instead of breaking reviewed smart contracts directly, attackers bypassed central defenses by targeting broader operational infrastructure. Cybercriminals consistently exploited peripheral components, focusing their intrusions on employee workstations, enterprise cloud environments, supply chains, freshly introduced unaudited code, and exposed private keys.

Major Exchange Heists and Private Key Compromises

​The scale of the problem is reflected in high-profile attacks, led by the February 2025 intrusion at Bybit, where North Korean-linked actors reportedly stole roughly 1.4 billion dollars, or around 13,300 crore rupees. Other notable compromises included approximately 292 million dollars taken from Kelp DAO and about 285 million dollars swiftly drained from Drift Protocol.

​Security specialists note that modern adversaries prioritize seizing administrative access credentials over cracking underlying blockchains. Because private cryptographic keys grant full control over wallet holdings, securing them allows intruders to authorize legitimate-looking outbound transfers without needing to breach core ledger architecture.

Human Vulnerabilities and Blockchain Recovery Hurdles

​Social engineering remains a primary route for key theft, with threat actors deploying deceptive emails, credential harvesting websites, malicious URLs, and executive impersonation to compromise staff credentials. A researcher at Algoritha Security emphasized that digital asset protection must extend beyond source-code evaluations to encompass strict identity verification, cloud perimeter monitoring, behavioral analysis, and defensive key custody.

​Mitigating these breaches remains exceptionally difficult due to the irreversible nature of distributed networks, where completed transfers cannot simply be rolled back or frozen as in traditional financial institutions. Stolen assets are rapidly distributed through multi-wallet networks and across separate chains, leaving platform investors dependent on proactive safeguards such as multi-factor authentication, rigorous post-audit change verification, and absolute secrecy around wallet seed phrases.

Stay Connected