Crypto platforms lose more than $3.6 billion to cyberattacks and theft incidents over roughly the past 18 months, according to findings cited by CNBC and PYMNTS. The losses include stolen funds linked to attacks such as compromised or stolen credentials (including passkeys), resulting in direct financial losses for affected platforms.

The reporting also points to a contradiction: many platforms that experience losses had previously completed security checks. CoinGecko data, as referenced across the two outlets, indicates that more than 60% of platforms involved in loss events had undergone independent security audits. PYMNTS adds that most incidents occur despite these audits, framing the figure as evidence that audits do not always prevent theft.

Across the sources, the shared takeaway is that cyber risk remains material for cryptocurrency platforms even when they pursue third-party review. The outlets differ mainly in their emphasis—CNBC highlights the scale of losses and the audit prevalence, while PYMNTS focuses on the persistence of losses despite security audits and the types of stolen access involved.