Why Did Crypto Hack Losses Reach $110 Million?
Crypto projects lost roughly $110 million to hacks in July, keeping cybersecurity risk high even as bug bounty programs identified more vulnerabilities before attackers could exploit them.
Immunefi said confirmed and paid bug bounty reports increased 18% during the month, while researchers received $2.32 million for valid findings. The cybersecurity platform also reported that 374 threats were prevented through its bounty programs, up from 317 in June and 339 in May.
The data points to a persistent gap between vulnerabilities discovered by security researchers and those found first by attackers. While bounty programs can reduce losses by rewarding researchers for responsible disclosure, the $110 million stolen during July shows that exploitable flaws remain a major cost for crypto protocols and their users.
For investors, the issue goes beyond individual hacks. Security failures can drain protocol treasuries, weaken token prices, interrupt operations and force projects to reimburse users. The financial impact can therefore extend well beyond the value directly stolen.
Are Audit Competitions Finding More Serious Bugs?
Immunefi said its review of 1,178 tier-1 audits found a median of zero critical or high-severity vulnerabilities. It compared those results with 58 audit competitions conducted through its own platform, which identified more serious flaws per engagement.
The firm said audit competitions found an average of 6.2 serious bugs per engagement, compared with 1.5 for tier-1 audits. The comparison suggests that opening code reviews to a larger pool of security researchers may uncover vulnerabilities that smaller private audit teams miss.
Audit competitions generally allow multiple researchers to independently inspect a project’s code and compete for rewards. That structure can expose the same codebase to different attack methods and specialist skills, potentially increasing the chances of finding complex vulnerabilities before deployment.
Traditional private audits still provide value by reviewing architecture, testing implementation and giving development teams structured security feedback. The findings, however, suggest projects may benefit from combining private audits with broader bounty programs rather than treating one security review as sufficient protection.
Investor Takeaway
The cost difference between finding a vulnerability before and after exploitation is substantial. Projects that spend more on competitive security reviews and bug bounties may face lower financial exposure than protocols relying mainly on one-time private audits.
How Much Does It Cost To Find A Critical Crypto Bug?
Immunefi estimated that identifying a critical vulnerability through an audit competition cost an average of $6,548. That compared with about $66,000 through a private tier-1 audit.
The financial difference becomes far larger when attackers discover vulnerabilities first. Immunefi estimated the average cost at $24.5 million when a critical weakness was exploited before security researchers identified it.
That comparison changes the economics of security spending. A project may view audit fees or bounty rewards as expensive before a vulnerability is found, but those costs can be small relative to the losses from an exploit, emergency response expenses and damage to user confidence.
The figures also help explain why bug bounty programs have become an important part of crypto security budgets. Paying thousands or even hundreds of thousands of dollars for a critical finding can still be cheaper than losing millions through a smart contract exploit or compromised infrastructure.
What Does Rising Researcher Activity Mean For Crypto Security?
Immunefi’s cumulative researcher payouts reached $143.1 million in July, up from $140.8 million in June. The increase shows that protocols continue to spend heavily on external researchers who identify vulnerabilities before they are exploited.
The rise from 317 prevented threats in June to 374 in July also suggests greater researcher activity or a larger number of vulnerabilities entering bounty programs. Either explanation matters for investors because it indicates that security risk remains active even when major exploits are not dominating market headlines.
Bug bounty programs can improve defenses, but they do not eliminate the need for secure development practices, internal testing and independent audits. Some vulnerabilities may also remain undiscovered until contracts are exposed to real market conditions or integrated with other protocols.
The broader lesson from July is that crypto security increasingly depends on layered defenses. Projects that combine internal reviews, private audits, competitive testing and continuous bounty programs have more opportunities to identify weaknesses before attackers do.
With $110 million still lost to hacks in a single month, the industry’s security problem remains costly. The growing volume of confirmed bounty reports, however, shows that more vulnerabilities are being converted into researcher payouts rather than exploit losses, giving protocols a financial reason to expand defensive spending before attackers collect the larger reward.
