Crypto Hacks Hit $110 Million in July as Bug Bounties and Audits Prove Their Value

Daily Feed
Crypto Hacks Hit $110 Million in July as Bug Bounties and Audits Prove Their Value

Crypto security had a rough July: hackers made off with about $110 million, even as researchers were paid more to find flaws before the thieves did.

  • $110 million lost to hacks in July, according to Immunefi data reported by The Block
  • $2.32 million paid to researchers for confirmed vulnerabilities
  • 374 threats blocked by bug bounty programs
  • Competitive audits found more serious bugs than private tier-1 reviews

That gap says a lot about crypto security economics. Paying researchers to break things responsibly is still far cheaper than finding out what breaks in public, with real money on the line. Wild concept, apparently.

Immunefi’s July data shows researchers were paid $2.32 million for confirmed vulnerabilities, while crypto projects lost roughly $110 million to hacks in the same month. The number of confirmed paid reports rose 18% from the previous month, and bug bounty programs prevented 374 threats, up from 317 in June and 339 in May.

Immunefi also said cumulative payments to security researchers reached $143.1 million by the end of July, up from $140.8 million at the end of June. That is not charity. It is a market price for not getting wrecked.

For readers new to the term, a bug bounty is a program that pays researchers to find and responsibly report vulnerabilities. In a space that loves to describe systems as “trustless”, meaning they try to minimize reliance on a central middleman, bug bounties are still very much a people problem. Code does not save itself.

Immunefi’s broader count is even less cheerful. The platform said it had recorded 164 crypto hacks through Aug. 3, including 67 incidents that each caused more than $1 million in losses. Based on that pace, Immunefi extrapolated 114 major hacks in 2026, which would exceed its previous annual record of 72 set in 2024.

That projection should be treated as a projection, not a prophecy carved into stone. It is a pace calculation from a partial-year snapshot, and those can swing. But the direction is still ugly enough to matter. If the current trend holds, 2026 could become another year where attackers keep proving they are extremely motivated by other people’s money.

One of the more useful findings in Immunefi’s research is that traditional audits are not enough on their own. That is not a hot take; it is just reality catching up with the PowerPoint.

Immunefi reviewed 1, 178 audits by tier-1 security firms and found the median result was zero critical or high-severity vulnerabilities. That sounds reassuring until you realize it does not mean a system was safe. It means the audit process often did not surface the kind of flaw that would have mattered most if a real attacker had found it first.

The sharper comparison came from looking at audit formats. In 58 competitive audits, Immunefi said its analysis found an average of 6.2 serious vulnerabilities per engagement. In private tier-1 audits, the average was 1.5 serious vulnerabilities per engagement.

In plain English: when multiple independent researchers are allowed to attack the same code, they tend to find more of the nasty stuff. That should not be shocking. A single review team can be excellent and still miss edge cases. A crowd of adversarial brains is harder to fool.

The economics behind that finding are brutal. Immunefi said the average cost of identifying a critical flaw through an audit competition was about $6, 548. The comparable cost through a private tier-1 audit was about $66, 000. If an attacker found the weakness first, the estimated cost jumped to $24.5 million.

That is a pretty brutal summary of the security math: spend a little now, or pay a lot later. Some projects still act like a clean launch and a shiny audit badge are enough. They are not. Audits matter, but they are only one layer.

The better security stack includes code review, bug bounties, monitoring, incident response, and the humility to accept that every system has blind spots. Especially in crypto, where one overlooked function can turn into a very expensive lesson.

The recent AFX incident shows why the details matter. AFX suffered a $24.15 million bridge exploit, but the attack hit an AFX-operated bridge, not Arbitrum’s native bridge. That distinction matters because a bridge is the plumbing that moves assets between networks. If the plumbing is compromised, the chain itself may still be intact, but the money can still leak out the side.

crypto.news reported that the attacker drained the stolen funds and converted them into 12, 467.5 ETH. Blockaid said it detected the exploit at 9:30 p.m. UTC on July 22 and helped coordinate response efforts. That kind of monitoring is increasingly part of the defense layer now. Not glamorous. Very useful.

The AFX case is also a reminder that crypto security is not just about smart contracts. It includes bridges, custody systems, price feeds, servers, and all the messy off-chain infrastructure that many protocols still depend on.

Off-chain infrastructure means the systems outside the blockchain itself, like servers, databases, price feeds, and other support machinery, that can still shape what a protocol does. If an attacker compromises that layer, they do not need to break the chain to cause real damage. They just need to fool the software that depends on it.

That is why security teams keep paying closer attention to continuous bug bounties and competitive audits. Bug bounties reward researchers for responsibly reporting flaws before criminals can weaponize them. Competitive audits, where multiple researchers tear through the same code, can expose issues a narrower review misses.

There is, of course, a catch. As AI tools make it easier to scan code and draft reports, bounty programs can also get flooded with low-quality submissions and false positives. More reports do not automatically mean more security. Sometimes they just mean more junk for a triage team to sift through.

That tension is the real story here. Crypto security has improved in real ways, but the attack surface is still broad, and the incentives for attackers remain absurdly strong. The industry has made progress. It has not outgrown its habit of learning the same lesson at the expense of the last person holding the bag.

The more honest takeaway is simple: security spending is boring until it is the thing that saves you from a public disaster. In crypto, that usually means someone else’s money is already gone.

Key questions and takeaways

  • Why do crypto hacks keep happening?
    Because the incentives are massive and the weak points are still everywhere, smart contracts, bridges, price feeds, off-chain systems, and human process failures. Attackers only need one opening; defenders need to close them all.

  • Are bug bounties worth it?
    Yes, when they are run well. Immunefi says researchers were paid $2.32 million in July while bug bounty programs helped prevent 374 threats, which is far cheaper than eating a nine-figure hack.

  • Do private audits catch enough bugs?
    They help, but Immunefi’s data suggests they miss more issues than competitive audits. The sensible approach is to pair private reviews with bug bounties, monitoring, and ongoing security work.

  • What is a bridge exploit?
    A bridge is software that moves assets between blockchains. If that plumbing is compromised, attackers can drain funds even if the underlying chain itself is not broken.

  • Is 2026 really on pace to be a record year for major hacks?
    Immunefi says its current pace extrapolates to 114 major hacks in 2026, which would exceed its previous annual record of 72 in 2024. That is a projection, not a final count, but the trend is clearly hostile.

Further reading

A few useful follow-ups on crypto security, bug bounties, and real-world exploit fallout.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog