Crypto projects lost about $110 million to hacks in July, while payouts to security researchers using Immunefi rose to $2.32 million, according to the cybersecurity platform’s latest monthly update. The figures place a sharp contrast at the center of the sector’s security debate: teams are spending more to identify vulnerabilities before launch, yet attackers continue to extract substantial sums from weaknesses that reach production.
Immunefi said the number of confirmed and paid bug reports increased 18% during the month. Its bug bounty programs also prevented 374 potential threats, up from 317 in June and 339 in May. The rise suggests that projects are receiving more actionable findings through ongoing public vulnerability-disclosure programs rather than relying only on security checks conducted before code goes live.
The platform’s cumulative payouts to researchers reached $143.1 million in July, compared with $140.8 million a month earlier. Those payments are small beside the losses attributed to successful exploits, but they provide a measure of how much crypto teams are willing to pay for security work before a vulnerability can be monetized by an attacker.
Audit competitions found more serious issues
Immunefi’s review of 1,178 tier-1 security audits found a median of zero critical or high-severity vulnerabilities. The platform compared those private audits with 58 audit competitions, where multiple independent researchers examine a project’s code under a defined program.
The audit competitions identified an average of 6.2 serious bugs per engagement, according to Immunefi, compared with 1.5 serious bugs in the tier-1 audit sample. The comparison does not establish that every private audit misses vulnerabilities or that every competition produces the same result. It does show that expanding the number of researchers reviewing code can expose a materially larger set of severe issues in the programs examined.
That distinction matters most for decentralized finance protocols and infrastructure projects that handle large pools of assets or control administrative functions. A conventional audit is usually a limited engagement involving a selected security firm and a specified scope. A competition can put the same code before a larger group of specialists, who may approach potential failures from different angles and receive rewards for reporting them.
Immunefi calculated the average cost of finding a critical bug at $6,548 through an audit competition. The comparable figure was about $66,000 in a private tier-1 audit, while a critical flaw found first by an attacker carried an average cost of $24.5 million, according to the platform.
The figures offer a practical argument for combining methods rather than treating an audit as a final security certification. A private review can identify architectural weaknesses and provide direct consultation with developers, while competitions and bug bounties can keep testing code after release. The $24.5 million attacker-first estimate also illustrates why a project’s security budget can be misleading if measured only by the cost of a formal audit.
Infrastructure attacks concentrated losses
The July update arrived after a difficult first half for crypto security. Immunefi said digital-asset projects lost $972 million to malicious actors in the first six months of 2026.
Infrastructure-level attacks accounted for 76% of those losses while representing 15% of recorded security incidents, the platform said. Such attacks typically target the systems around a protocol, including compromised private keys, centralized servers, administrator accounts, or deployment infrastructure, rather than exploiting a flaw in a smart contract’s on-chain logic.
The concentration of losses in relatively few infrastructure incidents can shape how teams allocate security resources. Smart-contract testing remains essential, particularly for protocols that custody or move user funds. Yet code reviews alone cannot protect a project whose upgrade key is compromised, whose employee credentials are stolen, or whose operational systems are breached.
Private keys deserve particular attention because they can grant direct control over wallets, multisignature signers, bridges, protocol upgrades, or treasury functions. Hardware-backed key management, separation of duties, strict approval policies, and limits on privileged permissions can reduce the damage from one compromised credential. These operational protections are harder to capture in a narrowly scoped code audit.
Bug bounties extend testing beyond launch
Bug bounty programs reward independent researchers for responsibly disclosing vulnerabilities under rules set by a project. Unlike a one-time audit, they can remain active as code changes, integrations are added, and new attack techniques emerge.
Immunefi said ethical hackers earned about $13.45 million for reporting 837 valid vulnerabilities across digital-asset networks between January and June. The platform’s July data indicates that active bounty programs are producing a growing flow of confirmed findings, although the available figures do not break down the affected projects or the severity of every reported issue.
For users assessing newer token projects or protocols, the existence of a bug bounty is one useful signal of a team’s security process, though it cannot guarantee safety. The program’s scope, reward structure, response process, and whether it covers deployed contracts and critical infrastructure can matter as much as its public presence.
For development teams, the July comparison adds pressure to move beyond a single security checkpoint. The difference between the reported cost of a critical finding in an audit competition and the cost of an attacker-led discovery gives projects a financial reason to maintain layered defenses: code audits, competitive reviews, public bounties, key-management controls, and incident-response plans.
July’s $110 million in reported hack losses shows that those layers are not yet preventing every major breach. But Immunefi’s numbers also suggest that the security process is becoming more continuous, with researchers finding and reporting more vulnerabilities before attackers can turn them into losses.
To strengthen your defenses against rising crypto hacks, learn key protection steps in this security guide today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

