toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Crypto hacks total $110 million in July

2026-08-10 14:25

Crypto projects lost about $110 million to hacks in July, while payouts to security researchers using Immunefi rose to $2.32 million, according to the cybersecurity platform’s latest monthly update. The figures place a sharp contrast at the center of the sector’s security debate: teams are spending more to identify vulnerabilities before launch, yet attackers continue to extract substantial sums from weaknesses that reach production.

Immunefi said the number of confirmed and paid bug reports increased 18% during the month. Its bug bounty programs also prevented 374 potential threats, up from 317 in June and 339 in May. The rise suggests that projects are receiving more actionable findings through ongoing public vulnerability-disclosure programs rather than relying only on security checks conducted before code goes live.

The platform’s cumulative payouts to researchers reached $143.1 million in July, compared with $140.8 million a month earlier. Those payments are small beside the losses attributed to successful exploits, but they provide a measure of how much crypto teams are willing to pay for security work before a vulnerability can be monetized by an attacker.

Audit competitions found more serious issues

Immunefi’s review of 1,178 tier-1 security audits found a median of zero critical or high-severity vulnerabilities. The platform compared those private audits with 58 audit competitions, where multiple independent researchers examine a project’s code under a defined program.

The audit competitions identified an average of 6.2 serious bugs per engagement, according to Immunefi, compared with 1.5 serious bugs in the tier-1 audit sample. The comparison does not establish that every private audit misses vulnerabilities or that every competition produces the same result. It does show that expanding the number of researchers reviewing code can expose a materially larger set of severe issues in the programs examined.

That distinction matters most for decentralized finance protocols and infrastructure projects that handle large pools of assets or control administrative functions. A conventional audit is usually a limited engagement involving a selected security firm and a specified scope. A competition can put the same code before a larger group of specialists, who may approach potential failures from different angles and receive rewards for reporting them.

Immunefi calculated the average cost of finding a critical bug at $6,548 through an audit competition. The comparable figure was about $66,000 in a private tier-1 audit, while a critical flaw found first by an attacker carried an average cost of $24.5 million, according to the platform.

The figures offer a practical argument for combining methods rather than treating an audit as a final security certification. A private review can identify architectural weaknesses and provide direct consultation with developers, while competitions and bug bounties can keep testing code after release. The $24.5 million attacker-first estimate also illustrates why a project’s security budget can be misleading if measured only by the cost of a formal audit.

Infrastructure attacks concentrated losses

The July update arrived after a difficult first half for crypto security. Immunefi said digital-asset projects lost $972 million to malicious actors in the first six months of 2026.

Infrastructure-level attacks accounted for 76% of those losses while representing 15% of recorded security incidents, the platform said. Such attacks typically target the systems around a protocol, including compromised private keys, centralized servers, administrator accounts, or deployment infrastructure, rather than exploiting a flaw in a smart contract’s on-chain logic.

The concentration of losses in relatively few infrastructure incidents can shape how teams allocate security resources. Smart-contract testing remains essential, particularly for protocols that custody or move user funds. Yet code reviews alone cannot protect a project whose upgrade key is compromised, whose employee credentials are stolen, or whose operational systems are breached.

Private keys deserve particular attention because they can grant direct control over wallets, multisignature signers, bridges, protocol upgrades, or treasury functions. Hardware-backed key management, separation of duties, strict approval policies, and limits on privileged permissions can reduce the damage from one compromised credential. These operational protections are harder to capture in a narrowly scoped code audit.

Bug bounties extend testing beyond launch

Bug bounty programs reward independent researchers for responsibly disclosing vulnerabilities under rules set by a project. Unlike a one-time audit, they can remain active as code changes, integrations are added, and new attack techniques emerge.

Immunefi said ethical hackers earned about $13.45 million for reporting 837 valid vulnerabilities across digital-asset networks between January and June. The platform’s July data indicates that active bounty programs are producing a growing flow of confirmed findings, although the available figures do not break down the affected projects or the severity of every reported issue.

For users assessing newer token projects or protocols, the existence of a bug bounty is one useful signal of a team’s security process, though it cannot guarantee safety. The program’s scope, reward structure, response process, and whether it covers deployed contracts and critical infrastructure can matter as much as its public presence.

For development teams, the July comparison adds pressure to move beyond a single security checkpoint. The difference between the reported cost of a critical finding in an audit competition and the cost of an attacker-led discovery gives projects a financial reason to maintain layered defenses: code audits, competitive reviews, public bounties, key-management controls, and incident-response plans.

July’s $110 million in reported hack losses shows that those layers are not yet preventing every major breach. But Immunefi’s numbers also suggest that the security process is becoming more continuous, with researchers finding and reporting more vulnerabilities before attackers can turn them into losses.


To strengthen your defenses against rising crypto hacks, learn key protection steps in this security guide today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.