Crypto Projects Lose $110 Million in July Hacks, Audit Competitions Expose Major Flaws

1 hour ago 2 sources negative

Key takeaways:

  • Competitive audits uncover six critical bugs versus 1.5 privately, redefining security expectations.
  • Bug bounties prevented $110M in July hacks with just $2.32M payouts, a strong defense.
  • Accelerating hack frequency threatens institutional trust, pressuring unvetted DeFi token prices.

Cryptocurrency platforms lost approximately $110 million to hacks in July, according to data from security firm Immunefi. The month’s total adds to an already costly year, with 164 crypto hacks recorded through August 3, 67 of which exceeded $1 million in losses. Immunefi now projects that major incidents could reach 114 by year-end, surpassing the previous annual record of 72 set in 2024.

Two high-profile exploits contributed significantly to the July figure. Ostium lost 23.75 million USDC after an attacker compromised its off‑chain infrastructure and manipulated price data, while AFX suffered a $24.15 million bridge exploit. Together these incidents accounted for more than $47 million in losses.

At the same time, Immunefi highlighted a stark gap in vulnerability detection. A review of 1,178 tier‑1 security audits revealed a median of zero critical or high‑severity vulnerabilities per engagement. In contrast, 58 competitive audits—where multiple independent researchers examine the same code—discovered an average of 6.2 serious bugs per engagement, compared to just 1.5 in private audits.

The cost of finding a critical flaw also varied dramatically: an audit competition identified a vulnerability for an average of $6,548, whereas a private tier‑1 audit cost around $66,000. When attackers discovered the vulnerability first, the average cost soared to an estimated $24.5 million.

Bug bounty programs proved their worth, preventing 374 threats in July—up from 317 in June. Immunefi paid researchers $2.32 million for confirmed vulnerabilities that month, and cumulative payouts reached $143.1 million. The rise in submissions has been partly driven by AI tools that help researchers scan code more efficiently, though it has also brought more low‑quality reports.

With 2026 already on pace to break the annual record for major crypto hacks, Immunefi’s findings suggest that projects may need to layer competitive audits and continuous bug bounty programs on top of traditional reviews to close the security gaps that attackers continue to exploit.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.