NewsCryptoCrypto Hacks Cost $110 Million in July as Bug Bounty Reports Climb

Crypto Hacks Cost $110 Million in July as Bug Bounty Reports Climb

Author: CryptoNewsNet·

Key Takeaways

  • •Cryptocurrency projects lost approximately $110 million to hacks in July 2026, with the Ostium and AFX exploits together accounting for over $47 million in confirmed losses.
  • •Immunefi projects that hacks exceeding $1 million could reach 114 by the end of 2026, which would nearly double the previous annual record of 72 major incidents set in 2024.
  • •Competitive audit formats identified an average of 6.2 serious vulnerabilities per engagement compared to 1.5 in private tier-1 audits, while costing roughly $6,548 per critical flaw versus $66,000 for private audits.
  • •Confirmed and paid bug bounty reports rose 18% in July compared to the prior month, bringing cumulative researcher payouts to $143.1 million.
  • •A Blockaid report found that crypto security losses totaled $1.1 billion during the first six months of 2026 alone.
Crypto Hacks Cost $110 Million in July as Bug Bounty Reports Climb

Crypto Hacks Cost $110 Million in July as Bug Bounty Reports Climb

Cryptocurrency projects lost approximately $110 million to hacks in July, adding to an already expensive year for the industry. The monthly figure emerged as Immunefi, a leading blockchain security platform, recorded an increase in confirmed bug bounty reports and found that competitive audit formats uncovered more serious vulnerabilities than traditional private audits.

2026 Approaching Record Number of Major Incidents

Immunefi documented 164 crypto hacks through August 3, according to data published by the security platform. Of those, 67 incidents each resulted in losses exceeding $1 million.

The company projects that the number of hacks surpassing $1 million could reach 114 by the end of 2026, which would eclipse the previous annual record of 72 major incidents established in 2024. By the same point in 2024, only 49 such incidents had been recorded.

July's estimated $110 million in losses compounded what has already been a costly year. A recent Blockaid report found that crypto security losses totaled $1.1 billion during the first six months of 2026 alone.

Two large attacks accounted for a significant share of July's losses. Ostium lost 23.75 million USDC after an attacker compromised its off-chain infrastructure and manipulated price data relied upon by the protocol—a class of vulnerability that has repeatedly surfaced across decentralized finance as protocols depend on external data feeds for accurate asset pricing. In a separate incident, AFX suffered a $24.15 million bridge exploit. Cross-chain bridges have consistently ranked among the most targeted components in the crypto ecosystem, as they custody large pools of assets across multiple blockchains and introduce complex trust assumptions between networks. Together, the two events represented more than $47 million in confirmed losses.

Bug Bounty Reports and Payouts on the Rise

Immunefi reported that its researchers received $2.32 million in payouts for confirmed vulnerabilities in July. The number of reports that were both confirmed and paid increased 18% compared to the previous month.

The platform's bug bounty programs prevented 374 threats during July, up from 317 in June and 339 in May. Cumulative payments to security researchers reached $143.1 million, compared with $140.8 million at the end of June.

The upward trend coincides with the growing use of artificial intelligence tools, which make it easier for researchers to scan code and prepare vulnerability reports. Crypto.news previously reported that AI tools had driven a sharp increase in bug bounty submissions, though project teams have also contended with a higher volume of low-quality reports and false positives.

Institutional interest in preventive security measures has also expanded. Anchorage Digital invested in Immunefi earlier this year as part of a strategic push into on-chain security infrastructure, reflecting broader recognition among regulated financial institutions that custody and trading operations increasingly depend on the integrity of protocols they interact with.

Audit Competitions Identified More Serious Flaws Than Private Audits

Immunefi reviewed 1,178 audits conducted by tier-1 security firms and found a median of zero critical or high-severity vulnerabilities across those engagements. However, a comparison with 58 competitive audits yielded notably different results.

Audit competitions identified an average of 6.2 serious vulnerabilities per engagement, compared with 1.5 in private tier-1 audits, according to Immunefi. Competitive reviews involve multiple independent researchers examining the same codebase and receiving rewards based on the vulnerabilities they discover.

The average cost of identifying a critical flaw through an audit competition was $6,548. By comparison, the cost was approximately $66,000 through a private tier-1 audit and an estimated $24.5 million when an attacker discovered the vulnerability first.

Recent incidents have demonstrated that completed security reviews do not guarantee that code is free from exploitable weaknesses. A crypto.news investigation into the Coldcard breach found that an AI-assisted audit identified an additional 85 critical bugs across Bitcoin-related projects after a firmware weakness exposed wallet users.

Immunefi's findings suggest that projects may benefit from combining continuous bug bounty programs and competitive reviews alongside conventional audits. With 2026 already approaching the annual record for major incidents, the cost differential between preventive research and live exploitation remains substantial.