Crypto Hacks Drain $110 Million in July as Immunefi Reveals Gaps in Blockchain Security Audits
Key Takeaways
- •Immunefi said a review of 1,178 tier-1 audits found a median of zero critical or high-severity vulnerabilities.
- •Audit competitions identified an average of 6.2 serious vulnerabilities per engagement, compared with 1.5 for conventional tier-1 audits.
- •Finding a critical vulnerability through an audit competition cost about $6,548 on average, versus roughly $66,000 through a private tier-1 audit.
- •Crypto hackers stole approximately $110 million in July, and attacker-first discovery of a critical vulnerability was estimated to cause about $24.5 million in average damage.
- •Immunefi reported that bug bounty programs prevented 374 threats in July and that cumulative researcher payouts reached $143.1 million by the end of the month.

Crypto Hacks Drain $110 Million in July as Immunefi Reveals Gaps in Blockchain Security Audits
Cryptocurrency hackers stole approximately $110 million from blockchain projects in July, underscoring the persistent security threats facing decentralized finance and other digital asset platforms. The losses coincide with new research from blockchain security firm Immunefi, which found that conventional audit practices may be less effective at identifying critical vulnerabilities than competitive security reviews.
Immunefi's analysis revealed a notable gap between traditional tier-1 security audits and competitive audit contests. A review of 1,178 tier-1 audits showed a median of zero critical or high-severity vulnerabilities identified, while 58 audit competitions uncovered substantially more serious weaknesses. The findings raise questions about whether a single conventional audit provides sufficient protection for increasingly complex blockchain applications, particularly as the total value locked in DeFi protocols has grown and the industry continues to recover from multi-billion-dollar losses seen during 2022's wave of major exploits.
Audit Method Comparison
Security audits have become a standard part of blockchain development, particularly for projects preparing to launch protocols that manage user funds. A conventional private audit typically involves a security firm assigning a dedicated team of researchers to review a project's codebase before deployment.
Competitive audits take a fundamentally different approach. Rather than relying on a single security team, an audit competition allows multiple independent researchers to examine the same code simultaneously. Each participant may approach the protocol from a distinct angle, potentially uncovering attack vectors that a single team might miss. The model parallels broader trends in traditional software security, where crowdsourced testing platforms have gained traction as organizations seek broader coverage than a single vendor engagement typically provides.
Immunefi's data showed that audit competitions identified an average of 6.2 serious vulnerabilities per engagement, compared with 1.5 serious vulnerabilities per conventional tier-1 audit. This disparity does not necessarily indicate that traditional audits are ineffective. Rather, the results suggest that engaging multiple independent researchers can provide additional coverage, especially for complex protocols where vulnerabilities emerge from interactions between different system components.
For developers, the findings point toward a multi-layered security strategy rather than relying on a single audit as the final word on protocol safety.
Cost of Finding Critical Vulnerabilities
The financial comparison in Immunefi's research was equally striking. Identifying a critical vulnerability through an audit competition cost an average of approximately $6,548. By contrast, finding a critical vulnerability through a private tier-1 audit cost roughly $66,000 on average — a tenfold difference in security spending.
For blockchain projects operating under limited development budgets, the cost of security is a significant consideration. Developers must weigh audit expenses against the potentially devastating consequences of an exploit. However, the cost of pre-launch vulnerability discovery represents only part of the equation.
Immunefi estimated that when an attacker discovers a critical vulnerability first, the average financial damage reaches approximately $24.5 million. For projects controlling millions of dollars in digital assets, identifying a vulnerability before malicious actors do can represent a decisive financial advantage.
July Losses Highlight Industry-Wide Stakes
The security findings come against the backdrop of approximately $110 million in cryptocurrency stolen during July. Crypto theft remains a persistent problem, with attackers continuously targeting smart contracts, decentralized applications, wallets, bridges, and infrastructure connected to digital asset platforms. Cross-chain bridges have been among the most lucrative targets historically, with several bridge exploits in 2022 — including the Ronin Network and Wormhole incidents — each resulting in hundreds of millions of dollars in losses and prompting renewed scrutiny of how assets are transferred between blockchains.
Unlike traditional financial systems, blockchain transactions are often irreversible. Once an attacker successfully transfers cryptocurrency from a compromised protocol, recovering the assets can be extremely difficult. This irreversibility makes preventive security particularly critical.
A vulnerability that appears relatively minor during a code review can become enormously costly when connected to a protocol holding millions or billions of dollars in assets. The July losses reinforce that code quality and security testing remain central concerns for the broader cryptocurrency industry, even as institutional participation grows and regulatory bodies in multiple jurisdictions increase their focus on digital asset oversight.
Bug Bounty Researchers Expand Their Role
Immunefi's data also highlighted increased activity among independent security researchers participating in bug bounty programs. During July, researchers received approximately $2.32 million in rewards for confirmed vulnerabilities, while the number of confirmed and paid bug bounty reports rose by 18%.
Bug bounty programs allow developers to establish financial incentives for researchers who discover and responsibly report vulnerabilities. Rather than exploiting a weakness for financial gain, researchers can disclose the problem to the project and receive compensation based on the severity of the finding.
For blockchain projects, these programs provide an additional layer of protection after an audit has been completed — a particularly important safeguard because software evolves continuously. Developers may introduce new contracts, modify existing code, or add features after an initial security assessment. A protocol considered secure months earlier may face a different risk profile following subsequent updates. Independent researchers can help identify these newly introduced weaknesses.
374 Threats Prevented in July
Immunefi reported that its bug bounty programs helped prevent 374 threats during July, compared with 317 prevented threats in June and 339 in May. The upward trend suggests that independent security research continues to play an increasingly important role in identifying vulnerabilities before exploitation.
The figures also demonstrate why bug bounty programs have become commonplace throughout the Web3 industry. A project may invest significant resources in a formal pre-launch audit, but that assessment captures only a specific point in time. As protocols evolve, new vulnerabilities can emerge, making continuous monitoring and responsible disclosure valuable complements to traditional security assessments.
Cumulative Researcher Payouts Reach $143.1 Million
Immunefi reported that cumulative payouts to security researchers reached $143.1 million by the end of July, representing the total amount paid to researchers who identified and reported vulnerabilities through the platform's programs.
The growing value of these payouts reflects the increasing importance of independent security researchers in the cryptocurrency ecosystem. For skilled researchers, blockchain protocols offer a unique environment where a single vulnerability can expose large pools of capital. For projects, compensating researchers for responsible disclosure can be far less costly than dealing with a successful exploit.
This incentive structure creates a direct economic relationship between security researchers and blockchain developers — researchers are rewarded for discovering weaknesses, while projects gain the opportunity to address them before malicious actors can intervene.
Why a Single Audit May Not Suffice
The central takeaway from Immunefi's analysis is not that conventional audits should be discarded. Rather, the data suggests that blockchain projects benefit from combining multiple security approaches. A private audit provides a structured examination by an experienced team. Competitive audits introduce multiple independent perspectives. Bug bounty programs enable ongoing vulnerability discovery after deployment.
Together, these methods create a more comprehensive security framework. This layered approach is increasingly relevant as blockchain applications grow more complex. Modern DeFi protocols can contain lending mechanisms, liquidity pools, governance systems, cross-chain functionality, price oracles, and automated smart contracts. A vulnerability may not reside within any single component but instead emerge from the interaction of several systems. Multiple researchers examining the same protocol increase the likelihood that unusual attack paths are discovered.
Attackers' Financial Incentives
The cryptocurrency industry presents an unusual security environment because attackers can potentially move large amounts of capital without physical access to any facility. Smart contract vulnerabilities can sometimes be exploited remotely, and once funds are transferred, blockchain transactions can be difficult or impossible to reverse.
Attackers also have strong financial incentives to search for weaknesses before legitimate researchers discover them, creating a continuous race among developers, security researchers, and malicious actors. The estimated $24.5 million average cost associated with attacker-first discovery of a critical vulnerability demonstrates how expensive losing that race can be. For a protocol managing substantial user deposits, a single exploit can threaten a project's reputation, liquidity, and long-term viability.
Evolving Approaches to Blockchain Security
Immunefi's findings point toward a broader shift in how blockchain projects approach cybersecurity. Rather than treating an audit as a one-time certification of safety, developers may increasingly view security as an ongoing process encompassing pre-launch audits, competitive code reviews, formal verification, automated testing, bug bounty programs, and continuous monitoring.
Each layer addresses different risks. Competitive audits bring multiple perspectives to the same code. Bug bounty programs attract researchers from outside the original audit team. Continuous monitoring helps identify suspicious activity after a protocol goes live. No single method can guarantee that a project will never be exploited, but combining different security mechanisms makes it significantly harder for vulnerabilities to remain undiscovered.
Practical Lessons for Crypto Projects
For cryptocurrency developers, Immunefi's data offers several practical takeaways. First, security assessments should not necessarily end after a single private audit — additional independent reviews can uncover issues missed during earlier assessments. Second, bug bounty programs provide an ongoing channel for vulnerability disclosure. Third, projects should recognize that the cost of prevention is often substantially lower than the potential cost of an exploit. Finally, developers should avoid treating an audit report as definitive proof that a protocol is completely secure. Audits identify risks based on the code and assumptions examined at a particular point in time and cannot eliminate every possible attack vector.
Key Figures
The cryptocurrency industry lost approximately $110 million to hackers in July, underscoring the financial consequences of security failures across blockchain networks and applications. Immunefi's analysis found that competitive audit reviews uncovered considerably more serious vulnerabilities per engagement than conventional tier-1 audits — an average of 6.2 serious bugs through competitions versus 1.5 through traditional audits.
The cost comparison was equally notable: finding a critical vulnerability through a competitive audit averaged about $6,548, compared with roughly $66,000 through a private tier-1 audit. Meanwhile, independent researchers earned $2.32 million in rewards during July, with Immunefi reporting 374 prevented threats during the month and cumulative researcher payouts reaching $143.1 million.
For an industry where a single coding error can expose millions of dollars in digital assets, the difference between finding a vulnerability first and discovering it after an attack can be measured not only in security reports but in millions of dollars.