Hooded figure viewed from behind sitting at multiple monitors showing code and a world map
TECHNOLOGY

Crypto Hacks Cost $110 Million in July as Bug Bounty Payouts Rise 18%

Image Credit: Shutterstock

Key Takeaways

  • Crypto hacks cost approximately $110 million in July, far exceeding the $2.32 million paid to researchers through bug bounty programs.
  • Audit competitions found more than four times as many serious bugs as private audits, at roughly one-tenth the cost per critical bug found.
  • Researchers prevented 374 threats in July, the third straight monthly increase, as cumulative bounty payouts reached $143.1 million.

The crypto industry lost approximately $110 million to hacks and exploits in July, according to data from security platform Immunefi. At the same time, bug bounty activity strengthened, with confirmed and paid vulnerability reports rising 18% during the month, the company said.

Bug Bounty Activity Climbs as Exploits Continue

Researchers earned $2.32 million in July for identifying verified vulnerabilities through Immunefi’s bounty programs, the company said. The increase in paid reports comes as more security researchers are actively probing crypto protocols for weaknesses, even as attackers continue extracting nine-figure sums from the same ecosystem.

The gap between what defenders earn for finding flaws and what attackers steal by exploiting them remains wide. July’s $110 million in losses far exceeds the $2.32 million paid out to researchers during the same period. 

Immunefi said a similar gap has appeared in most months this year, which is why bug bounty programs are typically framed as a complement to, rather than a replacement for, other security layers such as audits and monitoring.

Audit Competitions Find More Bugs Than Private Reviews

Immunefi’s data points to a meaningful gap between two common approaches to code review. The company reviewed 1,178 top-tier private audits and found a median of zero critical or high-severity bugs per engagement. 

Its 58 audit competitions, structured contests in which multiple independent researchers compete to find vulnerabilities in the same codebase, found an average of 6.2 serious bugs per engagement, more than four times the 1.5 average found in private audits.

The cost difference was also substantial. Audit competitions averaged $6,548 to identify a single critical bug, according to Immunefi, compared with roughly $66,000 for private top-tier audits, a ratio of roughly ten to one. 

The figures show that audit competitions surfaced more serious flaws at a lower cost per discovery than private audits in this dataset. The two approaches are not necessarily interchangeable, since private audits typically offer more structured, confidential engagement for pre-launch code.

Prevented Threats Climb for a Third Straight Month

Researchers working through Immunefi’s bounty programs prevented 374 threats in July before they could be exploited, the company said. That figure has climbed steadily, up from 339 in May and 317 in June. Immunefi attributed the increase to either a growing volume of vulnerability submissions, improved detection capability, or both.

Cumulative payouts to researchers through Immunefi’s platform have reached $143.1 million to date, the company said. That total reflects years of accumulated bounty activity across the protocols using the platform, rather than a single-year or single-month figure.

Two Trends Emerge From July’s Security Data

The July figures show two parallel trends. Losses from successful exploits remain large and persistent, while the infrastructure built to catch vulnerabilities before attackers do appears to be catching more threats over time. 

Whether that translates into lower losses over a longer horizon is not yet established by a single month of data, and Immunefi’s figures reflect its own platform’s coverage rather than the industry as a whole.

The cost comparison between audit competitions and private reviews could matter most for protocol teams weighing how to allocate security budgets. That question carries particular weight for smaller projects operating with limited runway, in a year that has already seen more than 100 crypto projects shut down or fold.

More For You

Explore More News