Why did cryptocurrency hacking lose US$110 million?
The cryptocurrency project lost approximately US$110 million due to hacking in July. Although the Vulnerability Bounty Program discovered more vulnerabilities before attackers exploited them, cybersecurity risks remain high. Immunefi said the number of bug bounty reports confirmed and paid out increased by 18% that month, and researchers received $2.32 million for effective discoveries. The cybersecurity platform also reported that 374 threats were blocked through its bounty program, up from 317 in June and 339 in May.
These data indicate that there is still a persistent gap between the vulnerabilities discovered by security researchers and the vulnerabilities discovered by attackers first. Although the bounty program can reduce losses by rewarding responsible disclosure, the $110 million stolen in July shows that exploitable vulnerabilities remain a major cost facing cryptocurrency protocols and their users.
For investors, the problem is not limited to individual hacking incidents. Security breaches could drain the protocol's cash pool, weaken token prices, disrupt operations, and force project parties to compensate users. As a result, the financial impact may well exceed the value of the direct theft.
Did the audit competition reveal more serious vulnerabilities?
Immunefi said its review of 1178 level one audits found a median of zero critical or high-risk vulnerabilities. The platform compared it with the results of 58 audit competitions conducted through its own platform, which found more serious flaws each time they participated. The company said an average of 6.2 critical vulnerabilities were found per audit competition, compared with an average of 1.5 for a level one audit. This comparison suggests that opening code review to a wider community of security researchers may reveal vulnerabilities missed by smaller private audit teams.
Audit competitions typically allow multiple researchers to independently review project codes and compete for rewards. This structure can expose the same codebase to different attack methods and expertise, potentially increasing the chances of discovering complex vulnerabilities before deployment. Traditional private audits still have value by reviewing architecture, testing implementation, and providing structured security feedback to development teams. However, the findings suggest that projects may benefit from combining private audits with a broader bounty program, rather than viewing a single security review as adequate protection.
Investor revelation
The cost difference between discovering a vulnerability before it is exploited and discovering it after it is exploited. Projects that invest more in competitive security reviews and vulnerability bounties may have lower financial risks than agreements that rely mainly on one-time private audits.
How much does it cost to discover a key cryptocurrency vulnerability?
Immunefi estimates that the average cost of discovering a critical vulnerability through an audit competition is $6548. By comparison, the cost of discovering similar vulnerabilities through a private-level audit is approximately $66,000. When attackers first discover the vulnerability, the financial difference becomes even greater. Immunefi estimates that when critical vulnerabilities are exploited before they are discovered by security researchers, the average cost is $24.5 million. This comparison changes the economics of security investment. Projects may consider audit fees or reward rewards expensive until the vulnerability is discovered, but these costs may be negligible compared to the losses caused by exploiting the vulnerability, the cost of Incident Response Service, and the damage to user confidence. The data also helps explain why vulnerability bounty programs have become an important part of the cryptocurrency security budget. Paying thousands or even hundreds of thousands of dollars for a critical discovery is still more cost-effective than losing millions of dollars through smart contract vulnerabilities or compromised infrastructure.
What does rising researcher activity mean for cryptocurrency security?
Immunefi's cumulative researcher spending reached $143.1 million in July, up from $140.8 million in June. This increase suggests that the protocol continues to invest heavily in external researchers who discover vulnerabilities before they are exploited. The number of threats blocked increased from 317 in June to 374 in July, which also suggests that researchers are more active or that more vulnerabilities are entering the bounty program. Either explanation is crucial to investors because it shows that security risks are still active even if major hacking incidents do not dominate the market. Vulnerability bounty programs can improve defenses, but they do not eliminate the need for secure development practices, internal testing, and independent audits. Some vulnerabilities may not be discovered until the contract is exposed to real market conditions or integrated with other agreements. The broader lesson learned in July is that cryptocurrency security increasingly relies on layered defenses. Projects that combine internal review, private audits, competitive testing and ongoing bounty programs have more opportunities to identify weaknesses before attackers do. Given that $110 million is still lost in a single month to hacking, security issues in the industry remain costly. However, the growing number of confirmed bounty reports suggests that more vulnerabilities are being translated into compensation for researchers rather than exploitation losses, providing a financial reason for the agreement to expand defense investment before attackers can reap greater rewards.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following