EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Cryptocurrency hacking caused approximately US$110 million in losses...

2026-08-11 12:26:23
Bookmark

Why did cryptocurrency hacking lose US$110 million?

The cryptocurrency project lost approximately US$110 million due to hacking in July. Although the Vulnerability Bounty Program discovered more vulnerabilities before attackers exploited them, cybersecurity risks remain high. Immunefi said the number of bug bounty reports confirmed and paid out increased by 18% that month, and researchers received $2.32 million for effective discoveries. The cybersecurity platform also reported that 374 threats were blocked through its bounty program, up from 317 in June and 339 in May.

These data indicate that there is still a persistent gap between the vulnerabilities discovered by security researchers and the vulnerabilities discovered by attackers first. Although the bounty program can reduce losses by rewarding responsible disclosure, the $110 million stolen in July shows that exploitable vulnerabilities remain a major cost facing cryptocurrency protocols and their users.

For investors, the problem is not limited to individual hacking incidents. Security breaches could drain the protocol's cash pool, weaken token prices, disrupt operations, and force project parties to compensate users. As a result, the financial impact may well exceed the value of the direct theft.

Did the audit competition reveal more serious vulnerabilities?

Immunefi said its review of 1178 level one audits found a median of zero critical or high-risk vulnerabilities. The platform compared it with the results of 58 audit competitions conducted through its own platform, which found more serious flaws each time they participated. The company said an average of 6.2 critical vulnerabilities were found per audit competition, compared with an average of 1.5 for a level one audit. This comparison suggests that opening code review to a wider community of security researchers may reveal vulnerabilities missed by smaller private audit teams.

Audit competitions typically allow multiple researchers to independently review project codes and compete for rewards. This structure can expose the same codebase to different attack methods and expertise, potentially increasing the chances of discovering complex vulnerabilities before deployment. Traditional private audits still have value by reviewing architecture, testing implementation, and providing structured security feedback to development teams. However, the findings suggest that projects may benefit from combining private audits with a broader bounty program, rather than viewing a single security review as adequate protection.

Investor revelation

The cost difference between discovering a vulnerability before it is exploited and discovering it after it is exploited. Projects that invest more in competitive security reviews and vulnerability bounties may have lower financial risks than agreements that rely mainly on one-time private audits.

How much does it cost to discover a key cryptocurrency vulnerability?

Immunefi estimates that the average cost of discovering a critical vulnerability through an audit competition is $6548. By comparison, the cost of discovering similar vulnerabilities through a private-level audit is approximately $66,000. When attackers first discover the vulnerability, the financial difference becomes even greater. Immunefi estimates that when critical vulnerabilities are exploited before they are discovered by security researchers, the average cost is $24.5 million. This comparison changes the economics of security investment. Projects may consider audit fees or reward rewards expensive until the vulnerability is discovered, but these costs may be negligible compared to the losses caused by exploiting the vulnerability, the cost of Incident Response Service, and the damage to user confidence. The data also helps explain why vulnerability bounty programs have become an important part of the cryptocurrency security budget. Paying thousands or even hundreds of thousands of dollars for a critical discovery is still more cost-effective than losing millions of dollars through smart contract vulnerabilities or compromised infrastructure.

What does rising researcher activity mean for cryptocurrency security?

Immunefi's cumulative researcher spending reached $143.1 million in July, up from $140.8 million in June. This increase suggests that the protocol continues to invest heavily in external researchers who discover vulnerabilities before they are exploited. The number of threats blocked increased from 317 in June to 374 in July, which also suggests that researchers are more active or that more vulnerabilities are entering the bounty program. Either explanation is crucial to investors because it shows that security risks are still active even if major hacking incidents do not dominate the market. Vulnerability bounty programs can improve defenses, but they do not eliminate the need for secure development practices, internal testing, and independent audits. Some vulnerabilities may not be discovered until the contract is exposed to real market conditions or integrated with other agreements. The broader lesson learned in July is that cryptocurrency security increasingly relies on layered defenses. Projects that combine internal review, private audits, competitive testing and ongoing bounty programs have more opportunities to identify weaknesses before attackers do. Given that $110 million is still lost in a single month to hacking, security issues in the industry remain costly. However, the growing number of confirmed bounty reports suggests that more vulnerabilities are being translated into compensation for researchers rather than exploitation losses, providing a financial reason for the agreement to expand defense investment before attackers can reap greater rewards.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP