Bitcoin
Crypto Attackers Stole $110 Million in July as Security Researchers Flag Hundreds of Threats
Crypto attackers stole roughly $110 million in July 2026, while Immunefi researchers prevented 374 threats and received more than $2.32 million through bug bounties and audit competitions. The report also highlights a sharp cost gap between finding vulnerabilities early and discovering them after an exploit.
Crypto attackers stole roughly $110 million in July 2026, while security researchers identified and prevented hundreds of additional threats before they could potentially turn into costly exploits, according to a new report from blockchain security platform Immunefi.
Immunefi’s July 2026 Ecosystem Update found that researchers working through its platform prevented 374 threats during the month and received more than $2.32 million through bug bounty programs and audit competitions.
The findings underline a persistent challenge for the cryptocurrency industry. Blockchain networks, smart contracts, wallets, exchanges and decentralized applications continue to attract attackers because successful exploits can provide access to large pools of digital assets, often within minutes.
The problem becomes more serious because, as The Crypto Encounter previously explained in its guide to irreversible crypto transactions, recovering digital assets after a successful transfer can be considerably harder than reversing fraudulent activity within conventional payment systems.
Crypto Hackers Stole About $110 Million in July
According to Immunefi, attackers stole approximately $110 million from the crypto ecosystem during July.
The figure arrived alongside another significant number: 374 potential threats were prevented by security researchers operating through Immunefi during the same period.
That contrast illustrates the two sides of the modern cryptocurrency security environment. Attackers continue searching for weaknesses capable of generating multimillion-dollar returns, while increasingly sophisticated security researchers attempt to identify those vulnerabilities before they can be exploited.
It also shows why describing crypto security simply in terms of whether a blockchain itself can be “hacked” misses much of the actual risk.
Cryptocurrency losses can originate from smart-contract vulnerabilities, compromised private keys, malicious wallet permissions, infrastructure failures, access-control weaknesses and attacks against people managing digital assets.
That distinction matters because a technically secure blockchain does not automatically make every crypto user or application safe. Security depends on multiple layers stretching from protocol code to wallets, devices, applications and individual behavior.
Paid Bug Bounty Reports Increased 18%
Activity across Immunefi’s security programs increased during July.
The number of confirmed and paid bug bounty reports rose 18% compared with June, according to the report.
The largest individual payment during the month reached $250,000 and was awarded for the discovery of a critical vulnerability.
Immunefi said cumulative payments to security researchers through its ecosystem have now reached approximately $143.1 million.
Five new bug bounty programs also launched during July, collectively offering another $465,000 in available rewards.
Bug bounty programs provide financial incentives for independent security researchers to investigate software, smart contracts and blockchain infrastructure and responsibly disclose qualifying vulnerabilities to the projects involved.
For cryptocurrency companies controlling substantial amounts of customer or protocol capital, such programs can provide an additional line of defense alongside development testing, internal reviews and professional security audits.
Immunefi Analyzes 1,178 Public Crypto Audits
One of the most notable sections of the July report deals with the effectiveness of different approaches to blockchain security auditing.
Immunefi analyzed 1,178 publicly available audits conducted by Trail of Bits, Zellic and OpenZeppelin and compared their findings with vulnerabilities identified through audit competitions conducted on its own platform.
According to Immunefi, its 58 audit competitions found an average of 6.2 serious vulnerabilities per engagement.
Traditional audits included in its comparison identified an average of 1.5 serious vulnerabilities per audit.
The difference is significant, although the figures should be interpreted carefully. Audit scope, project complexity, researcher numbers, methodology and vulnerability classifications may differ between engagements.
Traditional security audits also serve an important role and can involve detailed interaction between an audit team and a project’s developers. Audit competitions use a different model by allowing a larger pool of independent researchers to examine a codebase during a defined period.
Immunefi’s findings therefore strengthen the case for layered security rather than suggesting projects should depend exclusively on one audit model.
What Are Crypto Audit Competitions?
An audit competition allows multiple independent security researchers to examine the same protocol or codebase and compete to identify vulnerabilities.
Researchers are generally rewarded according to the validity and severity of their discoveries.
The model can expose software to a wider collection of skills, attack methods and technical perspectives than a security review conducted by a relatively small team.
This approach may be particularly useful in decentralized finance, where smart contracts can control large pools of assets and interact with multiple protocols simultaneously.
A weakness in one contract can sometimes create consequences elsewhere through integrations, liquidity pools, bridges, lending markets or automated transactions.
As The Crypto Encounter has examined in its coverage of the security gap between crypto experts and ordinary users, technical complexity can also make it difficult for users to understand exactly where their exposure begins and ends.
Base Azul and Firedancer V1 Pay About $750,000
Two audit competitions stood out during July.
Immunefi said competitions involving Base Azul and Firedancer V1 distributed approximately $750,000 across 606 paid findings.
The volume of compensated discoveries provides another indication of the growing professional market around proactive crypto security.
Developers increasingly face a basic economic calculation: pay researchers to find weaknesses before deployment or potentially face far greater financial losses if attackers discover those weaknesses first.
Finding a Critical Vulnerability Can Cost $6,548. Missing It Can Cost Millions
Perhaps the clearest economic argument in Immunefi’s report comes from its comparison of vulnerability-discovery costs.
The company estimated that the average cost of identifying a critical vulnerability through an audit competition was approximately $6,548.
Immunefi compared that with approximately $66,000 through a private tier-one security audit.
The financial difference becomes dramatically larger when the security community fails to discover the vulnerability first.
According to Immunefi’s calculations, the average cost when a vulnerability was discovered by an attacker reached approximately $24.5 million.
The comparison illustrates why preventative spending can look expensive before an attack but relatively modest afterward.
A $50,000, $100,000 or even $250,000 bounty may initially appear substantial. If the vulnerability could otherwise expose tens of millions of dollars in assets, the cost changes considerably when viewed as insurance against catastrophic loss.
Why Crypto Security Needs More Than One Audit
Blockchain applications rarely remain static after launch.
Developers introduce new features. Protocols integrate with other platforms. Governance decisions modify systems. Smart contracts receive upgrades, and new bridges or liquidity sources connect previously separate ecosystems.
Each change can alter the security environment.
That means a successful audit at launch should not necessarily be treated as permanent proof that a project will remain secure indefinitely.
Strong security programs increasingly combine several layers:
- internal code reviews;
- independent security audits;
- audit competitions;
- ongoing bug bounty programs;
- real-time monitoring;
- access-control protections;
- incident-response procedures; and
- continuous testing after major upgrades.
The principle also applies at the individual-user level. A protocol may operate correctly while a user still authorizes a malicious transaction.
As our analysis of why a technically valid crypto transaction can still be fraudulent explains, blockchains generally determine whether a transaction contains valid authorization. They cannot determine whether the person signing it was deceived beforehand.
Crypto Attackers Do Not Always Need to Break a Blockchain
The word “hack” can create the impression that attackers routinely break the cryptography protecting major blockchain networks.
Real-world cryptocurrency theft is considerably more diverse.
Attackers may compromise administrator credentials, exploit smart-contract logic, steal private keys, manipulate application interfaces or convince users to approve malicious wallet requests.
Phishing and impersonation attacks can be particularly effective because criminals may only need legitimate authorization from the victim.
A deceptive wallet prompt, fake support page or fraudulent application can generate a transaction that appears completely valid to the underlying blockchain.
The Crypto Encounter explored this problem in our investigation into the limits of encrypted crypto payments, including how attackers can exploit wallet approvals without defeating blockchain cryptography.
Password and Account Security Remain Part of the Attack Surface
Not every attack requires a sophisticated smart-contract exploit either.
Some criminals can achieve their objective by gaining access to an email account, exchange login, cloud account or device connected to cryptocurrency assets.
This is why strong passwords, multifactor authentication, secure recovery procedures and careful account management remain important even in an industry built around advanced cryptography.
As The Crypto Encounter has previously reported in Crypto’s Password Problem Is Bigger Than People Think, attackers frequently target the weakest accessible layer rather than attempting to defeat the strongest one.
For some victims, that weakest layer may be an exposed password or recovery phrase rather than Bitcoin or Ethereum itself.
The Myth of the “Unhackable” Blockchain
July’s $110 million loss figure also demonstrates why statements describing cryptocurrency as either completely secure or fundamentally insecure tend to oversimplify the issue.
A blockchain network can maintain its cryptographic integrity while applications operating on top of it remain vulnerable.
The user’s wallet can also be compromised while the blockchain behaves exactly as intended.
Similarly, a scammer can persuade a victim to authorize a transfer without exploiting any technical vulnerability at all.
The distinction is central to understanding modern digital-asset security and is explored further in The Crypto Encounter’s examination of the “unhackable blockchain” myth.
Crypto security therefore works more like a chain than a single wall. Its strength depends on networks, contracts, applications, infrastructure, credentials and people operating together.
Security Researchers Receive Growing Community Support
Immunefi also reported increasing activity around its researcher ecosystem during July.
Community members pledged approximately 38.2 million IMU behind 305 security researchers, representing 46% month-over-month growth, according to the company.
The figures indicate that security research is developing into an increasingly structured economy of its own within the broader cryptocurrency sector.
Protocols have incentives to protect capital. Researchers have incentives to find flaws before attackers. Communities have incentives to support researchers with strong records.
That alignment becomes increasingly important as the value and complexity of onchain systems expand.
What Immunefi’s July Report Tells Us About Crypto Security
The July numbers reveal two security trends operating at the same time.
Attackers remain capable of extracting enormous amounts of money from vulnerable cryptocurrency systems. Approximately $110 million disappeared through attacks during a single month.
At the same time, professional researchers are finding vulnerabilities that may never become headline-grabbing exploits precisely because somebody identified them early.
Immunefi recorded 374 prevented threats during July. The financial value of attacks that never happened because of those discoveries is much harder to calculate.
The report therefore raises an important question for cryptocurrency developers and investors: how much security testing is enough when a protocol controls millions or billions of dollars?
There is unlikely to be one answer for every project.
A relatively simple blockchain application has different security requirements from a cross-chain bridge, decentralized exchange, derivatives platform or lending protocol managing enormous pools of user capital.
What is becoming harder to defend is the assumption that one audit, conducted at one moment in a project’s development, can guarantee long-term security.
The Bigger Picture
Crypto’s security challenge increasingly comes down to economics as much as technology.
Attackers have powerful financial incentives to search continuously for vulnerabilities. A single successful exploit can generate millions of dollars.
The defensive side therefore needs equally strong incentives for talented researchers to identify those flaws first.
Bug bounties and audit competitions attempt to change that equation by making responsible vulnerability disclosure financially worthwhile.
July’s numbers show why that race matters.
The approximately $110 million already stolen represents the visible cost of security failures. The hundreds of threats identified by researchers represent the less visible side of the equation: incidents that may have become the next major crypto hack but never reached that stage.
For protocols, exchanges, developers and users, that may be the most important lesson from Immunefi’s July report. Security is no longer something that can be checked once and considered finished.
In an ecosystem where software moves money automatically and transactions can become irreversible within minutes, vulnerability discovery has to happen before attackers get there.