cleartext

Independent, sourced crypto news. No paid placements.

security

Immunefi puts July crypto hack losses at $110 million — and uses the occasion to market its audit competitions

Immunefi says crypto lost about $110 million to hacks in July and paid researchers $2.32 million, in a statement that also markets its own audit-competition product against rival auditors.

Crypto lost roughly $110 million to hacks in July, according to a statement issued Monday by bug bounty platform Immunefi and reported by The Block. The same statement bundled the loss tally with a set of numbers arguing that Immunefi's own audit product outperforms established audit firms — a distinction worth holding onto, because the two claims carry very different evidentiary weight.

The verifiable-ish operational figures first. Immunefi said researchers were paid $2.32 million for confirmed bugs during July, and that the number of bug bounty reports confirmed and paid rose 18%. It said 374 threats were prevented through its bounty programs during the month, up from 317 in June and 339 in May. Cumulative researcher payouts since the platform's launch reached $143.1 million, against $140.8 million in June — a month-over-month increase that reconciles with the $2.32 million July payout figure.

The comparative claims are where the marketing lives. Immunefi said it reviewed 1,178 "tier-1" audits and found a median of zero critical or high-severity bugs per engagement. Against that, it set 58 of its own audit competitions, which it said surfaced an average of 6.2 serious bugs per engagement versus 1.5 for tier-1 audits. It further put the cost of finding a critical bug at $6,548 in an audit competition, about $66,000 in a private tier-1 audit, and $24.5 million when an attacker finds it first.

Key facts

  • ~$110 million lost to crypto hacks in July 2026 — Immunefi, via The Block (Aug. 10, 2026)
  • $2.32 million paid to researchers for confirmed bugs in July; confirmed-and-paid reports up 18% — Immunefi
  • 374 threats prevented in July, vs 317 in June and 339 in May — Immunefi
  • Cumulative researcher payouts $143.1 million, up from $140.8 million — Immunefi
  • 1,178 tier-1 audits reviewed: median zero critical/high bugs; 58 Immunefi competitions averaged 6.2 serious bugs vs 1.5 for tier-1 audits — Immunefi
  • Cost per critical bug: $6,548 (competition), ~$66,000 (private tier-1 audit), $24.5 million (found by attacker) — Immunefi

The real-world read

Every number here traces back to a single interested party describing its own product. Immunefi sells audit competitions; the study finding that audit competitions beat auditors is Immunefi's, run by Immunefi, with no published methodology, no named tier-1 firms, and no independent replication.

The $24.5 million line is the tell. That is an average exploit loss, not a discovery cost, and setting it beside a $6,548 bounty fee compares a fee schedule to a catastrophe. The tier-1 comparison also skips confounders: audits and competitions don't run on the same codebases at the same maturity, and "median zero criticals" may mean an auditor found nothing because a prior review already had.

Conspicuously absent: any breakdown of the $110 million — no incidents named, no protocols, no split between exploits, key compromises and fraud. "374 threats prevented" is unauditable by construction; a threat that was prevented leaves no public trace. Immunefi did not disclose how the tier-1 audit sample was assembled.

Opinion, and whose

The claim that competitions find more serious bugs at lower cost than tier-1 audits is Immunefi's position, not an established finding. No independent security researcher or rival audit firm is on record responding to it.

Sources

  • The Block, Brian Danga (Aug. 10, 2026) — reporting on Immunefi's Monday statement; all figures cited are attributed by The Block to Immunefi. The Block discloses that Foresight Ventures has been its majority investor since November 2023.
  • Immunefi's statement (primary, but interested) — the source of every figure above, including the audit comparison, which functions as promotion for the firm's own audit-competition business.

Not financial advice.