
July's $110M in crypto hacks pushed 2026 losses higher; Immunefi found audit competitions uncover 6.2 serious flaws per engagement vs 1.5 for private audits, at a fraction of the cost.
Crypto projects lost roughly $110 million to hacks in July, according to data from the security platform Immunefi. The month added to a year that has already seen $1.1 billion in crypto security losses during the first six months, as reported by Blockaid.
Immunefi recorded 164 crypto hacks through Aug. 3, including 67 incidents that each caused more than $1 million in losses. The company projects that the number of such major incidents could reach 114 by the end of 2026, which would surpass the previous annual record of 72 set in 2024. Only 49 had been recorded by the same point that year.
Two large attacks drove July's total. Ostium lost 23.75 million USDC after an attacker compromised its off-chain infrastructure and manipulated price data. AFX suffered a separate $24.15 million bridge exploit. Together, the two accounted for more than $47 million in losses.
Immunefi said its researchers received $2.32 million for confirmed vulnerabilities in July. The number of reports that were both confirmed and paid rose 18% from the previous month. Its bug bounty programs prevented 374 threats, up from 317 in June and 339 in May. Cumulative payments to security researchers reached $143.1 million, compared with $140.8 million at the end of June.
The rise in submissions comes as artificial intelligence tools make it easier for researchers to scan code and prepare vulnerability reports. crypto.news previously reported that AI had driven a sharp increase in bug bounty submissions, though project teams also faced more low-quality reports and false positives.
Institutional interest in preventive security has grown. Anchorage Digital invested in Immunefi earlier this year as part of a strategic push into on-chain security infrastructure.
Immunefi reviewed 1,178 audits conducted by tier-1 security firms and found a median of zero critical or high-severity vulnerabilities. A comparison with 58 competitive audits produced a different result. Audit competitions identified an average of 6.2 serious vulnerabilities per engagement, compared with 1.5 in private tier-1 audits, Immunefi said. Competitive reviews involve multiple independent researchers examining the same code and receiving rewards based on the vulnerabilities they find.
The average cost of identifying a critical flaw through an audit competition was $6,548. That compared with about $66,000 through a private tier-1 audit and an estimated $24.5 million when an attacker discovered the vulnerability first.
Recent incidents have shown that completed security reviews do not guarantee code is free from exploitable flaws. A crypto.news investigation into the Coldcard breach found that an AI-assisted audit identified another 85 critical bugs across Bitcoin-related projects after a firmware weakness exposed wallet users.
Immunefi's findings suggest that projects may need continuous bug bounty programs and competitive reviews alongside conventional audits. With 2026 already approaching the record for major incidents, the cost gap between preventive research and live exploitation remains substantial.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.