Crypto projects suffered roughly $110 million in losses from hacks in July, according to data cited by security platform Immunefi, adding to what is already an expensive year for the sector. The company also reported a rise in confirmed bug bounty reports and said competitive audit formats are finding more serious vulnerabilities than traditional private reviews.
Immunefi’s latest figures suggest 2026 is tracking toward a record year for large crypto security incidents. Through Aug. 3, the platform had logged 164 hacks, including 67 cases where losses exceeded $1 million.
Major incidents are accumulating faster than in prior years
Immunefi projects that the number of hacks causing more than $1 million in losses could reach 114 by the end of 2026. If that happens, it would surpass the current annual record of 72 major incidents set in 2024. By the same stage in 2024, only 49 such incidents had been recorded, underscoring how much faster this year’s tally has grown.
July’s losses came on top of a difficult first half for the industry. A separate report from Blockaid recently estimated that crypto security losses reached $1.1 billion in the first six months of 2026, placing the latest monthly total within a broader pattern of heavy damage across the sector.
Two July attacks made up a large share of the month’s losses
Among the largest incidents, Ostium lost 23.75 million USDC after an attacker compromised off-chain infrastructure and manipulated the price data used by the protocol. In a separate event, AFX was hit by a bridge exploit that caused losses of $24.15 million.
Taken together, those two attacks accounted for more than $47 million of the roughly $110 million lost during July, meaning a substantial part of the month’s damage came from a small number of large breaches.
Bug bounty activity and payouts moved higher
Immunefi said its researchers received $2.32 million in July for confirmed vulnerabilities. The number of reports that were both validated and paid increased 18% from the previous month, while the company said its bug bounty programs prevented 374 threats, up from 317 in June and 339 in May.
Cumulative payouts to security researchers rose to $143.1 million, compared with $140.8 million at the end of June. Immunefi linked the broader rise in reporting to easier code analysis and report preparation with artificial intelligence tools. Earlier reporting by crypto.news said AI had helped drive a sharp increase in submissions, even as project teams dealt with more low-quality reports and false positives.
Institutional interest in preventive security has also expanded. Earlier this year, Anchorage Digital invested in Immunefi as part of what was described as a strategic move into on-chain security infrastructure.
Competitive audits surfaced more severe bugs than private reviews
Immunefi said its review of 1,178 audits from tier-1 security firms showed a median of zero critical or high-severity vulnerabilities. By contrast, when the company compared those results with 58 competitive audits, it found that audit competitions identified an average of 6.2 serious vulnerabilities per engagement, versus 1.5 in private tier-1 audits.
In this model, several independent researchers examine the same codebase and are rewarded according to the vulnerabilities they uncover. Immunefi estimated that finding a critical flaw through an audit competition cost $6,548 on average, compared with about $66,000 through a private tier-1 audit and an estimated $24.5 million when attackers found the weakness first.
Security reviews remain only one layer of defense
Recent incidents, the company said, show that completed audits do not guarantee code is free of exploitable weaknesses. It pointed to an AI-assisted audit that later identified another 85 critical bugs across Bitcoin-related projects after a firmware weakness exposed wallet users.
The findings support a broader argument from Immunefi that conventional audits may need to be supplemented with ongoing bug bounty programs and competitive reviews. With the count of major incidents already nearing the previous record pace, the next confirmed step for projects is likely to be how they expand preventive security efforts before more vulnerabilities are exploited in production.
Source: crypto.news