Key Highlights:
  • Crypto projects lost roughly $110 million to hacks in July, according to Immunefi.
  • Bug bounty programs prevented 374 threats during the month.
  • Immunefi says its audit competitions found significantly more serious vulnerabilities than traditional tier-1 audits.

The crypto industry lost roughly $110 million to hacks in July, according to cybersecurity platform Immunefi.

At the same time, Immunefi said its bug bounty programs prevented hundreds of potential attacks and researchers received $2.32 million for confirmed vulnerabilities.

The number of confirmed and paid bug bounty reports increased 18% during the month.

Immunefi also compared traditional security audits with its audit competitions. Its review of 1,178 tier-1 audits found a median of zero critical or high-severity vulnerabilities.

By comparison, 58 Immunefi audit competitions found an average of 6.2 serious bugs per engagement, compared with 1.5 for tier-1 audits.

The company said identifying a critical vulnerability through an audit competition cost an average of $6,548.

That compares with roughly $66,000 for a private tier-1 audit and $24.5 million when an attacker discovers the vulnerability first.

Immunefi's bug bounty programs prevented 374 threats in July, up from 317 in June and 339 in May.

Total payouts to security researchers have now reached $143.1 million.

The figures highlight the growing importance of bug bounty programs as crypto protocols continue to face large financial incentives for attackers. Finding vulnerabilities before they are exploited can save projects millions of dollars compared with dealing with an attack after the fact.