Summary Crypto hackers stole roughly $110 million in July, highlighting persistent security vulnerabilities affecting blockchain projects despite widespread use of audits. Immunefi found audi
Summary
- Crypto hackers stole roughly $110 million in July, highlighting persistent security vulnerabilities affecting blockchain projects despite widespread use of audits.
- Immunefi found audit competitions uncovered 6.2 serious bugs per engagement, compared with only 1.5 vulnerabilities found through traditional tier-one audits.
- Bug bounty programs prevented 374 threats, while researcher payouts reached $143.1 million as projects invested further in identifying vulnerabilities before exploitation.
Crypto hackers stole roughly $110 million in July, while Immunefi identified major weaknesses in traditional security audits used across blockchain projects. The cybersecurity platform found that competitive audit reviews uncovered substantially more serious vulnerabilities than conventional tier-1 audits.
According to Immunefi, its review of 1,178 tier-1 audits found a median of zero critical or high-severity vulnerabilities, while 58 audit competitions revealed significantly more serious security weaknesses. Those competitions uncovered an average of 6.2 serious bugs per engagement, compared with only 1.5 during traditional tier-1 audits. The findings highlight a substantial gap between both security approaches as cryptocurrency platforms remain attractive targets for sophisticated attackers.
Moreover, Immunefi reported stronger activity among independent researchers working through its bug bounty programs to identify potentially costly security weaknesses. Researchers received $2.32 million for confirmed vulnerabilities during July, while confirmed and paid bug bounty reports increased by 18%.
Immunefi also recorded 374 prevented threats through its bug bounty programs, compared with 317 in June and 339 in May. Cumulative researcher payouts reached $143.1 million, rising from the $140.8 million recorded at the end of June.
Also Read: Binance Bitcoin Traders Outpace Hyperliquid by 4,753% as Buying Pressure Surges
Audit Competitions Find More Serious Vulnerabilities
Immunefi’s comparison showed that competitive audits uncovered more serious vulnerabilities per engagement than conventional private security assessments. Audit competitions allow multiple independent researchers to examine the same project and search for vulnerabilities across different potential attack paths.
Consequently, projects can receive broader security scrutiny instead of depending entirely on findings produced through a traditional private audit. The cost difference between both approaches also formed a significant part of Immunefi’s findings on cryptocurrency security practices.
Finding one critical vulnerability through an audit competition cost an average of $6,548, based on Immunefi’s analysis. By comparison, identifying a critical bug through a private tier-1 audit carried an average cost of approximately $66,000. That difference becomes considerably larger when malicious actors discover vulnerabilities before legitimate researchers can identify and report them.
Undetected Bugs Carry Much Higher Costs
Immunefi estimated that attacker-first discovery of a critical vulnerability generated an average cost of approximately $24.5 million. Therefore, vulnerabilities missed during security reviews can become considerably more expensive once attackers successfully exploit weaknesses within blockchain applications.
The $110 million stolen during July demonstrates the financial consequences that security failures can create across cryptocurrency platforms. Additionally, the 374 prevented threats show how bug bounty researchers can identify weaknesses before attackers turn vulnerabilities into damaging exploits.
Immunefi’s figures also suggest that relying on traditional audits alone may leave some serious vulnerabilities undiscovered despite substantial security spending. Competitive audits provide another layer of scrutiny by bringing several researchers into the vulnerability discovery process for individual blockchain projects.
Immunefi’s findings reveal a notable difference between traditional audits and competitive reviews in detecting serious vulnerabilities across cryptocurrency projects. With hackers stealing roughly $110 million in July, effective vulnerability discovery remains critical for limiting costly exploits across the crypto industry.
Also Read: Vitalik Buterin Reveals Major Ethereum Shift Toward Privacy and Quantum Security
The post Crypto Hacks Drain $110M as Immunefi Exposes Major Flaws in Traditional Audits appeared first on 36Crypto.