CertiK reports $187.7M in exploit losses during July, with the five largest incidents accounting for over $116M.
Security & Exploits ·
Security auditor CertiK documented $187.7M in cryptocurrency losses from exploits during July, with the five most severe incidents representing more than $116M of that total. The analysis tracked vulnerabilities weaponized across on-chain systems and user endpoints during the month.
Exploits in crypto leverage gaps in smart contract code, bridge infrastructure, or user behavior to redirect funds or seize control of protocols without authorization. These attacks differ from ordinary software bugs in that they represent deliberate, economically motivated weaponization of latent weaknesses—flaws that may exist undetected for extended periods before attackers discover scalable methods to extract value. Damage spans direct asset theft, liquidity disruption, and erosion of user confidence.
The concentration of losses in a small number of incidents underscores how certain vulnerabilities carry outsized systemic risk. What remains unclear is the breakdown of these five largest cases by protocol type, blockchain, or attack vector, and whether the remaining $71.7M reflected numerous smaller compromises or a different loss distribution pattern.