Crypto ecosystem lost $110M to hacks in July; Immunefi's bug bounty competitions outperformed traditional tier-1 audits.
Security & Exploits ·
Crypto platforms and protocols sustained roughly $110 million in losses to hacks during July, according to reporting on the month's security incidents. Immunefi, a bug bounty platform, characterized its audit competition model as having outperformed tier-1 audits during the period, suggesting an alternative or complementary approach to traditional security review processes.
The comparison underscores a shift in how some projects are managing vulnerability detection. Rather than relying solely on established audit firms, bug bounty competitions distribute the security review process across a broader set of independent researchers, incentivizing discovery through reward structures tied to findings. The scale of July's losses and Immunefi's performance claims suggest the crypto sector continues to grapple with significant security gaps despite increasing investment in multiple verification methods.
What remains unclear is whether bug bounty outperformance reflects a fundamental advantage of the model, the particular audits being compared, or the specific attack vectors that emerged in July. The relationship between rising bug bounty activity and the overall $110 million in losses—whether one mitigated the other or they occurred across separate incidents—has not been detailed.