The $110M cost of finding bugs too late
Attackers took roughly $110 million in July while researchers received $2.32 million for confirmed vulnerabilities, according to the source report. The contrast is not a simple spending ratio—it is a test of whether protocols can turn discoveries into prevention.

- ~$110M
- July crypto attack losses
- $2.32M
- Paid for confirmed vulnerabilities
- 6.2 vs 1.5
- Serious flaws per cited audit format
The story in three answers
What happened
Immunefi recorded roughly $110 million in crypto losses from July attacks while paying researchers $2.32 million for confirmed vulnerabilities. Its audit competitions found 6.2 serious flaws per engagement, compared with 1.5 in conventional tier-one audits.
Why it matters
Audit competitions are surfacing more serious flaws per engagement than conventional audits, changing how protocols buy security.
What to watch
Whether higher bounty payments reduce repeat exploits and shorten the time between disclosure and remediation.
Two security numbers that measure different moments
The linked report says Immunefi recorded roughly $110 million in crypto losses from attacks during July. It also says researchers received $2.32 million for confirmed vulnerabilities. Placing the figures together is striking, but they sit on opposite sides of an incident: one measures harm after an attack, while the other rewards findings intended to prevent harm.
That means the figures should not be read as though every additional bounty dollar would have mechanically removed an equal amount of loss. Exploit outcomes depend on which vulnerability exists, how quickly it is found, the value exposed at that moment and whether the project can patch safely before an attacker acts.
The comparison is still useful because it forces security spending into the context of value at risk. A reward can look large as a standalone payment and small beside the assets a critical flaw could expose. The relevant question is whether the programme finds consequential issues early enough to reduce expected loss.
The winning security model is not the one that produces the longest findings list; it is the one that turns a serious discovery into a verified fix before an attacker turns it into a loss.
Crypto News Today Analysis
Why audit competitions are drawing attention
The same report describes an average of 6.2 serious flaws per audit-competition engagement, compared with 1.5 in conventional tier-one audits. A competition can invite a broader researcher pool to examine the same code in a defined period, potentially bringing more approaches and assumptions to the search.
The reported averages do not prove that competitions will outperform every conventional audit. Engagement scope, code maturity, severity definitions, researcher mix and sample selection can all affect how many issues are found. The comparison is observational in the source account, not a controlled demonstration of cause.
A sensible security programme does not have to turn the formats into rivals. A fixed audit team can build deep context, while a competition can widen the search before deployment or a major change. The stronger process is the one that connects multiple forms of review to decisive remediation rather than treating any completed audit as a safety certificate.
Finding a flaw is only the middle of the process
Discovery creates value only when the project validates the report, fixes the underlying issue and tests the repair. A slow or incomplete response can leave the same exposure open after a researcher has already done the difficult part. Protocols need clear ownership of each report and a route for urgent decisions.
Retesting matters because a rushed patch can move a vulnerability rather than eliminate it. Transparent learning matters because repeated exploit patterns suggest that lessons are not travelling between projects. The measure of a mature programme is not the length of its findings list but the time and quality of the path from disclosure to verified resolution.
That is also why bounty totals alone are an imperfect performance metric. A high payout may reflect an effective discovery programme, unusually risky code or both. Better reporting would connect the severity of confirmed issues with patch time, protected value and whether the same class of weakness reappears.
What the source reports
Immunefi recorded roughly $110 million in crypto losses from attacks during July, according to the source report.
1Researchers received $2.32 million for confirmed vulnerabilities in the period described.
1The reported audit-competition average was 6.2 serious flaws per engagement, compared with 1.5 for conventional tier-one audits.
1
What to watch now
- 01
Time from confirmed disclosure to patch and independent retest.
- 02
Repeat exploit patterns across projects that had already been audited.
- 03
Future comparisons that disclose sample size, severity definitions and project scope.



