
What happened
An Immunefi Research report based on five years of data shows that the damage to protocols from exploits is not limited to direct financial losses.
Why it matters
Understanding the full cost of a hack is critically important for protocol developers and investors, as direct financial losses are often just the tip of the iceberg, hiding deeper operational and reputational risks.
The research division of Immunefi has published an updated report for 2024–2025, analyzing the consequences of hacks in the blockchain environment. The document is based on aggregated data regarding onchain incidents accumulated over the past five years.
The authors of the study emphasize that the actual cost of exploiting a vulnerability for a crypto protocol significantly exceeds the sum of stolen assets. The report focuses on hidden costs and the long-term impact of such events on the viability of projects.
The material serves as an attempt to quantify the full spectrum of damage inflicted on the security of decentralized systems, going beyond the simple counting of stolen tokens.
Confirmed facts
- Immunefi Research published a report titled "What an Onchain Hack Actually Costs: 2024-2025 Update".
- The study is based on data regarding onchain incidents over a five-year period.
- The report claims that the real consequences of an exploit for a protocol extend beyond the amount of funds stolen by hackers.
Context
Security remains one of the main challenges in the crypto industry, where various auditing firms and bug bounty platforms strive to assess risks. This report adds a new layer of analysis, shifting the focus from immediate losses to cumulative damage.
What remains unknown
- What specific metrics, besides stolen funds, were used to calculate the total cost of the hack?
- What are the exact quantitative indicators of the hidden costs mentioned in the full text of the report?
- Does the study provide examples of specific protocols to illustrate these points?
AI analysis
Confidence: medium
Judging by the wording of the abstract, the study aims to change the paradigm of risk assessment in the industry. If previously the success or failure of protection was measured only by the volume of funds withdrawn by hackers, Immunefi's new approach likely includes factors such as the drop in user trust, the cost of emergency fixes, legal expenses, and loss of market share. This could lead to a revision of insurance strategies and the allocation of reserve funds by projects.
Strategic AI conclusion
A probable consequence of the publication will be an increase in demand for comprehensive security audits that consider not only the code but also the resilience of the protocol's business model to shocks. The next observable signal may be the emergence of new incident reporting standards that include expanded damage metrics. The main uncertainty lies in the methodology for calculating intangible losses, which remains unverified without access to the full text of the report.