July 2026 Crypto Security: $97M Lost as Off-Chain Hacks and Bridge Failures Dominate Threat Landscape
Key Takeaways
July 2026 saw $97M in crypto losses, driven by off-chain infrastructure breaches and cross-chain bridge exploits. Key incidents involved Ostium, AFX Trade, and BonkDAO, highlighting a shift from code vulnerabilities to governance and key management failur
Woofun AI reports that the cryptocurrency security landscape in July 2026 underwent a structural transformation, with total losses reaching approximately $97 million as attack vectors pivoted decisively away from smart contract code flaws toward off-chain infrastructure and governance failures. Data indicates that while the frequency of protocol-related security incidents dropped sharply to 14 from 67 in June, the severity of each event escalated, driving total losses up by 18.7% compared to the $81.
73 million recorded in the previous month. The financial impact was heavily skewed toward direct hack attacks and smart contract vulnerabilities, which accounted for roughly $94 million of the total, while phishing attacks contributed a comparatively smaller but still significant $3 million. This divergence highlights a critical trend: fewer but far more devastating breaches are now defining the threat environment, with cross-chain bridges and off-chain systems emerging as the primary targets for sophisticated adversaries.
The vulnerability of cross-chain bridges remained a persistent and costly liability, with platforms such as AFX Trade, Verus, and B² Network suffering coordinated or sequential attacks that collectively drained over $35 million in assets. The most significant incident involved AFX Trade, a decentralized perpetual contract exchange operating within the Arbitrum ecosystem, where attackers exploited a leak of private validator signature keys to authorize unauthorized withdrawals.
Because the smart contract logic correctly verified these stolen signatures, the breach was not a code failure but a key management catastrophe, resulting in the theft of approximately $24.15 million in USDC. These funds were bridged from Arbitrum to Ethereum, where they were liquidated at an average price of around $1,937 per token, ultimately consolidating into a single wallet holding 12,467.5 ETH. In response, AFX suspended the compromised bridge and offered a 30% bounty to facilitate fund recovery, underscoring the industry’s reliance on post-breach incentives rather than preventive security architecture.
Further compounding the bridge crisis, the Verus-Ethereum cross-chain bridge fell victim to a second attack on July 23, resulting in losses of approximately $7.55 million. This incident utilized the exact same contract vector and vulnerability type as a previous breach in May, demonstrating how unpatched flaws combined with newly deposited liquidity create recurring exposure windows. The attack fell squarely into the category of cross-chain bridge validation bypass, where attackers exploited the same entry point to siphon funds, highlighting a systemic failure in patching and monitoring protocols across the bridge ecosystem.
Simultaneously, B² Network on the BNB Chain suffered a distinct but related failure when attackers seized control of staking contract upgrade permissions, leading to the loss of approximately 8.591 million B2 tokens valued at around $3.86 million. The perpetrators converted these assets into 5,409 WBNB tokens, worth approximately $3.11 million, and began transferring them to Zcash via NEAR Intents. The B² Network team suspended staking functions and engaged in on-chain negotiations, offering to forego legal action if at least 10% of the stolen funds were returned within 24 hours, a desperate measure that reflects the limited recourse available in such key-compromise scenarios.
The intrusion into off-chain infrastructure reached new heights with the Ostium oracle manipulation attack on July 15, which resulted in losses of approximately $23.75 million. Ostium, an RWA perpetual trading protocol on Arbitrum, was compromised not through a smart contract bug or governance multisig breach, but via an intrusion into its off-chain price signing system. Attackers forged BTC/USD price data, artificially manipulating the Bitcoin price to around $5,000, and exploited this discrepancy to repeatedly open and close trades, draining approximately $23.
75 million in USDC from the OLP liquidity pool. Officials confirmed that user deposits remained unaffected and that trading resumed on July 23, but the incident exposed a critical gap in security standards: off-chain permission management lacked the robust protection mechanisms typically associated with on-chain multisig wallets. This breach illustrates how attackers are increasingly targeting the peripheral systems that feed data into smart contracts, bypassing the hardened code itself to achieve maximum financial impact.
Governance mechanisms also emerged as a primary attack vector, exemplified by the BonkDAO vote manipulation incident on July 6, which led to losses of approximately $20 million. Attackers invested around $4 million to purchase sufficient BONK tokens to influence the Solana Realms governance platform, which allowed proposals to pass with a mere 1% voting rate. By submitting and approving malicious proposals, the attackers transferred approximately 4.
426 billion BONK tokens from the BonkDAO treasury, exploiting a design flaw in the governance rules rather than a defect in the contract code. Immunefi noted that this pattern represents the most severe losses of 2026, where funds were lost due to inadequate voting thresholds and rule design rather than technical vulnerabilities. This incident underscores the growing risk of low-barrier governance structures, where minimal capital outlays can yield massive returns through social engineering and protocol exploitation.
Woofun AI data shows that oracle manipulation continued to plague lending protocols, as seen in the Bonzo Lend attack on July 11, which resulted in losses of approximately $9.05 million. Bonzo Lend, the largest lending protocol in the Hedera ecosystem, was targeted through a signature verification flaw in the third-party oracle provider Supra. Attackers injected manipulated SAUCE token prices into the protocol, artificially inflating the value of collateral to borrow assets worth far more than the underlying security.
Before the oracle could correct the values, the exploit was executed, leading to significant losses. The protocol has since suspended all activities, with Bonzo Labs and the Bonzo Finance foundation collaborating to restore normal operations and address the underlying integration issues. This case highlights the fragility of relying on external data feeds without sufficient redundancy or validation mechanisms, as a single point of failure in the oracle layer can cascade into catastrophic losses for the entire lending platform.
Logic errors in treasury management also proved costly, as demonstrated by the Summer.fi exploit on July 6, which resulted in losses of approximately $6.04 million. The attack targeted the FleetCommander treasury of the Ethereum DeFi yield protocol Summer.fi, formerly known as Oasis.app, which was launched in 2019 for MakerDAO users and transitioned to an AI-driven automated yield optimization layer at the beginning of 2026.
The vulnerability stemmed from a discrepancy in the totalAssets() calculation, where strategy components that had set deposit limits and were scheduled for decommissioning were still included in the active asset list. Attackers exploited this accounting error to accumulate assets and earn alpha, highlighting how complex treasury configurations can introduce subtle but exploitable logic flaws. This incident serves as a reminder that even established protocols with long histories are vulnerable to configuration errors, particularly as they evolve and integrate new technological layers.
Phishing and scam attacks continued to target individual users, with two notable incidents on Ethereum involving address prefixes 0x8c94 and 0x3e1b. On July 9, victims with addresses starting with 0x8c94 signed a phishing token authorization document, resulting in losses of USDT worth $999,999. A more sophisticated attack occurred on July 24, where victims with addresses starting with 0x3e1b lost $340,463 due to a phishing multicall attack.
The timeline of this second incident reveals the precision of modern phishing operations: at 06:51:47 UTC, victims signed a multicall on the alphaUSDCDeltaV2 token contract, which contained an approve request with unlimited allowances. Just 36 seconds later, at 06:52:23 UTC, 332,787 alphaUSDCDeltaV2 tokens were depleted via transferFrom, demonstrating how quickly automated scripts can execute theft once authorization is granted. These incidents highlight the evolving nature of phishing, which has moved from simple social engineering to complex, time-sensitive technical exploits.
The scope of phishing expanded beyond digital interfaces to include physical mail, as seen in the SecondFi app and Ledger letter scams. On July 12, a global crypto security monitoring platform disclosed a phishing attack using a fake SecondFi mobile app, which targeted developers and resulted in losses of approximately $14.2 million. Simultaneously, from July 3 to July 7, scammer groups sent fake physical letters from Ledger to users’ addresses, featuring the official logo, the CTO’s signature, and information about post-quantum cryptography security updates.
These letters aimed to trick users into scanning QR codes to access highly realistic phishing websites and entering their seed phrases. Queensland police confirmed that between July 3 and 7, victims reported total losses of over 1.47 million Australian dollars, equivalent to approximately $960,000. Police warned that Ledger would never ask for seed phrases via letter or phone call, emphasizing the need for user vigilance against multi-vector attacks that blend physical and digital deception.
The core characteristics of blockchain security incidents in July 2026 can be summarized by a shift in attack vectors, continuous failures of cross-chain bridges, and prominent governance-related vulnerabilities. The AFX Trade incident, where $24.15 million was withdrawn via stolen keys, and the Ostium breach, which exploited off-chain permissions, illustrate the growing sophistication of non-code-based attacks. Similarly, the BonkDAO exploit demonstrated how governance mechanisms can be weaponized, while the rise of brand-trust exploitation in phishing scams, such as those targeting X Corp users, shows that social engineering remains a potent tool.
Lingshi Technology recommends that individuals regularly revoke wallet approvals and use separate wallets for high-value assets, while project teams must implement multisig, hardware signatures, time locks, and circuit breaker mechanisms. Industry-wide, there is an urgent need for standardized audits of off-chain infrastructure, enhanced APT threat intelligence sharing, and the development of blacklist databases to mitigate these evolving threats.
Comments
No comments yet.