Crypto Security Review for July 2026: Losses Hit $97M as Cross-Chain Bridge Exploits Accelerate
AI مارکیٹ کا خلاصہ
July 2026 crypto security losses reached ~$97M (+18.7% m/m), with cross-chain bridge incidents exceeding $35M and attack vectors shifting toward offchain infrastructure, key compromise, and governance manipulation. High-profile events (AFX Trade, Ostium, BonkDAO, Verus, B² Network) underscore systemic operational and governance risks beyond smart-contract bugs. Near-term, this can dampen DeFi and bridge activity, raise risk premia, and intensify scrutiny of key management and offchain controls.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+1.63%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Zero Hour Tech has released its monthly security incident roundup. Data aggregated from multiple blockchain security monitoring platforms shows that July 2026 marked a sharp realignment in crypto attack patterns, with off-chain infrastructure emerging as a major weak point.
Total losses from security incidents in July were estimated at about $97 million. Roughly $94 million was linked to hacker attacks and smart contract-related incidents, while phishing accounted for about $3 million. More than 14 protocol-related incidents were recorded, down from 67 in June, but average losses per incident climbed. Overall losses rose about 18.7% month over month from June's $81.73 million.
Cross-chain bridges stayed in the crosshairs. A cluster of attacks—targeting AFX Trade, Verus, and B² Network—played out within hours, with combined losses topping $35 million. Monitoring indicates attackers are moving away from pure smart contract code exploits toward non-code techniques such as off-chain system compromise, signature key exposure, and governance vote manipulation.
Key hacker incidents (7 cases)
1) Ostium — Off-chain oracle signing privilege compromise
Time: July 15
Loss: about $23.75 million
Ostium, an RWA perpetual trading protocol in the Arbitrum ecosystem, was attacked after the intruder gained access to the off-chain price signing system. The attacker forged BTC/USD pricing, drove the BTC price to about $5,000, and drained around $23.75 million USDC from the OLP liquidity pool through repeated position opens and closes. The team said the incident was not caused by a smart contract flaw or a compromised governance multisig, but by a breach of off-chain signing infrastructure. User margin was unaffected, and trading resumed on July 23.
2) AFX Trade — Cross-chain bridge validator verification key compromise
Time: July 22
Loss: about $24.15 million
AFX Trade's cross-chain bridge (used by its decentralized perpetual futures exchange on Arbitrum) was compromised after an attacker obtained a private signing key used by validator nodes and authorized withdrawals. The smart contract validated signatures as designed, with no contract-level vulnerability reported. About 24.15 million USDC was bridged from Arbitrum to Ethereum and swapped for 12,467.5 ETH at an average price of $1,937, then consolidated into a single wallet. The native Arbitrum bridge was not affected. AFX suspended the compromised bridge and offered the attacker a 30% bounty in exchange for returning the funds.
3) BonkDAO — Governance voting manipulation via access control weakness in rule design
Time: July 6
Loss: about $20 million
The attacker reportedly spent about $4 million to acquire enough BONK tokens and leveraged the Solana Realms governance process, where proposals can pass with a 1% voting threshold. A malicious proposal was submitted and approved, after which about 44.26 billion BONK tokens (around $20 million) were transferred from the BonkDAO treasury. No smart contract bug was exploited; the failure was in governance rule design. Immunefi described the case as emblematic of 2026's most severe loss profile: losses driven by governance mechanics rather than contract defects.
4) Bonzo Lend — Oracle manipulation
Time: July 11
Loss: about $9.05 million
Bonzo Lend, the largest lending protocol in the Hedera ecosystem, suffered an oracle manipulation incident. The attacker exploited a signature validation vulnerability in Supra, a third-party oracle provider, to feed manipulated SAUCE token pricing. By inflating collateral value, the attacker borrowed assets far beyond true collateral value before the oracle corrected, leading to losses of about $9.05 million. The protocol suspended activity as Bonzo Labs and the Bonzo Finance Foundation coordinated recovery and remediation.
5) Verus — Second exploit of the Ethereum cross-chain bridge
Time: July 23
Loss: about $7.55 million
The Verus–Ethereum bridge was hit again, with losses estimated at $7.55 million. The incident followed the same contract pathway and vulnerability class cited in the May attack, underscoring the risk of unpatched weaknesses and the redeposit of funds after an initial exploit. The issue falls under cross-chain bridge verification bypass, enabling theft via the same entry point.
6) B² Network — Staking contract upgrade authority compromise
Time: July 23
Loss: about $3.86 million
An attacker gained control of the upgrade authority for B² Network's staking contract on BNB Chain, stealing about 8.591 million B2 tokens (around $3.86 million). The tokens were swapped for 5,409 WBNB (about $3.11 million) and bridged to Ethereum, with the attacker reportedly using NEAR Intents to move funds toward Zcash. The case highlights that compromised keys and permissions—not cryptography itself—continue to drive major thefts. The team suspended staking and sent an on-chain message offering to forgo legal action if at least 10% of funds were returned within 24 hours.
7) Summer.fi — Vault configuration vulnerability
Time: July 6
Loss: about $6.04 million
Summer.fi's FleetCommander vault, part of its Ethereum DeFi yield product, was exploited. The issue stemmed from totalAssets() including strategy components that had deposit caps and were slated for deactivation but had not been removed from the active pool. Attackers leveraged the miscalculation to build positions and withdraw excess yield. Summer.fi (formerly Oasis.app) launched in 2019 for MakerDAO users and shifted to an AI-driven automated yield optimization layer in early 2026.
Rug pull / phishing and scam activity (4 cases)
1) Ethereum token approval phishing
Date: July 9
Loss: $999,999 USDT
Victims associated with addresses beginning 0x8c94 signed a phishing token approval, leading to the theft.
2) Ethereum multicall phishing
Date: July 24
Loss: $340,463
Victims tied to addresses beginning 0x3e1b were drained via a phishing multicall.
Timeline:
06:51:47 UTC — victim signed multicall() on the alphaUSDCDeltaV2 token contract, embedding an unlimited approve() allowance.
06:52:23 UTC — 36 seconds later, 332,787 alphaUSDCDeltaV2 (~$340K) was drained via transferFrom.
3) Counterfeit SecondFi mobile app phishing
Date: July 12
Loss: about $14.2 million
A global security monitoring platform reported three high-severity crypto asset attacks within 24 hours. The first involved fake mobile apps impersonating SecondFi, reportedly targeting developers. The cluster affected developers, retail users, and high-net-worth holders, pointing to broader Web3 security gaps.
4) Ledger physical mail phishing
Peak period: July 3 to July 7
Loss: about $960,000
A scam group sent counterfeit Ledger letters to user addresses, featuring Ledger branding, a purported CTO signature, and a narrative around post-quantum cryptography security updates. The letters directed recipients to scan a QR code to a convincing phishing site, where victims entered recovery phrases and lost wallet assets. Queensland Police said reported losses during the period exceeded AUD 1.47 million. Authorities reiterated that Ledger never asks for recovery phrases by mail or phone.
What July 2026 revealed
July's incident profile can be distilled into three themes: attack vectors are shifting, cross-chain bridge compromises remain persistent, and governance risk is rising. Non-code attacks—including off-chain infrastructure compromise, signature key leakage, and governance vote manipulation—are increasing quickly.
The AFX Trade case showed how a single exposed signing key can enable a $24.15 million withdrawal. Ostium highlighted how off-chain access controls often lack protections comparable to on-chain multisignature setups. BonkDAO demonstrated that governance mechanisms can become the exploit surface.
Phishing also showed a recurring pattern: hijacking high-profile accounts and pushing fake tokens, turning brand trust into a fraud channel. Authorization-based phishing is increasingly automated and repeatable.
Recommendations from the Zero Time Technology Security Team
• Individuals: Treat sudden "official" token promotions on Platform X with caution. Avoid unknown links and signing requests. Regularly revoke wallet approvals. Use separate wallets to isolate high-value holdings.
• Project teams: Apply on-chain-grade standards to off-chain access control. Use multisig plus hardware signing for validator keys. Raise governance voting thresholds and add timelocks. Maintain 24/7 monitoring and circuit breakers. Expand audits to cover key storage, permissions, and governance rules end to end.
• Industry: Push for standards in cross-chain bridge key management and standardized off-chain infrastructure security audits. Strengthen APT intelligence sharing and blacklist databases. Encourage projects to adopt bug bounty programs.