Review of DeFi security incidents in July 2026: Overview of eight major vulnerability attacks
July 2026 was a difficult month for DeFi security. Eight separate protocols suffered losses of more than $110 million, and the incidents were not caused by new smart contract vulnerabilities-almost all of this month's cryptographic attacks resulted from key leaks, governance manipulation, authority failures, or operational errors.
The following content will sort out the process, cause and subsequent handling of each incident.
Overview of encryption attacks in July 2026
AFX Trade: Loss of US$24.15 million, attack type is bridge key disclosure, status is under investigation, reward has been awarded.
Ostium: Loss of US$23.75 million. The attack type is oracle signature key disclosure, and the status is transaction restored and funds have not been recovered.
BonkDAO: Loss of US$20 million, attack type is governance takeover, status is reported.
Wanchain: About US$10 million, the attack type is signature multiplexing, the status is bridging offline, and a reward deadline has been set.
Triple-A: Loss of $9.7 million (subsequent estimates rose to $11.8 million), attack type is hot wallet intrusion, and status is service restored.
Bonzo Finance: Loss of approximately US$9.05 million, attack type is oracle manipulation, status is borrowing suspended, oracle repaired.
Verus Bridge: Loss of US$7.54 million, attack type is unpatched bridge vulnerability, status is partially recovered through reward.
Summer.fi: Loss of $6 million, attack type is outdated collateral valuation, status is agreement is about to close.
Detailed analysis of each event
AFX Trade
What happened: On July 22, the attacker gained control of the verifier signing key of AFX's managed bridge on Arbitrum and withdrew funds indefinitely.
Root cause: Off-chain signature key leaked, non-smart contract defect. Arbitrum's native infrastructure was not affected.
Amount of loss: US$24.15 million in USDC, converted into approximately 12,467 ETH pieces.
User impact: Capital losses almost exhausted the entire value of AFX's lockup.
Current progress: AFX publicly offered attackers a 70/30 reward plan.
Ostium
Incident: On July 15, attackers used a leaked oracle signature key to submit false price reports, creating artificial trading profits.
Root cause: Off-chain certificate stolen, non-code vulnerability. Traders 'collateral is stored in separate contracts and is not affected.
Amount of loss: US$23.75 million was withdrawn from the liquidity treasury.
User impact: The treasury lost nearly one-third of its assets, and trader funds remained isolated.
Current progress: The transaction resumed on July 23, and the stolen funds have not yet been recovered.
BonkDAO
What happened: On July 6, attackers spent approximately US$4 million on BONK tokens to gain majority voting rights, and then passed a proposal to drain the treasury.
Root cause: Governance manipulation. Low voter turnout resulted in a single wallet dominating voting results and code vulnerabilities were not exploited.
Amount of loss: approximately US$20 million in BONK tokens.
User impact: BONK prices fell by about 8% to 10% after the news was disclosed.
Current progress: BonkDAO has reported the case and coordinated with the exchange to track the funds.
Wanchain
Incident: From July 20 to 21, the attacker reused a valid signature of a small withdrawal and extracted a larger amount of funds from the Cardano-BNB Bridge.
Root cause: Signature reuse flaw in message encoding is a privilege and verification failure, not a new contract vulnerability.
Amount of loss: approximately 515.2 million NIGHT tokens worth approximately US$10 million.
User impact: The price of NIGHT token first plummeted and then partially rebounded.
Current progress: Wanchain's deadline for white hats to attackers (August 6).
Triple-A
Event history: From July 24 to 25, an attacker gained access to Triple-A's hot wallet on multiple chains and withdrew funds.
Root cause: The hot wallet was compromised, which is a key management and access control failure.
Amount of loss: Initially reported as US$9.7 million, subsequent estimates increased to US$11.8 million.
User impact: The company stated that client funds are held independently in trust and are not affected.
Current progress: Service has been restored after temporary suspension.
Bonzo Finance
History of the incident: On July 11, the attacker deposited a very small amount of SAUCE tokens and then manipulated the oracle to report a significantly inflated price.
Root cause: The third-party oracle validator accepted an invalid signature and failed permission outside of Bonzo's own contract.
Amount of loss: Lending approximately $9.05 million using false collateral value.
User impact: Lending and rewards have been suspended, and other Bonzo products are still operating normally.
Current progress: Oracle provider Supra has fixed the validator.
Verus Bridge
Incident: On July 22 and 23, attackers exploited the same vulnerability category as the Verus-Ethereum Bridge in May.
Root cause: The bridging vulnerability was not repaired and was essentially an operational error that failed to completely close the known vulnerability.
Loss amount: US$7.54 million, converted into ETH.
User impact: Bridging liquidity is directly impaired.
Current progress: The attacker returned about 75% of the money after receiving a reward.
Summer.fi
Incident history: On July 6, attackers used a $65.4 million flash loan to exploit outdated valuation data left over from the incomplete treasury removal process.
Root cause: Operational error. The value of outdated tokens from a retired treasury is still included in the total assets of the main treasury.
Amount of loss: $6 million redeemed from two USDC vaults.
User impact: SUMR tokens fell by more than 18%, and the treasury was immediately suspended.
Current progress: Summer.fi is gradually shutting down its business, applications will continue to run until August 31, and governance will be transferred to the DAO.
Market Impact
The impact of this round of events on confidence goes beyond the scope of a single agreement. Each encryption attack this month has heightened the industry's sense that there are still structural gaps in DeFi security. Governance security came under review after the BonkDAO incident-when voting rates were low, treasury voting could be acquired at such a low cost. Operational security (rather than audited code) has become a common failure point for AFX, Ostium, Triple-A, and Bonzo: off-chain keys, oracle signers, and hot wallets are all outside the scope of standard smart contract audits. During this period, DeFi's total lockdown volume shrank, users withdrew funds from platforms that were considered risky, and various DeFi protocols also began to comprehensively review multi-signature settings, oracle redundancy mechanisms and treasury accounting logic.
Conclusion
Eight incidents, with losses exceeding US$110 million, almost none of which originated from new smart contract vulnerabilities. This wave of cryptographic attacks has pointed out clear patterns: keys, governance votes, oracle permissions, and operating procedures that have now become DeFi's main attack surfaces. The security lesson worth remembering is that audit code alone cannot protect protocols. The infrastructure surrounding the code-who holds the key, who votes, who verifies data-also requires rigorous scrutiny.
This document is for information purposes only and does not constitute financial advice. Please be sure to study your own before investing.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BONK
ETH