July Security Report: Total Losses Approximately $97 Million, Cross-Chain Bridge Attacks Concentrated with Over $35 Million
In July 2026, the cryptocurrency sector suffered total losses of approximately $97 million, with hacker attacks and contract vulnerabilities accounting for about $94 million. A significant trend was the shift in attack vectors from smart contract code to off-chain infrastructure, signature key leaks, and governance manipulation.
Major incidents included:
* **Ostium ($23.75M loss):** An attacker gained access to its off-chain price oracle signing system, manipulated BTC prices, and drained funds.
* **AFX Trade Bridge ($24.15M loss):** The private validator key for its cross-chain bridge was compromised, allowing unauthorized withdrawals.
* **BonkDAO ($20M loss):** An attacker acquired enough tokens to pass a malicious governance proposal and drain the treasury, exploiting low voting thresholds.
* **Bonzo Lend ($9.05M loss):** A third-party oracle provider's signature verification was exploited to inject manipulated token prices.
* **Verus Bridge ($7.55M loss):** A repeat attack exploiting the same unpatched bridge vulnerability.
* **B2 Network ($3.86M loss):** An attacker seized the upgrade authority for a staking contract.
Cross-chain bridges remained a prime target, with concentrated attacks causing over $35 million in losses. Phishing scams resulted in roughly $3 million in losses, employing sophisticated methods like fake mobile apps and physical counterfeit letters targeting Ledger users.
Key takeaways are the acceleration of attacks on off-chain infrastructure, the persistent vulnerability of cross-chain bridges, and the rising prominence of governance-layer exploits. Recommendations include enhancing off-chain key management with multi-sig security, implementing stricter governance controls, and increasing user vigilance against phishing.
marsbitIeri 02:21