July Security Report: Total Losses Approximately $97 Million, Cross-Chain Bridge Attacks Concentrated with Over $35 Million

marsbitОпубліковано о 2026-08-04Востаннє оновлено о 2026-08-04

Анотація

In July 2026, the cryptocurrency sector suffered total losses of approximately $97 million, with hacker attacks and contract vulnerabilities accounting for about $94 million. A significant trend was the shift in attack vectors from smart contract code to off-chain infrastructure, signature key leaks, and governance manipulation. Major incidents included: * **Ostium ($23.75M loss):** An attacker gained access to its off-chain price oracle signing system, manipulated BTC prices, and drained funds. * **AFX Trade Bridge ($24.15M loss):** The private validator key for its cross-chain bridge was compromised, allowing unauthorized withdrawals. * **BonkDAO ($20M loss):** An attacker acquired enough tokens to pass a malicious governance proposal and drain the treasury, exploiting low voting thresholds. * **Bonzo Lend ($9.05M loss):** A third-party oracle provider's signature verification was exploited to inject manipulated token prices. * **Verus Bridge ($7.55M loss):** A repeat attack exploiting the same unpatched bridge vulnerability. * **B2 Network ($3.86M loss):** An attacker seized the upgrade authority for a staking contract. Cross-chain bridges remained a prime target, with concentrated attacks causing over $35 million in losses. Phishing scams resulted in roughly $3 million in losses, employing sophisticated methods like fake mobile apps and physical counterfeit letters targeting Ledger users. Key takeaways are the acceleration of attacks on off-chain infrastruc...

The monthly security event highlights from Zero Hour Technology are here! According to statistics from multiple blockchain security monitoring platforms, the security landscape in the cryptocurrency field in July 2026 exhibited the characteristic of "accelerating shift in attack vectors, with off-chain infrastructure becoming the new target." The total losses caused by security events in the month were approximately $97 million, of which hacker attacks and contract vulnerabilities accounted for about $94 million in losses, and phishing attacks resulted in about $3 million in losses. Over 14 protocol-related security incidents occurred, a decrease from 67 in June, but the single-incident loss amount increased significantly. Total losses in July rose by about 18.7% month-on-month from June's $81.73 million. Cross-chain bridges remained the hardest hit area, with multiple attacks including AFX Trade, Verus, and B2 Network concentrated within hours, resulting in combined losses exceeding $35 million. Attack vectors are accelerating the shift from smart contract code vulnerabilities to non-code level attack methods such as off-chain infrastructure intrusion, signature key leaks, and governance vote manipulation.

Hacker Attacks

Typical security events: 7

• Ostium Off-Chain Oracle Authority Intrusion

Time: July 15

Loss Amount: Approximately $23.75 million

Event Details: Ostium, an Arbitrum ecosystem RWA perpetual trading protocol, was attacked. The attacker gained access to the off-chain price signature system authority, forged BTC/USD price data, manipulated the BTC price to approximately $5,000, and stole about 23.75 million USDC from the OLP liquidity pool through cyclic opening and closing of positions. The official confirmed that this incident was not due to a smart contract vulnerability or a breach of the governance multi-signature wallet, but rather an intrusion into the off-chain price signature infrastructure. User margins were not affected, and the protocol resumed trading on July 23.

• AFX Trade Cross-Chain Bridge Verification Key Leak Attack

Time: July 22

Loss Amount: Approximately $24.15 million

Event Details: The cross-chain bridge operated by AFX Trade, a decentralized perpetual contract exchange on Arbitrum, was attacked. The attacker obtained the bridge's private validator signing key and used it to authorize withdrawals. Since the smart contract verified the signature and released funds as designed, there was no vulnerability at the contract level. Approximately 24.15 million USDC was stolen and bridged from Arbitrum to Ethereum, exchanged for 12,467.5 ETH at an average price of about $1,937, and consolidated into a single wallet. The native Arbitrum bridge was unaffected. AFX suspended the attacked cross-chain bridge and offered a 30% bounty to the attacker to recover the funds.

• BonkDAO Governance Vote Manipulation & Authority Management Vulnerability Attack

Time: July 6

Loss Amount: Approximately $20 million

Event Details: The attacker spent approximately $4 million to purchase enough BONK tokens, exploiting the Solana Realms governance platform's mechanism where a proposal requires only a 1% voting rate to pass, submitted a malicious proposal, and got it passed. After the proposal passed on July 6, the attacker transferred about 4.426 billion BONK (approximately $20 million) from the BonkDAO treasury. No smart contract failed during the entire process; the vulnerability was not in the contract code but in the governance rule design itself. Immunefi pointed out that this is a typical pattern for the most severe loss incidents in 2026 – funds are not lost from contract flaws but from governance votes and rule designs.

• Bonzo Lend Oracle Manipulation Attack

Time: July 11

Loss Amount: Approximately $9.05 million

Event Details: Bonzo Lend, the largest lending protocol on Hedera, suffered an oracle manipulation attack. The attacker exploited a signature verification vulnerability in the third-party oracle provider Supra to inject manipulated SAUCE token prices into the protocol. By artificially inflating collateral value, the attacker borrowed assets far exceeding the collateral value before the oracle corrected, causing approximately $9.05 million in losses. The protocol has suspended all activities, and Bonzo Labs and the Bonzo Finance foundation are coordinating recovery and remediation efforts.

• Verus-Ethereum Cross-Chain Bridge Secondary Attack

Time: July 23

Loss Amount: Approximately $7.55 million

Event Details: The Verus-Ethereum cross-chain bridge was attacked again, resulting in losses of approximately $7.55 million. This attack used the same contract path and vulnerability category as the May attack, highlighting how unpatched defects and re-deposited funds can make the system vulnerable to secondary attacks. This vulnerability is of the cross-chain bridge verification bypass type, where the attacker completed the fund theft through the same entry path.

• B2 Network Staking Contract Upgrade Authority Attack

Time: July 23

Loss Amount: Approximately $3.86 million

Event Details: The upgrade authority for the staking contract of B2 Network on BNB Chain was seized by an attacker, resulting in the loss of approximately 8.591 million B2 tokens (about $3.86 million). The attacker exchanged them for 5,409 WBNB (about $3.11 million) and bridged to Ethereum, currently transferring funds to Zcash via NEAR Intents. This event highlights that compromised keys and authorities – not the encryption technology itself – remain the main cause of major cryptocurrency thefts. The team has suspended staking functions and contacted the attacker on-chain, stating that if at least 10% of the stolen funds are returned within 24 hours, legal proceedings will not be initiated.

• Summer.fi Vault Configuration Vulnerability Attack

Time: July 6

Loss Amount: Approximately $6.04 million

Event Details: The FleetCommander vault of the Ethereum DeFi yield protocol Summer.fi was attacked. The root cause of the vulnerability was that when calculating totalAssets(), strategy components that had been set with deposit caps, were preparing to be decommissioned but had not yet been removed from the active set, were still included in the calculation. The attacker exploited this calculation deviation to accumulate assets and extract excess yield. Summer.fi, formerly Oasis.app, launched for MakerDAO users in 2019 and shifted to an AI-driven automated yield optimization layer in early 2026.

Rug Pull / Phishing Scams

Typical security events: 4

(1) On July 9, a victim with address starting 0x8c94 signed a phishing token approval on Ethereum, losing USDT worth $999,999.

(2) On July 24, a victim with address starting 0x3e1b lost $340,463 due to a phishing multicall on Ethereum.

Timeline:

06:51:47 UTC — The victim signed multicall() on the alphaUSDCDeltaV2 token contract. It contained: an approve() with unlimited allowance.

06:52:23 UTC — 36 seconds later, 332,787 alphaUSDCDeltaV2 (~$340K) was drained via transferFrom.

(3) Fake SecondFi Mobile App Phishing Attack

Loss Amount: Approximately $14.2 million

Nature of Event: On July 12, global crypto security monitoring platforms disclosed three high-risk crypto asset attack incidents. The first type was a fake SecondFi mobile app phishing attack targeting developers. The three attacks concentrated within 24 hours, targeting developers, ordinary retail investors, and high-net-worth whales, exposing security weaknesses across the entire Web3 ecosystem.

(4) Ledger Physical Letter Phishing Scam

Loss Amount: Approximately $960,000

Nature of Event: From July 3 to 7 (concentrated outbreak), a scam group mailed forged official Ledger physical letters to users' addresses. The letters featured the official logo, CTO signature, and post-quantum cryptography security update instructions, inducing users to scan a QR code to enter a highly imitated phishing website and enter their seed phrase, thereby stealing wallet assets. The Queensland Police confirmed that just during the period from July 3 to 7, the total losses reported by victims had exceeded 1.47 million AUD. Police reminded that Ledger officials will never request seed phrases via letters or phone calls.

Summary

The core characteristics of blockchain security incidents in July 2026 can be summarized with three keywords: Shift in Attack Vectors, Persistent Cross-Chain Bridge Failures, Prominent Governance-Level Vulnerabilities.

A clear shift in attack vectors is occurring: Non-code level attack methods such as off-chain infrastructure intrusion, signature key leaks, and governance vote manipulation are rising sharply. In the AFX Trade incident, the attacker completed a $24.15 million withdrawal merely by obtaining the signing key; the Ostium incident exposed the lack of protection mechanisms for off-chain authority management comparable to on-chain multi-signature standards; the BonkDAO incident shows that governance voting mechanisms themselves can become attack entry points.

Regarding phishing scams, several attacks this month exhibited a new pattern of "high-profile account compromise + fake token promotion," where brand trust is directly converted into a scam tool, and approval phishing has evolved from a one-time scam into a replicable, automated fund-draining process.

Zero Hour Technology Security Team Recommendations:

• For Individuals: Be wary of sudden "official" token promotions on platform X; do not click on unknown links or signing requests; regularly revoke wallet authorizations; use separate wallets to isolate risks for high-value assets.

• For Project Teams: Off-chain infrastructure authority management should meet the same security standards as on-chain multi-signature; use multi-signature + hardware signing for validator keys; set higher voting thresholds and timelocks for governance proposals; establish 7x24 monitoring and circuit breaker mechanisms; audits should cover the entire chain including key storage, authorities, and governance rules.

• For the Industry: Establish industry standards for cross-chain bridge key management; promote standardization of off-chain infrastructure security audits; strengthen APT threat intelligence sharing and blacklist database construction; recommend that project teams deploy bug bounty programs.

Пов'язані питання

QWhat was the total estimated loss due to security incidents in the cryptocurrency field in July 2026, and what were the main causes?

AThe total estimated loss due to security incidents in July 2026 was approximately 97 million US dollars. The main causes were hacker attacks and contract vulnerabilities (around 94 million USD) and phishing attacks (around 3 million USD).

QList three specific attack types targeting off-chain infrastructure or non-code vulnerabilities mentioned in the July 2026 security report.

AThree specific attack types targeting off-chain or non-code vulnerabilities mentioned are: 1. Off-chain price signature system intrusion (Ostium attack). 2. Validation key compromise for a cross-chain bridge (AFX Trade attack). 3. Governance voting manipulation exploiting low quorum rules (BonkDAO attack).

QAccording to the report, what is a significant trend shift in the attack paths during July 2026 compared to earlier periods?

AThe significant trend shift is that attack paths are accelerating the transition away from smart contract code vulnerabilities towards targeting off-chain infrastructure, signature key leaks, governance vote manipulation, and other non-code layer attack methods.

QWhich incident involved a phishing scam using physical mail, and what was the key deceptive element?

AThe incident was the Ledger physical letter phishing scam. The key deceptive element was sending forged official-looking physical letters bearing the Ledger logo and CTO signature, which instructed users to scan a QR code leading to a phishing site to steal their wallet seed phrases.

QWhat common target category linked the attacks on AFX Trade, Verus, and B2 Network in late July, and what was the combined estimated loss from these specific incidents?

AThe common target category was cross-chain bridges. The attacks on AFX Trade, Verus (the second attack), and B2 Network, which were concentrated over a few hours, resulted in a combined estimated loss of over 35 million US dollars.

Пов'язані матеріали

On the Eve of Circle's Earnings Report, Wall Street Shows Major Divergence in CRCL Valuation

On the eve of Circle (CRCL) releasing its quarterly earnings report, Wall Street analysts are deeply divided over the company's valuation. Morgan Stanley downgraded Circle from "Equal Weight" to "Underweight," slashing its price target from $106 to $38. Analyst James Faucette argues the market overestimates the growth potential of Circle's core USDC stablecoin, noting its circulation hasn't increased since Q3 2025 and new use cases beyond remittances and card spending are limited. He warns that slowing USDC growth could pressure the crucial "reserve income" and shift revenue toward lower-margin transaction fees. In stark contrast, TD Cowen initiated coverage with a "Buy" rating and an $82 price target. Analyst Bryan Bergin believes the market underestimates Circle's potential to evolve from a stablecoin issuer into a broader digital financial infrastructure platform. He forecasts a ~31% annual growth rate for USDC through 2030 and expects faster growth in fee-based revenue from services like payments, RWA tokenization, and its Arc network. A key external factor adding uncertainty is the stalled progress of the CLARITY Act in the US Senate, whose delay could dampen institutional adoption expectations for stablecoins. The core disagreement lies in whether Circle's future hinges on USDC circulation growth or a successful platform-based transformation. The upcoming earnings report is keenly awaited for insights into reserve income trends and the progress of newer business verticals.

marsbit22 хв тому

On the Eve of Circle's Earnings Report, Wall Street Shows Major Divergence in CRCL Valuation

marsbit22 хв тому

Hong Kong Stock Market in July: Super IPOs Coexist with Wave of Breakings, Hard Tech Still the Main Theme

The Hong Kong IPO market in July presented a "two-tiered" scenario characterized by both a mega-IPO and a significant wave of new stock listings falling below their issue price ("breaking issue"). The highlight was Zhongji Innolight's (stock code: 03308.HK) listing on July 30, which raised approximately HK$53.41 billion. This marked the largest IPO on the Hong Kong exchange in nearly seven years since Alibaba's secondary listing. A prominent trend was the continued dominance of A+H listings, with companies like Luxshare (02475.HK) and others contributing significantly to the total monthly fundraising of around HK$116 billion. In stark contrast, the market saw a sharp rise in "broken issues." Out of 17 new listings for the month, 7 broke issue on their debut, with the rate climbing to 47% by month-end. Factors contributing to this included an intense concentration of listings (15 in one week), profit-taking by investors, and a market reassessment of valuations, particularly for companies with unclear commercial prospects. Despite the sell-off, hard tech remained the core theme, accounting for over 70% of July's listings. Key sectors were semiconductors and AI/autonomous driving. However, market enthusiasm became highly selective, with extreme over-subscription for certain niche players while others were heavily sold off. This signals a shift from speculative fervor towards a more value-driven assessment. Looking ahead, recent listing reforms by the Hong Kong Exchanges are expected to attract more tech firms. With a large pipeline of over 350 companies awaiting listing, including potential large offerings like SHEIN, the market is poised for continued activity. Analysts view July's correction not as a downturn but as a healthy valuation reset, emphasizing the need for investors to carefully discern company fundamentals.

marsbit24 хв тому

Hong Kong Stock Market in July: Super IPOs Coexist with Wave of Breakings, Hard Tech Still the Main Theme

marsbit24 хв тому

Wall Street Shows Sharp Divergence in CRCL Valuation on the Eve of Circle's Earnings Report

On the eve of its earnings report on August 5th, significant divergence emerged on Wall Street regarding the valuation of Circle (CRCL). Morgan Stanley downgraded Circle from "Equal Weight" to "Underweight," slashing its target price from $106 to $38. Analyst James Faucette argues that the market has overestimated the growth potential of USDC, noting stagnant circulation since Q3 2025 and a lack of major new use cases beyond remittances and card spending. He warns that slower USDC growth could pressure Circle's core "reserve income" and shift its revenue mix toward lower-margin transaction fees, making current valuations excessive. In contrast, TD Cowen initiated coverage with a "Buy" rating and an $82 target price. Analyst Bryan Bergin believes the market underestimates Circle's potential to evolve from a stablecoin issuer into a broader digital financial infrastructure platform. He focuses on future services like payments, asset management, RWA tokenization, and blockchain infrastructure, forecasting a ~31% CAGR for USDC circulation through 2030 and faster growth in fee-based revenues. A key external variable is the delayed progress of the CLARITY Act, whose uncertainty may pressure market sentiment by slowing regulatory clarity for stablecoins. Ultimately, the split centers on whether Circle's value hinges on USDC growth or its platform transformation. The upcoming earnings report will be scrutinized for details on reserve income, payment services, and RWA initiatives.

Odaily星球日报28 хв тому

Wall Street Shows Sharp Divergence in CRCL Valuation on the Eve of Circle's Earnings Report

Odaily星球日报28 хв тому

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

Apple has temporarily suspended and limited submissions to its Bug Bounty Program due to a flood of AI-generated vulnerability reports. The program, launched in 2016 and offering rewards up to $5 million, has been overwhelmed by reports from amateur researchers using tools like ChatGPT, many containing false positives or "AI hallucinations." This AI-driven surge in bug reports is straining Apple's security review team, leading the company to impose a 30-day "cooling-off" period and submission caps. The trend highlights a broader industry challenge, with other major firms like Google and GitHub also adjusting their vulnerability disclosure programs. Paradoxically, while AI is creating a reporting bottleneck, it's also accelerating defense. Apple's recent macOS Tahoe 26.6 security update, which patched 194 vulnerabilities, included its first-ever acknowledgments to AI tools (Claude, Codex Security, etc.) for helping discover flaws. This forces Apple into faster, more frequent security updates, a departure from its traditionally controlled release cadence. A key example involves Apple's advanced "Memory Integrity Enforcement" (MIE) security feature, touted as a major breakthrough. However, researchers using an AI model bypassed its protections in just five days, demonstrating both the power and disruptive pace of AI in cybersecurity. The incident underscores a critical shift: as AI compresses the vulnerability discovery cycle to days, traditional monthly security update cycles may become dangerously long exposure windows.

marsbit1 год тому

AI Bulk Bombards Apple Bug Bounty Program, Review Team Has Gone Offline

marsbit1 год тому

Торгівля

Спот
活动图片