Crypto security losses reached about $97 million in July 2026, according to ZeroShadow’s monthly security report. Based on data compiled from multiple blockchain security monitoring platforms, the firm said the month was marked by a clear shift in attack routes, with off-chain infrastructure increasingly becoming the main target.
About $94 million of the total was tied to hacker attacks and contract-related vulnerabilities, while phishing attacks accounted for roughly $3 million. The report logged more than 14 protocol-related security incidents, down from 67 in June, but said losses per incident rose sharply. Total losses were up about 18.7% from June’s $81.73 million.
Cross-chain bridges remained the most heavily hit sector
ZeroShadow said cross-chain bridges were still the main loss concentration point in July. Attacks involving AFX Trade, Verus and B² Network broke out within a span of hours, with combined losses of more than $35 million.
The report said the threat pattern is moving away from smart-contract code bugs and toward non-code attack surfaces, including off-chain infrastructure breaches, signing-key leaks and governance vote manipulation.
Seven major hacking incidents in July
Ostium: off-chain oracle permissions compromised
On July 15, Ostium, an RWA perpetuals protocol in the Arbitrum ecosystem, was attacked for about $23.75 million. The attacker gained access to the off-chain price-signing system, forged BTC/USD price data, pushed the BTC price to roughly $5,000, and drained about 23.75 million USDC from the OLP liquidity pool through repeated open-and-close trading loops.
The team said the incident was not caused by a smart-contract flaw or a compromised governance multisig. Instead, the breach stemmed from compromised off-chain price-signing infrastructure. User margin was not affected, and the protocol resumed trading on July 23.
AFX Trade: validator key leak at a cross-chain bridge
On July 22, the cross-chain bridge operated by Arbitrum-based decentralized perpetual exchange AFX Trade was exploited for about $24.15 million. The attacker obtained the bridge’s private validator signing key and used it to authorize withdrawals. Because the smart contract verified valid signatures and released funds as designed, the report said there was no contract-layer bug.
Roughly 24.15 million USDC was bridged from Arbitrum to Ethereum, swapped into 12,467.5 ETH at an average price of about $1,937, and consolidated into a single wallet. Arbitrum’s native bridge was not affected. AFX suspended the compromised bridge and offered the attacker a 30% bounty in exchange for the return of funds.
BonkDAO: governance vote manipulation
On July 6, BonkDAO suffered a governance manipulation attack that led to losses of about $20 million. The attacker spent around $4 million to acquire enough BONK tokens, then took advantage of a Solana Realms governance setup in which only a 1% participation rate was needed for a proposal to pass.
After the malicious proposal was approved, the attacker moved about 4.426 billion BONK, worth about $20 million, out of the BonkDAO treasury. No smart contract failed during the process. The issue lay in governance design rather than in contract code. Immunefi said this is a typical form of major loss seen in 2026, where funds are drained through governance voting and rule design rather than contract defects.
Bonzo Lend: oracle manipulation
On July 11, Bonzo Lend, described in the report as the largest lending protocol in the Hedera ecosystem, was hit by an oracle manipulation attack that caused about $9.05 million in losses. The attacker exploited a signature-verification flaw at third-party oracle provider Supra, injected manipulated SAUCE token prices into the protocol, and borrowed assets far above the collateral’s true value before the feed was corrected.
The protocol has paused all activity, and Bonzo Labs and the Bonzo Finance Foundation are coordinating recovery and remediation efforts.
Verus: second attack on the Ethereum bridge
On July 23, the Verus-Ethereum cross-chain bridge was attacked again, with losses of about $7.55 million. The report said the exploit used the same contract path and the same vulnerability category as the May attack, showing how unpatched flaws and redeposited funds can leave a system exposed to a repeat incident.
The weakness was described as a cross-chain bridge verification bypass, and the attacker used the same entry route to steal funds.
B² Network: staking contract upgrade permissions seized
Also on July 23, B² Network on BNB Chain lost control of staking contract upgrade permissions. The incident led to the loss of about 8.591 million B2 tokens, worth roughly $3.86 million. The attacker swapped the tokens into 5,409 WBNB, worth about $3.11 million, then bridged the funds to Ethereum and is now moving them to Zcash through NEAR Intents.
The report said the case again showed that compromised keys and permissions, rather than cryptography itself, remain a primary cause of major crypto theft. The team has paused staking and contacted the attacker on-chain, saying it would not start legal action if at least 10% of the stolen funds were returned within 24 hours.
Summer.fi: vault configuration flaw
On July 6, Ethereum DeFi yield protocol Summer.fi suffered an attack on its FleetCommander vault, losing about $6.04 million. The root cause was tied to the way totalAssets() was calculated. Strategy components that had reached deposit caps, were being prepared for deprecation, but had not yet been removed from the active set, were still included in the calculation. The attacker used that mismatch to accumulate assets and extract excess yield.
The report noted that Summer.fi was formerly Oasis.app, launched for MakerDAO users in 2019, and shifted in early 2026 toward an AI-driven automated yield optimization layer.
Four notable phishing and scam cases
The report also listed four representative rug pull or phishing-related incidents:
- On July 9, a victim using an Ethereum address beginning with 0x8c94 signed a phishing token approval and lost $999,999 worth of USDT.
- On July 24, a victim with an address beginning with 0x3e1b lost $340,463 through a phishing multicall on Ethereum. The timeline in the report said that at 06:51:47 UTC the victim signed multicall() on the alphaUSDCDeltaV2 token contract, which embedded an unlimited approve(). At 06:52:23 UTC, 36 seconds later, 332,787 alphaUSDCDeltaV2, worth about $340,000, was drained via transferFrom.
- On July 12, a global crypto security monitoring platform disclosed three high-impact crypto asset attacks. One involved a fake mobile application impersonating SecondFi and targeting developers. The reported loss was about $14.2 million. The disclosure said the three attacks erupted within 24 hours and targeted developers, retail users and high-net-worth whales.
- From July 3 to July 7, scammers mailed counterfeit Ledger letters to users’ home addresses in a phishing campaign that caused about $960,000 in losses. The letters carried the company logo, a CTO signature and an explanation about a post-quantum cryptography security update, pushing users to scan a QR code, open a fake website and enter their seed phrases. Queensland Police said reported losses during July 3-7 alone exceeded A$1.47 million, and reminded users that Ledger does not ask for seed phrases by mail or phone.
Three patterns stood out in July
ZeroShadow summarized the month with three themes: attack-route migration, persistent failures at cross-chain bridges, and growing exposure at the governance layer.
Off-chain infrastructure breaches, signing-key leaks and governance vote manipulation took up a larger share of incidents. In AFX Trade’s case, obtaining a signing key alone was enough to withdraw $24.15 million. In Ostium’s case, the incident exposed weaker protection around off-chain permission management than around on-chain multisig systems. BonkDAO, meanwhile, showed that governance voting rules themselves can become an attack vector.
In phishing, the report said several July incidents followed a new pattern that combined compromised high-profile accounts with fake token promotion. That turned brand trust directly into a fraud tool, while approval-based phishing evolved from a one-off trick into a repeatable automated theft flow.
Recommendations from the ZeroShadow security team
For individual users
- Be cautious of sudden “official” token promotions on X.
- Do not click unknown links or sign unexplained requests.
- Revoke wallet approvals on a regular basis.
- Use separate wallets to isolate high-value assets.
For project teams
- Treat off-chain infrastructure permission management with the same security standard as on-chain multisig.
- Use multisig plus hardware signing for validator keys.
- Set higher voting thresholds and timelocks for governance proposals.
- Build 24/7 monitoring and circuit-breaker mechanisms.
- Extend audits to key storage, permissions and governance rules across the full stack.
For the industry
- Establish sector standards for cross-chain bridge key management.
- Standardize security audits for off-chain infrastructure.
- Strengthen APT threat intelligence sharing and blacklist database construction.
- Encourage projects to deploy bug bounty programs.

