Bonzo

crypto hacks
2026-08-07 08:08:56

Hackers Stole $247M in Crypto in July, Second-Highest Month of 2026: DefiLlama

According to data from DefiLlama, hackers stole $247 million in crypto assets during July, making it the second-largest month for thefts so far in 2026. Only April was higher, with $644 million stolen. The July total also jumped sharply from $75 million in June and $60 million in May. Galaxy Digital said the Coldcard vulnerability was the largest attack event of the month. The firm confirmed three rounds of exploits affecting 7,300 wallets, with at least $100 million in Bitcoin stolen. It also identified a suspected fourth round that could bring total losses to around $130 million. DefiLlama's hack tracker estimates losses tied to the vulnerability at $115 million. Other July incidents include a $9 million attack on DeFi lending protocol Bonzo Lend, a $2.6 million theft from the Cardano-based wallet SecondFi, a $24 million drain of Arbitrum-based perpetual trading platform AFX, and a $7.5 million loss at Verus Ethereum Bridge.

1010
Hackers Stole $247M in Crypto in July, Second-Highest Month of 2026: DefiLlama
ZeroShadow
2026-08-04 01:55:00

Crypto losses hit about $97 million in July as cross-chain bridge attacks topped $35 million

Blockchain security firm ZeroShadow said the crypto sector lost about $97 million to security incidents in July 2026, with losses rising roughly 18.7% from $81.73 million in June. Of that total, around $94 million came from hacker attacks and contract-related flaws, while phishing accounted for about $3 million. The report counted more than 14 protocol-related incidents, down from 67 in June, but noted that the amount lost per incident rose sharply. Cross-chain bridges remained the hardest-hit area. AFX Trade, Verus and B² Network were among the projects hit within a matter of hours, with combined losses exceeding $35 million. ZeroShadow said the main attack path is shifting away from smart-contract coding bugs and toward off-chain infrastructure compromises, validator or signing-key leaks, and governance manipulation. The report highlighted seven major hacking cases, including the $23.75 million Ostium exploit tied to compromised off-chain price-signing infrastructure, the $24.15 million AFX Trade bridge attack involving validator keys, and the $20 million BonkDAO treasury drain carried out through governance rules rather than contract failure. It also listed four notable phishing or scam incidents and offered separate recommendations for users, project teams and the broader industry.

1240
Crypto losses hit about $97 million in July as cross-chain bridge attacks topped $35 million
PeckShield
2026-08-01 03:10:57

PeckShield says crypto hacks caused $210.3 million in losses in July

PeckShield tracked 30 major hacking incidents across the crypto industry in July, with total losses reaching $210.3 million. The figure was up 177.2% from June, when losses stood at $75.87 million. Among the incidents listed, the COLDCARD case accounted for about $70 million, making it the third-largest cryptocurrency theft recorded so far this year, according to the update cited by ChainCatcher. Other large losses in July included AFX Trade on Arbitrum at about $24 million, Ostium at about $24 million, BONK at about $21.2 million, and Wanchain at about $13 million. The list also included Triple-A, Bonzo Lend, Verus, WEMIX, and Summer.fi, each with reported losses ranging from roughly $6 million to $10 million. The figures were published in a market security update referenced by ChainCatcher.

1140
PeckShield says crypto hacks caused $210.3 million in losses in July
Onchain Lens
2026-07-25 07:40:52

Onchain Lens says 224 crypto hacks caused about $1.32 billion in losses in the first half of 2026

Onchain Lens said in a post on X that 224 publicly disclosed crypto hacking incidents were recorded in the first half of 2026, with total losses reaching about $1.32 billion. The largest losses came from access control failures, phishing attacks and oracle-related issues. Within the access control category, compromised permissions and privileged access were tied to several of the biggest incidents, including Kelp DAO with losses of $292 million and Drift Protocol with $280 million. Other named cases in that group included Humanity Protocol, Step Finance, Truebit, Resolv Labs, AFX and BonkDAO. Onchain Lens also said social engineering attacks caused $282 million in losses. For oracle-related incidents, the post listed Ostium, Blend Protocol and Bonzo. The data points to a familiar pattern in crypto security: a small number of incidents accounted for a large share of total losses, with compromised permissions and privileged access standing out among the costliest attack vectors disclosed during the period.

1170
Onchain Lens says 224 crypto hacks caused about $1.32 billion in losses in the first half of 2026
Ethereum
2026-07-17 07:41:25

Jito routes JTX revenue to JTO buybacks as ETH treasury firms step into protocol funding

A MarsBit feature published on July 17 argues that two separate developments may reshape parts of the crypto market: Jito DAO is trying to hardwire token value capture through JIP-38, while Ethereum treasury companies such as Bitmine and SharpLink are starting to fund protocol development as the Ethereum Foundation tightens spending. According to the article, JIP-38 would send JTX revenue allocated to the DAO into programmatic open-market buybacks and burns of JTO through at least the fourth quarter of 2027. The proposal gives the DAO 80% of JTX platform fees, with the remaining 20% reserved for reinvestment into the same platform. The piece argues that the real test is not rhetoric about “token-centric” models, but who receives revenue, who can shut off the burn mechanism, whether governance can remove operators, and whether company income has actually been redirected to token holders before. On Ethereum, the article says the funding mix is changing. After staff cuts and budget reductions at the Ethereum Foundation, new entities such as ETH Labs, Ethereum Institutional, and EthSystems emerged in quick succession. Behind that shift, the piece points to Bitmine, SharpLink, and Joe Lubin. It frames treasury companies’ move into protocol spending as a response to shrinking mNAV multiples and underwater ETH positions, with staking yield becoming a possible source of self-sustaining research and development capital.

1560
Jito routes JTX revenue to JTO buybacks as ETH treasury firms step into protocol funding
Ostium
2026-07-17 05:32:11

Ostium hit by oracle report exploit as five-minute incident drains up to $24 million

Onchain perpetuals platform Ostium said a five-minute security incident hit its public Ostium Liquidity Provider, or OLP, vault on July 15 between 14:18 and 14:23 UTC. Third-party security firms said the issue was not a missing signature. Instead, they said a registered PriceUpKeep forwarder submitted authorized oracle reports carrying future timestamps, which then generated false trading profits. Public loss estimates vary. Blockaid put the payout near $18 million, Cyvers estimated $23.7 million, and PeckShield later said about $24 million had been drained. SlowMist cited a lower figure of $11.86 million, apparently based on a visible vault outflow of 11,862,444.782 USDC in a referenced transaction. Ostium co-founder Kaledora Kiernan-Linn said the team detected the issue within minutes and coordinated a trading pause within an hour. She also said the protocol is working with law enforcement, SEAL 911, and outside security experts. Ostium has not yet published a final loss total, root-cause analysis, or post-mortem report. The case differs from Bonzo Lend’s recent Hedera incident, where the validator reportedly accepted a proof without a valid signature. In Ostium’s case, security firms said authentication passed, but the data itself was unsafe.

1090
Ostium hit by oracle report exploit as five-minute incident drains up to $24 million
Policy and Re
2026-07-17 02:14:00

July 17 crypto policy and market roundup: SEC proposes e-delivery rule, CFTC probes Kalshi-linked trades

A broad set of crypto, payments, regulatory and AI developments emerged between July 16 and July 17. CoinGecko’s 2026 second-quarter report showed total crypto market capitalization fell 12.6% to $2.1 trillion by the end of June, while stablecoin market cap slipped 1.6% to $305.1 billion, marking its first decline since Q3 2023. Centralized exchange spot volume dropped 27.9% to $1.95 trillion, but prediction market notional volume rose 48.7% to $113.8 billion. In Washington, the U.S. Securities and Exchange Commission proposed a new Regulation E-Delivery framework that would let issuers, broker-dealers and investment advisers default to electronic delivery for a wide range of required disclosures, with a 60-day public comment period after publication in the Federal Register. Separately, the Commodity Futures Trading Commission is investigating whether trading on Kalshi involving alleged early access to Trump speech content may have relied on nonpublic information. Corporate and product announcements also accelerated. Visa launched its Visa Stablecoin Platform, while Flex raised $70 million for its stablecoin-based cross-border banking platform. Crypto.com disclosed a $400 million strategic investment from Citadel Securities at a $20 billion valuation, and T. Rowe Price launched TKNZ, described as the first actively managed multi-token spot crypto ETF. Binance, MoonPay, Alpaca, Fireworks, Ethena and several other firms also announced new listings, acquisitions, funding rounds or ecosystem expansions.

1780
July 17 crypto policy and market roundup: SEC proposes e-delivery rule, CFTC probes Kalshi-linked trades