Back to Blog

Newsletter - July 2026

Code Auditing
July 31, 2026
4 min read
Key Insights
  • AFX Trade lost ~$24.15M after a supply-chain compromise enabled valid bridge validator signatures.

  • Ostium lost ~$23.75M when compromised oracle authority submitted signed fake prices draining the vault.

  • BonkDAO lost ~$20M via low-cost governance capture, enabled by weak quorum economics and no timelock.

Top 3 DeFi Incidents in July 2026

AFX Trade: ~$24.15M

On July 22, 2026, AFX Trade, an Arbitrum-based perpetuals protocol, suffered a security breach, resulting in approximately $24.15 million in losses.

The incident stemmed from a software supply chain attack, rather than a vulnerability in the bridge contract's signature-verification logic. According to AFX's post-mortem, the attack began on July 9, when a developer was tricked through Telegram into downloading a project containing malicious code. This allowed the attacker to compromise the development environment, gain access to internal systems, and ultimately obtain signing authority over the bridge's validator infrastructure.

The attack transaction trace shows that the five validator signatures submitted by the attacker passed the contract's checks. The active validator set had a total voting power of 10,000, while the five signatures represented 7,142, exceeding the required two-thirds threshold. The contract therefore processed the malicious withdrawal according to its rules. However, onchain evidence alone cannot determine whether the authorized validator keys were stolen or misused through other means. The stolen USDC was later moved to Ethereum and swapped for approximately 12,467 ETH. AFX stated that the incident was limited to its own custody bridge, with no evidence that the Arbitrum network or native Arbitrum bridge was compromised.

Ostium: ~$23.75M

On July 15, 2026, Ostium, an Arbitrum-based perpetuals protocol, suffered an Oracle-related attack that drained approximately $23.75 million from its OLP liquidity vault.

Ostium lets users trade perpetual contracts tracking stocks, foreign exchange, crypto assets, and other markets without holding the underlying assets. Trading PnL is settled against the USDC-funded OLP vault. If the settlement price is controlled, the vault can therefore be made to pay profits that never occurred in the real market.

The incident stemmed from a compromise of the offchain price infrastructure. The attacker used trusted Oracle-signing authority and a registered PriceUpKeep forwarder to submit correctly signed price reports with attacker-controlled timestamps. The onchain verifier authenticated the signer but could not establish that the reported price was genuine. In the largest executeBatch() transaction, the attacker repeatedly opened and closed BTC/USD positions. Onchain events show positions opened using an input price near $5,000 and settled near $60,000. Starting with roughly 1,000 USDC, the attacker increased the position size over successive loops and extracted about 11.86 million USDC from the OLP vault in one atomic transaction. All eight payout transactions went to the same address, totaling approximately $23.75 million, before the trading contracts were frozen.

BonkDAO: ~$20M

On July 6, 2026, BonkDAO on Solana suffered a governance attack, resulting in losses of approximately $20 million.

BonkDAO manages its community treasury through Solana Realms. BONK holders receive voting power based on their token balance, and proposals that meet quorum can execute treasury instructions through the governance program. The attacker exploited this process rather than a code vulnerability.

The root cause was that voting power could be concentrated at a cost far below the treasury value, while large transfers had no execution delay. On June 30, the attacker submitted BIP #76 with an onchain instruction transferring 4,426,104,450,305 BONK to their address, then spent about $4.4 million acquiring BONK. When the six-day voting period ended, the proposal had 882.38 billion votes, narrowly above the 879.95 billion threshold. Only seven addresses voted, and the attacker controlled about 99.9% of the supporting votes.

With no timelock, the proposal executed immediately and moved roughly $20 million in BONK to the attacker. About nine hours later, approximately $188,000 reached a centralized exchange, while the remaining $19 million was transferred to a multisig controlled by attacker-linked addresses.

These incidents demonstrate that a DeFi protocol's security boundary extends far beyond its smart-contract code. In both the AFX Trade and Ostium incidents, onchain verification operated according to its configured rules, but compromised development systems, validator infrastructure, or oracle authorities allowed malicious actions to appear as valid requests. BonkDAO likewise shows that even correctly functioning governance code can expose a treasury when voting thresholds are economically weak and execution delays are absent. Protocol teams and security reviewers should therefore evaluate offchain infrastructure with the same rigor applied to smart contracts, while continuously assessing the maximum loss that could result from the compromise of any single authority or infrastructure component.

The information above is based on data available as of 00:00 UTC on July 30, 2026.

Best Security Auditor for Web3

Validate design, code, and business logic before launch

References🔗

AFX Trade

Ostium

BonkDAO

The information above is based on data as of 00:00 UTC, July 30, 2026.

This concludes the July security incidents brief.

You can learn more in our Security Incidents Library.

Stay informed and stay secure!

Sign up for the latest updates
~$11.3M Lost: Multicall Router, Nostra | BlockSec Weekly
Security Insights

~$11.3M Lost: Multicall Router, Nostra | BlockSec Weekly

This report, covering 2026/09/14 - 2026/09/20, examines two security incidents with approximately $11.3M in combined losses, on Ethereum and Starknet. In the larger one, a multicall router accepted its own address as a dispatch target, so the nested call reached the Gateway module of a Safe wallet carrying the router's own already-authorized identity instead of the external caller's, and roughly 2,900 `aEthrsETH` was routed out of that wallet into an attacker-created Uniswap v4 pool. On Starknet, Nostra's oracle integration required a minimum of only one aggregated source, so when only two of the three configured price sources reached the aggregation, a manipulated thin-pool quote averaged with a normal quote to value `NSTR` at roughly $49.52, supporting approximately $3.5M of borrowing against overvalued collateral.

~$320M Lost: Liquid Network, Symbiosis Exploits | BlockSec
Security Insights

~$320M Lost: Liquid Network, Symbiosis Exploits | BlockSec

This report, covering 2026/09/07 - 2026/09/13, examines two security incidents that caused approximately $320M in losses, including the Liquid Network exploit of 2026/09/06 that the previous report did not cover. The larger was that Liquid Network exploit, where the rangeproof validation cache in Elements derived its key by hashing four fields — two of them variable in length — concatenated with nothing marking the boundaries between them, so a verdict recorded for one output was returned for another whose proof was never examined, letting the attacker create 4,000 unbacked L-BTC and peg out nearly all of them as bitcoin. On the Bitcoin route of the Symbiosis cross-chain bridge, spanning BNB Smart Chain, Ethereum and Rootstock, off-chain code that reads Bitcoin deposits took the depositor's identity from a field the depositor controls and then subtracted its fee from the deposit without checking whether the fee itself was negative, letting a 330-satoshi deposit mint `46,116,860,184.27388234 syBTC`; the pools it had to be sold through held only 11.26 syBTC, so the loss to liquidity providers and users came to an estimated 9.97 BTC (~$770K).

~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly
Security Insights

~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly

During the past week (2026/08/31 - 2026/09/06), four security incidents caused approximately $9.4M in losses across Injective, Solana, Ethereum, and Flow EVM. The largest was the Injective exploit, where an insurance fund identifier collided with a binary options market identifier and the settlement path never compared their denominations, draining about $4.8M; Aquifer on Solana lost about $2.47M because its swap path invoked an unvalidated caller-supplied Token Program, and Notional Finance V1 on Ethereum lost about $1.73M to an unchecked `uint128` cast that valued a debt at zero. Ankr FLOW on Flow EVM closed out the week with about $410K drained through a staking entry point that skipped its pause guard and minted against a stale ratio.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit