Top 3 DeFi Incidents in July 2026
AFX Trade: ~$24.15M
On July 22, 2026, AFX Trade, an Arbitrum-based perpetuals protocol, suffered a security breach, resulting in approximately $24.15 million in losses.
The incident stemmed from a software supply chain attack, rather than a vulnerability in the bridge contract's signature-verification logic. According to AFX's post-mortem, the attack began on July 9, when a developer was tricked through Telegram into downloading a project containing malicious code. This allowed the attacker to compromise the development environment, gain access to internal systems, and ultimately obtain signing authority over the bridge's validator infrastructure.
The attack transaction trace shows that the five validator signatures submitted by the attacker passed the contract's checks. The active validator set had a total voting power of 10,000, while the five signatures represented 7,142, exceeding the required two-thirds threshold. The contract therefore processed the malicious withdrawal according to its rules. However, onchain evidence alone cannot determine whether the authorized validator keys were stolen or misused through other means. The stolen USDC was later moved to Ethereum and swapped for approximately 12,467 ETH. AFX stated that the incident was limited to its own custody bridge, with no evidence that the Arbitrum network or native Arbitrum bridge was compromised.
Ostium: ~$23.75M
On July 15, 2026, Ostium, an Arbitrum-based perpetuals protocol, suffered an Oracle-related attack that drained approximately $23.75 million from its OLP liquidity vault.
Ostium lets users trade perpetual contracts tracking stocks, foreign exchange, crypto assets, and other markets without holding the underlying assets. Trading PnL is settled against the USDC-funded OLP vault. If the settlement price is controlled, the vault can therefore be made to pay profits that never occurred in the real market.
The incident stemmed from a compromise of the offchain price infrastructure. The attacker used trusted Oracle-signing authority and a registered PriceUpKeep forwarder to submit correctly signed price reports with attacker-controlled timestamps. The onchain verifier authenticated the signer but could not establish that the reported price was genuine. In the largest executeBatch() transaction, the attacker repeatedly opened and closed BTC/USD positions. Onchain events show positions opened using an input price near $5,000 and settled near $60,000. Starting with roughly 1,000 USDC, the attacker increased the position size over successive loops and extracted about 11.86 million USDC from the OLP vault in one atomic transaction. All eight payout transactions went to the same address, totaling approximately $23.75 million, before the trading contracts were frozen.
BonkDAO: ~$20M
On July 6, 2026, BonkDAO on Solana suffered a governance attack, resulting in losses of approximately $20 million.
BonkDAO manages its community treasury through Solana Realms. BONK holders receive voting power based on their token balance, and proposals that meet quorum can execute treasury instructions through the governance program. The attacker exploited this process rather than a code vulnerability.
The root cause was that voting power could be concentrated at a cost far below the treasury value, while large transfers had no execution delay. On June 30, the attacker submitted BIP #76 with an onchain instruction transferring 4,426,104,450,305 BONK to their address, then spent about $4.4 million acquiring BONK. When the six-day voting period ended, the proposal had 882.38 billion votes, narrowly above the 879.95 billion threshold. Only seven addresses voted, and the attacker controlled about 99.9% of the supporting votes.
With no timelock, the proposal executed immediately and moved roughly $20 million in BONK to the attacker. About nine hours later, approximately $188,000 reached a centralized exchange, while the remaining $19 million was transferred to a multisig controlled by attacker-linked addresses.
These incidents demonstrate that a DeFi protocol's security boundary extends far beyond its smart-contract code. In both the AFX Trade and Ostium incidents, onchain verification operated according to its configured rules, but compromised development systems, validator infrastructure, or oracle authorities allowed malicious actions to appear as valid requests. BonkDAO likewise shows that even correctly functioning governance code can expose a treasury when voting thresholds are economically weak and execution delays are absent. Protocol teams and security reviewers should therefore evaluate offchain infrastructure with the same rigor applied to smart contracts, while continuously assessing the maximum loss that could result from the compromise of any single authority or infrastructure component.
The information above is based on data available as of 00:00 UTC on July 30, 2026.
Best Security Auditor for Web3
Validate design, code, and business logic before launch
References🔗
AFX Trade
-
BlockSec security alert: https://x.com/Phalcon_xyz/status/2080139684790092275
-
Official announcement: https://x.com/AFX_XYZ/status/2080126901205770734
-
Official post-mortem: https://medium.com/@AFXTrade/afx-bridge-incident-what-happened-what-we-learned-and-what-comes-next-d97387746012
-
Attack transaction: https://app.blocksec.com/phalcon/explorer/tx/arbitrum/0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74
Ostium
-
BlockSec security alert: https://x.com/Phalcon_xyz/status/2077423604208439703
-
Official announcement: https://x.com/Ostium/status/2078640436688941194
-
Official post-mortem: https://x.com/Ostium/status/2082540358219747422
-
Attack transaction: https://app.blocksec.com/phalcon/explorer/tx/arbitrum/0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0
BonkDAO
-
BlockSec security alert: https://x.com/BlockSecTeam/status/2074335424328392874
-
Official announcement: https://x.com/bonk_inu/status/2074191403781906800
-
Governance and incident details: https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal
The information above is based on data as of 00:00 UTC, July 30, 2026.
This concludes the July security incidents brief.
You can learn more in our Security Incidents Library.
Stay informed and stay secure!



