Back to Blog

Newsletter - July 2026

Code Auditing
July 31, 2026
4 min read
Key Insights

Top 3 DeFi Incidents in July 2026

AFX Trade: ~$24.15M

On July 22, 2026, AFX Trade, an Arbitrum-based perpetuals protocol, suffered a security breach, resulting in approximately $24.15 million in losses.

The incident stemmed from a software supply chain attack, rather than a vulnerability in the bridge contract's signature-verification logic. According to AFX's post-mortem, the attack began on July 9, when a developer was tricked through Telegram into downloading a project containing malicious code. This allowed the attacker to compromise the development environment, gain access to internal systems, and ultimately obtain signing authority over the bridge's validator infrastructure.

The attack transaction trace shows that the five validator signatures submitted by the attacker passed the contract's checks. The active validator set had a total voting power of 10,000, while the five signatures represented 7,142, exceeding the required two-thirds threshold. The contract therefore processed the malicious withdrawal according to its rules. However, onchain evidence alone cannot determine whether the authorized validator keys were stolen or misused through other means. The stolen USDC was later moved to Ethereum and swapped for approximately 12,467 ETH. AFX stated that the incident was limited to its own custody bridge, with no evidence that the Arbitrum network or native Arbitrum bridge was compromised.

Ostium: ~$23.75M

On July 15, 2026, Ostium, an Arbitrum-based perpetuals protocol, suffered an Oracle-related attack that drained approximately $23.75 million from its OLP liquidity vault.

Ostium lets users trade perpetual contracts tracking stocks, foreign exchange, crypto assets, and other markets without holding the underlying assets. Trading PnL is settled against the USDC-funded OLP vault. If the settlement price is controlled, the vault can therefore be made to pay profits that never occurred in the real market.

The incident stemmed from a compromise of the offchain price infrastructure. The attacker used trusted Oracle-signing authority and a registered PriceUpKeep forwarder to submit correctly signed price reports with attacker-controlled timestamps. The onchain verifier authenticated the signer but could not establish that the reported price was genuine. In the largest executeBatch() transaction, the attacker repeatedly opened and closed BTC/USD positions. Onchain events show positions opened using an input price near $5,000 and settled near $60,000. Starting with roughly 1,000 USDC, the attacker increased the position size over successive loops and extracted about 11.86 million USDC from the OLP vault in one atomic transaction. All eight payout transactions went to the same address, totaling approximately $23.75 million, before the trading contracts were frozen.

BonkDAO: ~$20M

On July 6, 2026, BonkDAO on Solana suffered a governance attack, resulting in losses of approximately $20 million.

BonkDAO manages its community treasury through Solana Realms. BONK holders receive voting power based on their token balance, and proposals that meet quorum can execute treasury instructions through the governance program. The attacker exploited this process rather than a code vulnerability.

The root cause was that voting power could be concentrated at a cost far below the treasury value, while large transfers had no execution delay. On June 30, the attacker submitted BIP #76 with an onchain instruction transferring 4,426,104,450,305 BONK to their address, then spent about $4.4 million acquiring BONK. When the six-day voting period ended, the proposal had 882.38 billion votes, narrowly above the 879.95 billion threshold. Only seven addresses voted, and the attacker controlled about 99.9% of the supporting votes.

With no timelock, the proposal executed immediately and moved roughly $20 million in BONK to the attacker. About nine hours later, approximately $188,000 reached a centralized exchange, while the remaining $19 million was transferred to a multisig controlled by attacker-linked addresses.

These incidents demonstrate that a DeFi protocol's security boundary extends far beyond its smart-contract code. In both the AFX Trade and Ostium incidents, onchain verification operated according to its configured rules, but compromised development systems, validator infrastructure, or oracle authorities allowed malicious actions to appear as valid requests. BonkDAO likewise shows that even correctly functioning governance code can expose a treasury when voting thresholds are economically weak and execution delays are absent. Protocol teams and security reviewers should therefore evaluate offchain infrastructure with the same rigor applied to smart contracts, while continuously assessing the maximum loss that could result from the compromise of any single authority or infrastructure component.

The information above is based on data available as of 00:00 UTC on July 30, 2026.

Best Security Auditor for Web3

Validate design, code, and business logic before launch

References🔗

AFX Trade

Ostium

BonkDAO

The information above is based on data as of 00:00 UTC, July 30, 2026.

This concludes the July security incidents brief.

You can learn more in our Security Incidents Library.

Stay informed and stay secure!

Sign up for the latest updates
~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly
Security Audits

~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly

During the week of July 20-26, 2026, 8 notable security incidents resulted in approximately $39.5M in total losses across Solana, Ethereum, BNB Chain, Arbitrum, Zilliqa, and Cardano. The highlighted Allbridge Core incident (~$1.65M) exposed a Solana input validation flaw where the same Pool account was accepted in both swap roles, with analysis reconstructed entirely from the deployed program binary. Other analyzed incidents include Wanchain (~$500K, flawed message encoding in a Cardano bridge validator), Zilliqa (~$400K, flawed nonce generation in a Ledger app since 2019), and Lien Finance (~$542K, flawed validation logic in bond exchange).

~$1.35M Lost: BarnBridge, DeFiTuna | BlockSec Weekly
Security Insights

~$1.35M Lost: BarnBridge, DeFiTuna | BlockSec Weekly

This weekly report covers 2 security incidents from July 13 to July 19, 2026, with approximately $1.35M in total losses on Ethereum and Solana. DeFiTuna, a Solana lending protocol, lost ~$570K because the position health check treated a zero-value position as healthy regardless of outstanding debt; the attacker used controlled swap routing and a separate low-liquidity pool to trigger this defect. BarnBridge lost ~$776K after an attacker exploited the protocol's deprecated but still-active governance system on Ethereum to pass a malicious proposal and drain user-approved USDC.

~$800K Lost: Hinkal Double-Spend | BlockSec Weekly
Security Insights

~$800K Lost: Hinkal Double-Spend | BlockSec Weekly

This weekly security report covers 1 notable incident from June 29 to July 5, 2026, with approximately $800K in total losses on Ethereum. The Hinkal shielded-pool protocol was drained through a double-spend attack that likely exploited a flaw in the legacy note format, allowing the attacker to derive multiple nullifiers from a single deposit. The report analyzes the probable circuit-level vulnerability, the attack flow, and broader implications for nullifier-based privacy protocols.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit