Crypto Hack Roundup: The 8 Biggest DeFi Exploits of July 2026 July 2026 was a rough month for DeFi security. Eight separate protocols lost a combined total of over $110 million to attackers.
Crypto Hack Roundup: The 8 Biggest DeFi Exploits of July 2026
July 2026 was a rough month for DeFi security. Eight separate protocols lost a combined total of over $110 million to attackers.
What stands out isn't new smart contract bugs. Nearly every crypto hack this month traced back to compromised keys, governance manipulation, permission failures, or operational mistakes.

This breakdown covers what happened, why it happened, and what each project has done since.
July 2026 Crypto Hack Overview
Project
Amount Lost
Attack Type
Status
AFX Trade
$24.15M
Compromised bridge keys
Investigating, bounty offered
Ostium
$23.75M
Compromised oracle signer key
Trading resumed, funds unrecovered
BonkDAO
$20M
Governance takeover
Reported to law enforcement
Wanchain
~$10M
Signature reuse
Bridge offline, bounty deadline set
Triple-A
$9.7M
Hot wallet breach
Services restored
Bonzo Finance
$9M
Oracle manipulation
Lending paused, oracle patched
Verus Bridge
$7.54M
Unpatched bridge bug
Partial recovery via bounty
Summer.fi
$6M
Stale collateral valuation
Protocol shutting down
Breakdown of Each Exploit
AFX Trade
What happened: On July 22, an attacker gained control of validator signing keys for AFX's custody bridge on Arbitrum and withdrew funds without restriction.
Root cause:Compromised off-chain signing keys, not a smart contract flaw. Arbitrum's native infrastructure was untouched.
Amount exploited: $24.15 million in USDC, swapped for roughly 12,467 ETH.
User impact: The drain hit nearly all of AFX's total value locked.
Current update: AFX publicly offered the attacker a 70/30 bounty split.
Ostium
What happened: On July 15, an attacker used a compromised oracle signer key to submit fake price reports, manufacturing artificial trading profits.
Root cause:A stolen off-chain credential, not a code bug. Trader collateral in separate contracts was unaffected.
Amount exploited: $23.75 million drained from the liquidity vault.
User impact: The vault lost close to a third of its holdings; trader funds stayed isolated.
Current update: Trading resumed July 23; stolen funds remain unrecovered.
BonkDAO
What happened: On July 6, an attacker spent roughly $4 million buying BONK tokens to gain majority voting power, then passed a proposal draining the treasury.
Root cause: Governance manipulation. Low voter turnout let a single wallet dominate the vote; no code was exploited.
Amount exploited:Approximately $20 million in BONK tokens.
User impact: BONK price dropped roughly 8-10% following disclosure.
Current update: BonkDAO involved law enforcement and is coordinating with exchanges to trace funds.
Wanchain
What happened: On July 20-21, an attacker reused a valid signature meant for a small withdrawal to drain a much larger amount from the Cardano-BNB bridge.
Root cause: A signature-reuse flaw in message encoding, a permissions and validation failure rather than a new contract bug.
Amount exploited:About 515.2 million NIGHT tokens, roughly $10 million.
User impact: NIGHT token price fell sharply before partially recovering.
Current update: Wanchain offered the attacker a white-hat deadline of August 6.
Triple-A
What happened: On July 24-25, attackers gained access to Triple-A's hot wallets across multiple chains and drained funds.
Root cause: Hot wallet compromise, a key management and access control failure.
Amount exploited:$9.7 million initially reported (later estimates rose higher to $11.8 million).
User impact: Company said customer funds, held separately in trust, were unaffected.
Current update: Services were restored after a temporary pause.
Bonzo Finance
What happened: On July 11, an attacker deposited a tiny amount of SAUCE tokens, then manipulated the oracle to report a massively inflated price.
Root cause: A third-party oracle verifier accepted an invalid signature, a permissions failure outside Bonzo's own contracts.
Amount exploited: Roughly $9.05 million borrowed against the fake collateral value.
User impact: Lending and rewards were paused; other Bonzo products stayed active.
Current update: Oracle provider Supra patched the verifier.
Verus Bridge
What happened: On July 22-23, an attacker exploited the same vulnerability class that hit the Verus-Ethereum bridge back in May.
Root cause: An unpatched bridge bug, essentially an operational failure to fully close a known weakness.
Amount exploited: $7.54 million, converted to ETH.
User impact: Bridge liquidity took a direct hit.
Current update: The attacker returned roughly 75% of funds after a bounty offer.
Summer.fi
What happened: On July 6, an attacker used a $65.4 million flash loan to exploit stale valuation data left over from an incomplete vault offboarding process.
Root cause: Operational failure. A retired vault's stale token value stayed accounted for in the main vault's total assets.
Amount exploited:$6 million redeemed from two USDC vaults.
User impact: SUMR token fell over 18%; vaults were paused immediately.
Current update: Summer.fi is winding down operations, with the app staying live through August 31 while governance shifts to a DAO.
Market Impact
This wave of incidents shook confidence beyond any single protocol. Each crypto hack this month added to a broader sense that DeFi security still has structural gaps.
Governance security came under fresh scrutiny after BonkDAO showed how cheaply a treasury vote can be bought when turnout is low.
Operational security, not audited code, was the common failure point across AFX, Ostium, Triple-A, and Bonzo. Off-chain keys, oracle signers, and hot wallets sit outside what a standard smart contract audit checks.
DeFi's total value locked contracted through this stretch as users pulled funds from platforms seen as exposed, and DeFi protocols across the board began reviewing multisig setups, oracle redundancy, and vault accounting logic.
Conclusion
Eight incidents, over $110 M lost, and almost none of it from a freshly written smart contract bug. This crypto hack wave points to a clear pattern: keys, governance votes, oracle permissions, and operational processes are now the primary attack surface in DeFi.
The security insight worth remembering: audited code alone doesn't protect a protocol. The infrastructure sitting around that code, who holds the keys, who votes, and who verifies the data, needs the same scrutiny.
Disclaimer
This article is for informational purposes only and is not financial advice. Always do your own research before investing.