July 2026: the losses keep climbing
6 views
July 2026 was the third straight month of rising crypto losses tracked by 0xposed Lab: ~$191M across 39 confirmed incidents, up 34.4% from June's $142.2M and more than double May's $82M. Unlike June — where two outliers (SIREN Token's $64.8M whale dump and Humanity Protocol's $36M DPRK-linked phishing campaign) accounted for 71% of the total — July's losses were spread thin. No single incident cleared $40M, and the top ten incidents span oracle manipulation, bridge signature flaws, a Bitcoin hardware-wallet RNG bug, and a governance takeover of a meme-coin treasury.

The month's defining pattern: private-key, signer, and operator-key compromise dominated. Ten incidents in this category alone account for 61.3% of July's losses (~$117M) — more than triple the smart-contract code exploits and bridge failures combined.

The top ten
Coldcard Mk3 RNG — $38.3M. A 2021-era firmware bug silently downgraded seed-phrase randomness on Coldcard Mk3 hardware wallets to roughly 40 bits of entropy. An attacker swept 594 BTC from ~500 wallets in a 25-minute window on July 31. Disclosed by Coinkite; traced by Block's security engineering team.
AFX Trade — $24.15M. Five of seven hot-validator signing keys were compromised on the Arbitrum perpetuals DEX's bridge, draining virtually the entire bridge TVL. Attribution: North Korea's UNC4899/TraderTraitor group. Detected by Blockaid; attributed by zeroShadow and SEAL, confirmed by AFX.
BonkDAO Governance Attack — $20M. An attacker spent ~$4.4M buying BONK to clear a governance quorum met by just 7 wallets (2.9% turnout), then executed a malicious proposal draining the DAO treasury. Traced by PeckShield and Lookonchain.
Ostium — $18M. A compromised oracle signer key combined with a registered price-update forwarder let an attacker submit properly-signed but fabricated BTC/USD prices, looping ~10-20 cycles to drain the vault. Only LPs lost funds; no retail trader positions were affected. Flagged by Blockaid.
Solana Genesis Whale — $14.2M. A wallet tied to Solana's original genesis block distribution was drained via irregular unstaking and bridged to Ethereum; the compromise vector remains formally unconfirmed. Investigated jointly by ZachXBT and Specter.
Triple-A — $11.8M. A Singapore-licensed payment gateway's hot wallets across six chains were drained over 31 hours before the team noticed — deposits stayed open the entire time. Client funds in segregated trust accounts were unaffected. First flagged by Specter, amplified by PeckShield.
Wanchain NIGHT — $10M. A Cardano bridge contract concatenated redeemer fields without delimiters, letting a signature authorizing ~3,110 NIGHT be replayed for a 203M-token withdrawal — a ~65,000x amplification. Root-caused by BlockSec Phalcon.
Bonzo Lend — $9.05M. A zeroed BLS signature bypassed Supra's oracle verifier on Hedera, inflating a collateral token's price 12 orders of magnitude; the attacker borrowed against it eight seconds later. Bonzo later announced full position restoration backed by the Hedera Foundation. Identified by @SpecterAnalyst.
Crypto DAO — $8.2M. A publicly callable "Attack" function on a BSC token vault let an attacker loop a reserve-manipulation exploit at least 12 times. Flagged by Blockaid.
Verus Ethereum Bridge (2nd exploit) — $7.54M. The same bridge, the same contract, the same unpatched submitImports flaw that cost $11.58M in May — Verus redeposited recovered funds into the vulnerable contract without patching it, and a different attacker returned to exploit it again in July.

The geography of the losses
Arbitrum and Bitcoin led July's chain totals — Arbitrum on the back of AFX Trade, Ostium, Cascade, and Lumi Finance (~$43.8M across 4 incidents), Bitcoin on the strength of a single event, the Coldcard sweep, plus Ill Bloom's residual drain (~$43.3M across 2 incidents). Solana followed close behind with six separate incidents totaling ~$36.5M, led by BonkDAO's governance attack and the Solana genesis-whale compromise. Ethereum carried the widest spread — 12 incidents, but only ~$20M total — reflecting a long tail of smaller smart-contract and phishing losses rather than a single large drain.

Three trends that define the month
Key and signer compromise eclipsed every other attack class. AFX Trade's validator keys, Ostium's oracle signer, the Solana genesis whale's unstaking authority, Triple-A's hot wallets, Cascade's operator key — six-figure and seven-figure losses traced back to a compromised key rather than a contract bug. This is the same vector class that cost Bybit $1.5B in February 2025, and July shows no sign it is going away.
Bridges that got exploited once got exploited again. Verus patched nothing after its $11.58M May exploit and redeposited recovered funds straight into the same vulnerable contract — a second attacker drained $7.54M from it in July. Allbridge Core suffered its second flash-loan exploit of the same class first seen in 2023. Garden Finance was hit for the second time in under a year. Patch-once-and-move-on is not holding up against attackers who are clearly re-checking previously exploited targets.
Hardware and firmware are now squarely in scope. The Coldcard Mk3 RNG flaw — a five-year-old bug traced to a March 2021 libsecp256k1 migration — cost more than any single software exploit this month. Zilliqa's Ledger app carried a parallel nonce-generation flaw allowing private-key recovery via lattice reduction. Both cases show that "audit the smart contract" is no longer sufficient; the hardware and firmware supply chain is an equally live attack surface.
"So there is no contract exploit or anything like this" — an independent investigator's read on the Cascade incident, describing a pattern seen across multiple July incidents: professional-grade, multi-day rehearsed extractions through a compromised signer or operator key, not a broken line of Solidity.
Who caught it
Blockaid was the most active detector this month, publicly flagging or co-reporting 7 incidents in real time — Summer.fi, Lumi Finance, Ostium, Garden Finance, AFX Trade, Crypto DAO and more. CertiK and SlowMist each attributed 5, with Specter and PeckShield close behind on the hot-wallet and key-compromise cases. As in prior months, sub-$1M incidents (Lien Finance, LULA, 42DAO) surfaced almost exclusively through SlowMist's Hacked database and specialist X accounts — mainstream coverage remains thin below the seven-figure mark.

Recovery collapsed
May saw a bimodal but meaningfully positive recovery pattern: incidents caught live with an open negotiation channel returned 73-90% of stolen funds. July broke that pattern almost entirely. Every incident in the July top ten remains unrecovered at time of writing. The only clean recoveries were smaller: FlashTrade's $98K was 100% reimbursed by the protocol and MagicBlock jointly (not recovered from the attacker), and ChainConnect negotiated an 82.9% whitehat return on its $615K bridge exploit. AFX Trade's attacker was offered a standard 70/30 split and, as of the most recent update, had not accepted — instead moving to launder roughly 57% of the haul through THORChain within three days.

What to do about it
If you operate any kind of signer, validator, or oracle infrastructure: treat every hot key as a target, not a convenience. Multi-party computation or hardware-backed signing with a tested rotation plan should be the floor, not an upgrade — AFX Trade, Ostium, Bonzo, and Triple-A were all lost to exactly this gap.
If you've patched a bridge or contract after an exploit: verify the fix actually shipped before moving recovered or new funds back into it. Verus's second $7.54M loss happened because recovered funds were redeposited into the same unpatched contract.
If you hold funds on a hardware wallet: check your device and firmware version against the Coldcard and Zilliqa Ledger advisories. A wallet's security model is only as good as its random number generator, and RNG bugs can sit undetected for years.
If you run a DAO with on-chain governance: audit your quorum mechanics. BonkDAO's proposal passed with just 7 wallets voting (2.9% turnout), and the attacker drained a treasury worth roughly 4.5x what it cost them to acquire quorum-clearing voting power.
If you're a user: revoke unused token approvals regularly, verify any "official" memecoin or airdrop announcement through a second channel before trading — SCATMAN and the Robinhood $VLAD hijack both spread through compromised, previously-trusted X accounts.
A few caveats
Three incidents were excluded from July's totals because the underlying exploit predates the window: Gnosis Pay ($1.5M, exploited June 1, post-mortem published July 3), Namada Shielded Pools (~$600K, drained mid-June), and Lixir Finance ($12.3K, exploited June 25). Chi Protocol ($8,597, exploit and disclosure both fell within the July window) was separately flagged Bucket B by the team and is excluded as a case study rather than a headline incident.
Reported totals vary by source on several incidents: Wanchain NIGHT ranges from $6.5M (DeFiLlama) to $13M (CoinGape) — we use SlowMist's $10M. Ostium ranges from $11.86M (confirmed on-chain, SlowMist) to $24M (PeckShield's full trace) — we use Blockaid's $18M, the figure most consistently cited.
Ill Bloom's confirmed theft is $5M from the May 27 coordinated sweep; a further ~$2M in wallet movements after the July 5 public disclosure may partly reflect users proactively self-migrating funds, not confirmed theft, and is excluded from the total.
Six incidents in this month's count carry no dollar loss and contribute $0 to the totals above, but are included in the 39-incident count and the vector/chain breakdowns: npm Supply-Chain Campaign, Injective SDK Backdoor, jscrambler npm, Prism, Across Protocol (Risk Labs' own relayer capital only, no user funds affected, post-mortem pending), and Zilliqa (Ledger-app key exposure — amount withheld pending investigation).
All on-chain claims are independently verifiable on the respective block explorers. This report is informational and not financial, legal, or security advice.
0xposed Lab — Track. Document. Fight Back.