Crypto Security Review: $97 Million Lost to Off-Chain Infrastructure Attacks
73 million in June, according to KuCoin's monthly security review.

Cross-Chain Bridges Bleed $35M as Attack Vectors Pivot Off-Chain
July 2026 closed with $97 million in confirmed crypto security losses, up 18.7% from $81.73 million in June, according to KuCoin's monthly security review. The data indicates a structural shift: fewer incidents, larger payouts, and a pivot away from smart contract code flaws toward off-chain infrastructure compromise.
The Metrics
- 14+ protocol incidents recorded, down from 67 in June.
- $94M attributed to code exploits and direct attacks; $3M to phishing.
- $35M+ lost across three bridge-related incidents (AFX Trade, Verus, B² Network) within hours of each other.
- Average loss per incident rose materially as attack concentration increased.
Liquidity Pool and Bridge Exposure
The most significant pool-level drain hit Ostium, an RWA perpetual trading protocol on Arbitrum. The attacker compromised the off-chain price signing system, fabricated BTC/USD data, pushed the implied price to roughly $5,000, and extracted approximately $23.75 million USDC from the OLP liquidity pool through position cycling. Contract code remained intact; the failure point was the signing layer. Trading resumed July 23.
AFX Trade's cross-chain bridge lost approximately 24.15 million USDC when a validator signing key was exposed. The bridge contract validated the signatures correctly and released funds as designed. The attacker bridged USDC from Arbitrum to Ethereum and converted to 12,467.5 ETH at an average price of $1,937. AFX suspended the bridge and posted a 30% recovery bounty.
BonkDAO's treasury was drained via a governance exploit: roughly $4 million in BONK tokens acquired to pass a malicious proposal under Solana Realms' 1% voting threshold, yielding approximately 44.26 billion BONK (~$20M) transferred out on July 6. No contract code was broken; the flaw was the governance rule design.
What This Means for Marketplace Participants
The pattern is directly relevant to anyone routing trades through bridges, LP positions, or governance-weighted tokens:
- Signing key custody is now the primary attack surface, not contract code.
- Off-chain price oracles and bridge validators require the same audit scrutiny historically reserved for smart contracts.
- Governance thresholds below 5% present outsized risk relative to the liquidity they secure.
- Average loss per incident is rising, meaning fewer exploits extract more value.
Risk assessment: before committing capital through any cross-chain route or LP position, verify bridge validator architecture, review governance quorum parameters, and treat any pool exposed to off-chain price feeds as carrying counterparty risk equivalent to a centralized oracle dependency. The threat model has changed — code audits alone no longer cover the surface.