DeFi Security Analysis: How Three Major Protocols Lost $67 Million in One Week
BlockSec's weekly security report for late July 2026 documents a pattern of high-value DeFi failures across three protocols.
Caleb North·updated August 03, 2026

Combined losses across the named incidents exceed $67 million. Each exploit traces to a distinct non-contract vector: a compromised developer environment at AFX Trade, a controlled oracle signer at Ostium, and a governance quorum at BonkDAO.
AFX Trade: $24.15M via Validator Key Theft
The AFX Trade breach on July 22 did not involve a signature-verification flaw. The bridge contract enforced its deterministic rule: 7,142 voting units crossed the two-thirds threshold of 6,667. The contract executed. The failure was upstream.
According to the post-mortem, an AFX developer was social-engineered through Telegram on July 9 into running a project containing malicious code. The attacker gained signing authority over five of the seven validator nodes. The multisig held. The keys did not.
A 200-second dispute window existed. It was not triggered. Approximately 12,467 ETH moved from Arbitrum to Ethereum and settled in a single wallet. AFX subsequently offered a 30% white-hat retention. The invariant the multisig was designed to protect — that no single operator can unilaterally move funds — held in code and failed in operations.
Ostium: $23.75M via Trusted Oracle Signer
Ostium's OLP vault, settled in USDC, processed the largest single-ticket loss of the cycle. The attacker held a registered PriceUpKeep forwarder and the signing authority of a trusted price oracle. The onchain verifier authenticated the signer. It could not authenticate the price.
In one executeBatch transaction, the attacker opened BTC/USD positions at an input price near $5,000 and settled near $60,000. The state mutation passed every deterministic check. The settlement price was false. The vault paid approximately 11.86 million USDC in that atomic call. Eight payout transfers, one destination, $23.75 million total. Contracts were frozen only after the funds cleared.
The attack vector is not a bug. It is an oracle trust assumption extended to an adversary.
BonkDAO, Allbridge Core, Wanchain
BonkDAO lost roughly $20 million on July 6. The Solana Realms governance program accepted BIP #76, which transferred 4,426,104,450,305 BONK in a single onchain instruction. Voting power was acquired at a cost far below the treasury value. No execution delay applied. The attacker followed the governance spec. The spec permitted the extraction.
Allbridge Core on Solana exhibited input validation flaws. Wanchain's Cardano bridge contained flawed message encoding. Wanchain has set an August 6 deadline for a white-hat return.
Engineering Checklist
The recurring pattern is not novel contracts. It is assumed trust. Three items for any protocol shipping today:
1. Treat the developer workstation as production infrastructure. Signed builds, reproducible toolchains, hardware isolation for any key custodian.
2. Bound oracle trust. Require second-source price attestation, staleness checks independent of the reporting signer, and a kill switch that can freeze settlement per asset, not per protocol.
3. Governance delay and quorum cost. Any treasury-moving instruction should require a timelock proportional to value at risk. Quorum thresholds should be priced against the assets they can move.
None of these invariants were novel. All were absent in at least one of the cases above.