Risk in DeFi July 2026
BACK TO BLOG
August 12, 2026·22 min read

Risk in DeFi: July post-mortem


Overview

This review examines eight of July 2026’s most notable on-chain incidents in date order, investigating whether Credora’s risk assessment methodology would have covered each. Credora surfaces the risk in DeFi as the Probability of Significant Loss (PSL), which is the annualized probability that a position in a rated market or vault loses more than 1% of principal over a one-year horizon. A companion metric, the Probability of Default (PD), applies the same logic to individual assets. Each verdict below shows whether Credora’s framework would have flagged the risk before it materialized.

The review delivers a structured account of how and why each failure happened and provides a standing test of the methodology against realized losses. The verdicts that fall short matter as much as the ones that land, since they mark where the framework must evolve. A scorecard is presented at the end.


Risk in DeFi: Shifting attack vectors

July’s largest loss came from a firmware bug in Coldcard hardware wallets, which resulted in roughly $110M drained from thousands of Bitcoin wallets. The incident’s scale exceeds the total for all DeFi exploits of the month combined. Within DeFi, most of the damage follows the June pattern: compromised keys and validators (AFX, Ostium), bridge validation flaws (Wanchain, Verus), a governance takeover (BonkDAO), and price and valuation failures (Bonzo, Summer.fi). Once again, the failures stemmed from the operations and dependencies around the asset, its keys, bridges, oracles, governance, and accounting as opposed to the core asset logic itself.

July also saw a sharp step up in the scale of the incidents. DeFiLlama put the month’s losses at about $247M, the second-worst month of 2026 and roughly triple of June’s $75M. The Coldcard attack, which does not necessarily qualify as a DeFi incident, accounts for almost half of that amount; excluding it, DeFi losses of about $132M were in line with the recent months. Bridges were again the most expensive, in terms of incident losses, DeFi category, their third consecutive month at the top, and wallet and key compromises have now overtaken smart-contract exploits as the single most expensive attack class of 2026.


1. Summer.fi (Lazy Summer), est. ~$6M, July 6

Summer.fi’s Lazy Summer, an automated yield vault that routes USDC deposits across lending markets like Aave and Morpho, saw its vaults drained of about $6M, and the team wound the protocol down afterward, saying recovery was impossible due to the operational capital being wiped out. 

The attack amounted to vault share price manipulation, a known risk in DeFi. Lazy Summer derives its share price from a set of strategy adapters called Arks, and one Ark, capped for offboarding but still counted in the price, was carrying a stale valuation for Silo Varlamore tokens that had never been marked down after Stream Finance’s collapse in November 2025. The attacker donated those overvalued tokens into that Ark, lifting the vault’s reported value by about 9.5%, then redeemed shares at the inflated price and took roughly $6M of the vault’s genuinely liquid assets in a single atomic transaction. As Summer.fi put it, the failure was in a process: an impaired market had been left priced into the vault while it awaited removal.

Methodology mapping

Asset Quality: the framework marks a vault’s holdings to fair value across market, credit, and liquidity risk. Lazy Summer carried an impaired, illiquid asset: the Silo token left unmarked since Stream Finance’s November 2025 collapse, well above its real value. The vault’s true backing sat below its claimed NAV, exactly the reserve shortfall this component is built to catch.

Real-time NAV: assessing the share price against current, marked-to-market values exposes the gap the exploit relied on. A vault priced off live fair value would not carry a dead asset at an old price.

Verdict: COVERS. Marking the vault’s holdings to fair value and its share price to current NAV would have shown Lazy Summer’s true backing sitting below its stated value, which would have resulted in a poor rating. The stale, impaired mark was assessable in advance; a rating does not need the exact donation transaction to see that the vault was carrying a dead asset above value.


2. BonkDAO, est. ~$20M, July 6

BonkDAO’s treasury lost about $20M in BONK to a single governance proposal, prompting the BONK token to slip by roughly 8%. On June 30, an anonymous wallet submitted Bonk Improvement Proposal 76 to BonkDAO’s governance on Solana’s Realms platform; its single operative clause transferred 4.43 trillion BONK from the treasury to a wallet the submitter controlled.

From there, the attacker leveraged the governance mechanism to seal the deal fast. The quorum was low enough that about $4.4M of BONK bought through exchange wallets was enough to control the vote, and execution was immediate. When the vote closed on July 6, attacker-linked wallets held about 99.9% of the votes cast, the proposal executed on the spot, and the treasury paid out, netting the attacker roughly $20M in BONK for an overhead of about $4.4M.

Methodology mapping

Governance (capture risk), scored: the metric penalizes onchain governance capture, which refers to votes being cheap to acquire compared to the treasury they govern, with further penalties for low participation. BonkDAO’s roughly $4.4M position controlling a ±$20M treasury is a clear example of that, and it is the side of the attack the framework recognizes.

Execution timelock, not captured: the proposal executed on passage with no delay, but the metric’s timelock scoring is keyed to the mint and upgrade roles, not treasury-spend proposals. A treasury proposal’s execution delay is not yet a scored field, and that instant execution made the drain unstoppable.

Verdict: PARTIALLY COVERS. The capture side is scored: a cheap vote commanding a large treasury is exactly the governance risk the metric penalizes, and it would have ranked BonkDAO below a higher-quorum peer. The execution side was not scored: the timelock that would have turned an instant treasury drain into a contestable one is measured only for the mint and upgrade roles, not treasury proposals. The framework saw the fault line but not the missing delay that made it fatal, which is why this is partial rather than full coverage. A treasury-proposal timelock field closes the gap.


3. Bonzo Lend, est. ~$9M, July 11

Bonzo Lend, Hedera’s largest lending protocol, lost about $9.05M when an attacker manipulated the price of the SAUCE token. Bonzo’s TVL fell 77% and Hedera’s roughly 40% within a day.

The flaw was in the oracle Bonzo trusted, a risk in DeFi that’s not revealed by audits of the protocol’s own smart contracts. A wallet submitted a SAUCE price update carrying a zeroed BLS signature to Supra’s on-demand oracle; the update should have been rejected, but Supra’s verifier accepted it as genuine. The bad price inflated SAUCE by about twelve orders of magnitude, and eight seconds later the attacker borrowed roughly $6.6M in USDC and 34.5M wHBAR against 250 SAUCE of real collateral.

Methodology mapping

Oracle Risk: Credora scores the oracle a protocol depends on as its own unit, spanning the provider’s audit quality and operational security, its data-source diversity and fail-safes, and its recent-incident history, with the protocol inheriting that dependency score. Bonzo priced its collateral from a single Supra feed with no backup or deviation guard, and the failure was a defect in Supra’s verifier that accepted a zeroed signature; both the concentration and the provider defect are squarely what this component assesses.

Verdict: COVERS. Oracle risk is a scored component precisely because an oracle’s failure does not surface in the protocol’s audit. The framework assesses the audit posture and operational security of the oracle a protocol depends on, so Bonzo’s single-feed dependence and Supra’s security were both within scope. It would not have identified Supra’s specific signature defect, but the oracle-security weakness was assessable in advance.


4. Ostium, est. ~$23.75M, July 15

Ostium, a perpetual DEX on Arbitrum, was drained of 23,752,746 USDC from its OLP vault in a five-minute window. The team paused trading within the hour, investigated for eight days, and reopened on July 23.

The investigation found no smart-contract bugs or multisig compromises. The attacker obtained the offchain key that signs Ostium’s price feeds and used it to submit forged but validly signed prices, opening and closing large leveraged positions to manufacture profit until the vault was empty. Whoever holds that signing key can tell the protocol whatever price they want, bypassing the checks meant to keep the feed honest.

Methodology mapping

Oracle Risk (issuer-internal oracle): the framework scores the price feeds a protocol runs itself, including the operational security of the keys that sign them. Ostium settled every position against one signed feed produced by a single offchain key, and that key’s compromise is the oracle operational-security failure this component assesses. It was, here, the entire attack surface.

Circuit Breaker: the dimension scores whether a protocol can halt or cap outflows once a failure begins. Ostium’s manual pause within the hour limited the total loss, but no on-chain cap constrained the vault’s outflow during the five-minute attack itself.

Verdict: COVERS. The framework scores the operational security of the price feed a protocol relies on, including the custody of the key that signs it, so a settlement path trusting a single off-chain signer with no cross-check would have rated Ostium poorly before July 15. The rapid pause made for a sound incident response, but the standing weakness was assessable in advance.


5. Wanchain bridge, est. ~$13M, July 20

Wanchain’s Cardano-to-BNB bridge lost about $13M in NIGHT tokens, prompting the token to slump more than 30%. Wanchain took the bridge offline; the Midnight blockchain itself was unaffected.

The bridge’s validator built the message it signed by joining fourteen variable-length fields end to end, with no separators or length markers. That ambiguity let a legitimate signature authorizing about 3,110 NIGHT on BNB Chain be reused for a Cardano withdrawal of more than 203 million NIGHT, over 65,000 times the intended amount.

Methodology mapping

Bridging and Smart Contract Risk (bridge validation): a bridged asset is only as safe as the bridge that carries it, so the framework scores how the bridge constructs and validates the messages it signs. Wanchain built its signed message by concatenating fourteen fields without delimiters, which let a legitimate signature be reused for a withdrawal 65,000 times larger, a validation-model weakness rather than something an audit of either chain in isolation would surface.

Circuit Breaker: a reserve-versus-withdrawal check is precisely the guard this dimension scores. None was in place, so a withdrawal 65,000 times larger than the signature authorized cleared with nothing to flag the discrepancy.

Verdict: COVERS. A bridge that signs ambiguous, delimiter-free messages is a validation design the framework scores, and the absence of an outflow sanity check is a circuit-breaker gap. Both would have rated the bridge poorly in advance, though the specific encoding defect is audit territory.


6. AFX Trade bridge, est. ~$24.15M, July 22

AFX Trade, a perpetuals venue on Arbitrum, lost about $24.15M in USDC from its custody bridge, later converted into roughly 12,467 ETH. Arbitrum’s native bridge was not involved; the breach was entirely within AFX-managed infrastructure.

AFX’s bridge ran a seven-validator scheme requiring two-thirds of the voting units to move funds. The attacker compromised the signing keys of five of the seven validators, cleared the threshold, and co-signed a fraudulent transfer out of the bridge. Access came from a social-engineering campaign that began on July 9, a fake recruiter targeting an AFX developer, later attributed to the DPRK group UNC4899.

Methodology mapping

Key Custody Environment: five out of seven validator keys in a single attacker’s hands is June’s Humanity pattern at the validator layer, keys that appear distributed but were reachable through one developer. Signer count is not independence.

Privilege Scope: the dimension scores how much a compromised role can reach. AFX’s validator quorum held unbounded authority over the bridge balance, so the five captured keys could move everything at once rather than a limited amount.

Circuit Breaker: nothing delayed or flagged that transfer; no timelock, rate limit, or anomaly check stood between a co-signed message and the payout, the halt-and-catch layer the framework scores.

Verdict: COVERS. Validator-key custody, the independence of signers, and the absence of a limit on what a quorum can move are scored operational dimensions. A seven-validator bridge reachable through a single social-engineering path is a clear risk in DeFi and would have rated poorly before July 22. Social engineering was the delivery; the scored weakness was the custody and the unbounded privilege behind it.


7. Verus Ethereum Bridge, est. ~$7.5M, July 23

Verus’s Ethereum bridge was drained of about $7.54M on July 23, enduring its second attack in three months. A 0.01 VRSC transaction triggered unbacked payouts on the Ethereum side: 1,137 ETH, 71.5 tBTC, and a mix of USDC, USDT, EURC, MKR and scrvUSD, all routed to a single wallet and later laundered through Tornado Cash.

The flaw was not new. The same bridge import path had been drained for about $11.5M in May; that attacker returned most of the funds for a white-hat bounty, and the recovered assets were redeposited into the bridge on July 8. Days later a different attacker used the same unremediated vulnerability class to drain it again, forcing the bridge to pay out Ethereum-side assets that had no corresponding deposit backing.

Methodology mapping

Recent Incident: Credora applies a standing penalty for a documented incident within the past twelve months, and a bridge re-exploited through the same path that drained it in May is the clearest instance of that risk. The unremediated flaw was a matter of record, not a surprise.

Smart Contract Risk (bridge validation): the bridging assessment scores how rigorously a bridge verifies that an incoming message is backed by a genuine deposit. Verus released Ethereum-side assets against an import it never properly validated, paying out value with nothing behind it.

Circuit Breaker: a reserve-versus-payout check is a basic guard scored by this dimension. Its absence allowed a 0.01 VRSC input to trigger a multimillion-dollar payout that an outflow-versus-backing check would have caught.

Verdict: COVERS. A bridge carrying a known, unpatched vulnerability from two months earlier, with no check tying payouts to backing, is exactly what the Recent Incident and bridge-validation dimensions exist to flag. The framework would have rated it poorly the moment the May exploit went unremediated.


8. Coldcard hardware wallet, est. ~$110M, July 30

The month’s largest loss was not from a DeFi protocol at all. A firmware bug in Coldcard hardware wallets let attackers drain roughly $70M from about 1,196 Bitcoin addresses in a 41-minute window on July 30, with the running total near $110M across thousands of wallets by early August.

A 2021 firmware change had quietly routed seed generation through a software pseudorandom number generator instead of the device’s hardware randomness source, cutting entropy to roughly 40 to 72 bits against the 128-bit standard and making the seeds guessable. The flaw sat undetected for years; the attackers exploited it before Coinkite disclosed and patched on July 30, and the patch protects only newly-generated seeds.

Methodology mapping

No rated dimension applies. This was a failure in how a hardware wallet generates a private key, a device firmware and entropy problem. It has no credit, reserve, redemption, or protocol-operations surface and leaves no trace in any asset’s contract state or configuration.

Verdict: OUT OF SCOPE. Credora rates onchain assets and the protocols around them, not the wallets that hold the keys. A weak random number generator in a hardware device is a supply-chain and implementation failure a layer beneath anything an asset rating reads. It is the clearest out-of-scope case of the year, and naming that boundary is as important as claiming the cases the framework does cover.


Scorecard

IncidentDateEstimated lossRoot causePrimary Credora dimensionsVerdict
Summer.fi (Lazy Summer)Jul 6~$6MStale impaired asset still counted in vault NAV; inflated by donation, then redeemedAsset Quality, Real-time NAVCovers
BonkDAOJul 6~$20MLow quorum bought for ~$4.4M + immediate execution; hidden treasury transferGovernance (capture scored; treasury-proposal timelock gap)Partially covers
Bonzo LendJul 11~$9MThird-party oracle (Supra) accepted a zeroed signature; price inflatedOracle Risk (audit, OpSec, concentration)Covers
OstiumJul 15~$23.75MOff-chain price-signer key compromised; forged signed pricesOracle Risk (issuer-internal oracle), Circuit BreakerCovers
Wanchain bridgeJul 20~$13MDelimiter-free signed message; signature reused for 65,000x the amountSmart Contract Risk (bridge validation), BridgingCovers
AFX Trade bridgeJul 22~$24.15M5 of 7 validator keys compromised via social engineeringKey Custody Environment, Privilege Scope, Circuit BreakerCovers
Verus Ethereum BridgeJul 23~$7.5MRepeat of an unpatched May flaw; unbacked Ethereum-side payoutsRecent Incident, Smart Contract Risk (bridge validation)Covers
ColdcardJul 30~$110MHardware-wallet entropy bug from a 2021 firmware changeNone (device firmware, not asset risk)Out of scope

How to read the verdicts

Covers means the failure maps to a risk the framework scores, and a poor PSL score would have been assigned before the event. Six of the eight qualify. Coverage means the standing weakness was scorable in advance, which is the point of rating ahead of an incident rather than explaining one after. Pointing at the exact transaction, naming the defective line in the code, or predicting when a key is phished or a market breaks is beyond both the scope of this exercise and the Credora methodology.

Partially covers means the framework sees part of the risk but not the dominant part: the scored fault line is real and would rank the asset below its peers, yet the actual cause sits where the rating carries least weight. BonkDAO is the July example: the metric penalizes the governance-capture side, a vote cheap to acquire over a large treasury, but the execution timelock that would have made the drain contestable is scored only for the mint and upgrade roles, not for treasury proposals. It saw the fault line but not the missing delay.

Not covered is the most consequential verdict: an incident squarely within the framework’s remit, credit, reserves, custody, governance, or operational security, that it nonetheless failed to flag at all. Unlike out of scope, this is a false negative, a blind spot in the current metrics rather than a boundary of the discipline. No July incident fell here, but it is the verdict the exercise is designed to surface, since each one is a direct instruction to add or reweight a metric.

Out of scope means the failure sits on a layer an asset rating does not read. Coldcard was a hardware-wallet entropy failure, a device firmware problem beneath the asset entirely, so it leaves no trace in contract state, reserves, or governance. Marking that boundary is a feature, not a limitation: a rating that claimed every layer would be less credible, not more.


Key takeaways

Of July’s eight incidents, six mapped to risks Credora prices in advance, one was partially covered, and one was out of scope entirely. The framework covered the key, validator, bridge, and oracle failures (Ostium, AFX, Wanchain, Verus, Bonzo) and the vault-accounting manipulation (Summer.fi), because it assesses smart-contract risk for protocols and, separately, the audit and operational security of the oracles they depend on. 

The two exceptions are where the month earns its keep. BonkDAO was partially covered: the metric penalizes the governance-capture side, a cheap vote to acquire over a large treasury, but it does not yet score the execution timelock for treasury-spend proposals, and instant execution was what made the drain unstoppable. The fix is a treasury-proposal timelock field, precisely the refinement the methodology’s roadmap already anticipates. Coldcard, by contrast, sat beneath the asset layer entirely, a hardware-wallet entropy bug, out of scope rather than a blind spot. Where June was clean coverage, July surfaced a concrete refinement, which makes it the more useful stress test of the two.


Frequently Asked Questions

How does Credora assess risk in DeFi beyond the asset layer?

Credora’s methodology accounts for both onchain and offchain risk surfaces, including such dimensions as Key Custody Environment, Reserve Transparency, Counterparty Risk, and Peg Track Record. As indicated by the Coldcard exploit, some further layers of the overall blockchain ecosystem remain beyond the methodology’s scope, at least for now. The attack serves as a regrettable, but useful reminder to avoid concentrating your capital in a single wallet, even if it’s a cold one.

How does the Probability of Significant Loss (PSL) measure risk in DeFi?

The PSL is Credora’s main risk metric for markets and vaults, assessing the annualized probability that a position loses more than 1% of principal over a one-year horizon. A companion metric, the Probability of Default (PD), applies the same logic to individual assets. Both convert qualitative risk factors, from the quality of smart contract audits and key custody environment to reserve transparency, peg performance, and counterparty dependencies, into a single quantitative value that can be used to compare different markets, vaults, and assets. The result is converted into a risk rating, which runs from A+ to D.

What were the main DeFi exploit categories in July 2026?

While July’s single biggest exploit stems from a firmware vulnerability in a hardware cold wallet, it’s difficult to be qualified as a DeFi attack since the vulnerability was in a layer below the smart contracts powering decentralized applications. As far as “DeFi proper” goes, bridge exploits remained the most expensive category, while wallet and key compromises overtook smart-contract exploits in terms of single attack cost. 

How does Credora assess risk in DeFi beyond the asset layer?

Credora’s methodology accounts for both onchain and offchain risk surfaces, including such dimensions as Key Custody Environment, Reserve Transparency, Counterparty Risk, and Peg Track Record. As indicated by the Coldcard exploit, some further layers of the overall blockchain ecosystem remain beyond the methodology’s scope, at least for now. The attack serves as a regrettable, but useful reminder to avoid concentrating your capital in a single wallet, even if it’s a cold one.

How does the Probability of Significant Loss (PSL) measure risk in DeFi?

The PSL is Credora’s main risk metric for markets and vaults, assessing the annualized probability that a position loses more than 1% of principal over a one-year horizon. A companion metric, the Probability of Default (PD), applies the same logic to individual assets. Both convert qualitative risk factors, from the quality of smart contract audits and key custody environment to reserve transparency, peg performance, and counterparty dependencies, into a single quantitative value that can be used to compare different markets, vaults, and assets. The result is converted into a risk rating, which runs from A+ to D.

What were the main DeFi exploit categories in July 2026?

While July’s single biggest exploit stems from a firmware vulnerability in a hardware cold wallet, it’s difficult to be qualified as a DeFi attack since the vulnerability was in a layer below the smart contracts powering decentralized applications. As far as “DeFi proper” goes, bridge exploits remained the most expensive category, while wallet and key compromises overtook smart-contract exploits in terms of single attack cost. 


Disclaimer

This post-mortem serves two purposes. First, it is educational: a structured, repeatable way for readers to understand how and why each incident occurred, beyond the headline loss figure. Second, it is a governance exercise for the methodology itself. Each incident is treated as an out-of-sample test, and mapping realized losses back to the framework is how Credora identifies coverage gaps and recalibrates its models against observed failure modes. The “partially covers,” “not covered,” and “out of scope” verdicts carry the most weight in that respect, as they indicate where the methodology should be extended next.

This document is provided for informational purposes only and does not constitute investment, legal, or financial advice. The coverage verdicts are analytical judgments, not credit ratings for the named assets. Figures reflect public reporting available at the time of writing and may be revised as investigations conclude.


Sources

DefiLlama put July’s total at about $247.4M, the second-worst month of 2026, with other trackers reporting $210M to $242M depending on incident count and the Coldcard figure used. DeFi-only losses were roughly $132M. Coldcard estimates range from about $100M (Galaxy, three confirmed waves) to $115M (DefiLlama), with a suspected fourth wave that could reach ~$130M, and were still climbing at the time of writing. All other figures are sourced to the links above.