Protocol exploits have driven at least $57 million in crypto losses so far in July, extending a run of attacks that has shifted attention away from wallet breaches and back toward weaknesses inside DeFi applications themselves.
Recent incidents point to a broader mix of tactics than in earlier waves of decentralized finance hacks. The source report says smart contract logic flaws have again become a leading entry point, alongside oracle manipulation, front-end bugs, liquidity pool attacks, pricing exploits and fake minting schemes.
A wider attack surface
The pattern described for June and July suggests hackers are targeting how permissionless protocols process trades, governance actions and asset pricing rather than relying only on known weaknesses in copied code. The report says trading apps, prediction markets and decentralized exchanges have all presented multiple attack vectors.
It also lists malicious governance actions among the techniques seen in recent exploits. Other methods cited include silent auto-approval, flash-loan-assisted attacks, donation attacks, broken signature verification and malicious fake mining. Together, those methods indicate a more varied set of exploit paths than the more familiar DeFi hacks that often affected forked or heavily reused protocols.
The article further suggests that AI may be helping attackers uncover weak points faster, though this remains an assessment rather than a confirmed explanation. It argues the growing range of exploit methods could reflect more sophisticated vulnerability analysis.
July losses by chain
Losses have clustered on some of the industry’s most liquid networks. According to DeFi Llama data cited in the report, Solana protocols have lost more than $21 million in July to date, while Arbitrum has seen more than $18 million in losses.
Base recorded more than $14 million in exploited funds during the month, surpassing Ethereum, which was reported at about $7 million. The source also says more than $36 million was hacked from BNB Chain, and that stolen funds were later bridged and mixed on Ethereum.
That multi-chain movement has added to concerns that attacks are no longer isolated to a single ecosystem. The report argues that even smaller chains and protocols are increasingly being treated as easier targets.
From June into July
The July total follows more than $75 million stolen in June from multisig wallets and protocols. Over the past year, the source describes the broader pattern as a mix of routine smaller thefts punctuated by occasional large bridge or protocol breaches.
Even so, security analysts cited in the report say 2026 has seen fewer protocol hacks than the previous year. The article says that may partly reflect some Web3 projects shutting down, while other teams may be improving defenses by finding vulnerabilities before attackers do.
Broader implications for on-chain markets
The renewed focus on protocol-level weaknesses comes as parts of crypto infrastructure are pushing beyond token trading and toward real-world assets such as equities and debt instruments. The report argues that if on-chain equity trading expands, the consequences of smart contract and governance exploits could become more serious.
It also points to the arrival of more retail-facing products, including Robinhood’s chain and other RWA markets, as a sign that platforms may need to reconsider security design and the risks tied to permissionless operations.
Source: Cryptopolitan