The week of July 12 to July 19 delivered another rough stretch for crypto security, with a compromised oracle signer key at Ostium, a locked-fund drain at Polychain-backed Cascade, a Solana lending deficit at DeFiTuna, and a first-ever attack against Across on Solana pushing weekly confirmed damage well past $20 million.
The pattern lands directly on top of the previous week’s $35M loss across BonkDAO, Bonzo Lend and Summer.fi and fits the shift laid out in CertiK’s H1 2026 report, which found Web3 lost more than $1.31 billion across 344 incidents in the first half, with wallet compromises and infrastructure breaches now the costliest attack surface.
Show
Ostium Drained of Up to $24M in Oracle Signer Compromise
The biggest incident of the week hit Ostium, an Arbitrum-based real-world-asset perpetuals exchange, on July 15. Security firm Blockaid was the first to flag the breach, reporting on X that an attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a roughly $18 million USDC payout from the vault.
The primary transaction was publicly verifiable on Arbiscan, and on-chain records showed the exploit unfolded through around 20 looped delegated trades on pairIndex 0. Ostium’s own subgraph maps that pair to BTC/USD, meaning the position was opened at a delivered price of exactly $5,000 and closed at roughly $60,000, letting the attacker book a large synthetic profit and pull vault liquidity in a single batch.
The protocol confirmed the breach the same day, saying in an official X post that all trader funds and open positions were preserved as-is, with funds in the trading storage contract paused while the team investigated with external security experts.
The Scale of the Drain
Initial on-chain data put the extracted amount between $11.86 million and $18 million in USDC, equal to about 28% of the vault’s $63 million total value locked at the time of the attack. PeckShield’s follow-on monitoring later put the number closer to $24 million once secondary transfers were tracked, with the attacker converting the proceeds into roughly 12,085 ETH.
Ostium had raised about $27.8 million in prior funding rounds and had processed over $50 billion in cumulative trading volume before the incident.
Latest update: Ostium has not announced a compensation plan or recovery fund. A substantial portion of the stolen funds was routed through Tornado Cash, a mixing protocol that makes on-chain tracing significantly harder, and the protocol’s TVL collapsed from roughly $32.7 million to $9 million after the incident. Trading remains suspended pending the review, with the initial trading halt covered as the on-chain flow was still being reconstructed.
Cascade CLS Vault Drained of $1.34M in Locked Deposits
A day after Ostium, Polychain-backed neo-brokerage Cascade said its Cascade Liquidity Strategy vault had been exploited on July 16.
PeckShieldAlert flagged the incident in an X post, reporting that Cascade suffered an exploit affecting the CLS vault that drained 1.34M USDC from user funds. According to the same alert, the exploiter bridged the stolen funds from Arbitrum to Solana, then routed them to Ethereum via Relay Protocol and swapped them into DAI along the way, a laundering path designed to complicate freezes.
The stolen amount was small relative to other incidents this week, but the design of the loss made it worse. The CLS vault held pre-allocated deposits from Cascade’s invite-only First Wave campaign, and users had deposited USDC on Arbitrum to earn reward points ahead of the public launch. Those deposits were locked until the mainnet went live, which means affected depositors had no way to withdraw before the attacker struck.
Warnings Had Been Public for Weeks
On-chain researcher Morsy had publicly called Cascade a “scam project” days before the exploit, writing on X that he had already advised users to withdraw. Another analyst posting as @mztacat had warned depositors on July 6 to pull funds, and the analyst said on X that vault liquidity had fallen more than 95% in the interim.
Cascade had raised $15 million in a seed round led by Polychain and Variant in December 2025 and had marketed itself as a neo-brokerage offering perpetual trading on crypto, commodities, and tokenized pre-IPO shares.
Latest update: Cascade paused all trading and withdrawals and confirmed on Discord that it had hired SEAL 911 and other external security firms to investigate. The team has yet to publish a public post-mortem or lay out any reimbursement plan for affected depositors.
DeFiTuna Loses $580K, Leaves USDC Lending Pool in Deficit
Solana automated market maker DeFiTuna disclosed on July 16 that its lending pools had been exploited for roughly $580,000.
The SlowMist Hacked database logged the event as a $580,000 loss caused by a smart contract vulnerability, noting the attacker drained the lending pool and created a matching deficit on the USDC side of the ledger. The team said the attack vector had been identified and patched, and that recovery efforts and a deeper investigation were underway.
DeFiTuna combines Uniswap v3-style concentrated liquidity, on-chain lending, and leveraged positions of up to 5x in a single protocol, with all revenue routed to $TUNA stakers. The seam between those components appears to be where the exploit lived, since the attacker did not need to break the AMM or the leverage engine outright to walk out with a deficit sitting on the pool’s books.
Latest update: The USDC pool now sits in a bad-debt position, meaning liabilities exceed assets by roughly $580K. The team has not committed to a treasury backstop, a socialized loss, or a specific reimbursement plan, and spot trading infrastructure remains operational while the team decides how to close the shortfall.
Across Protocol Suffers First Attack on Solana Deployment
Cross-chain bridge Across Protocol confirmed a security incident on its Solana deployment in the early hours of July 17. It was the first attack the protocol has publicly disclosed since launching in 2021, a run of more than $34 billion in bridged volume with no user-facing exploits.
Across said in an official X post that the protocol was attacked on Solana at around 5:30 AM UTC and that user funds were safe. All bridge transactions were completed, and Solana deposits were temporarily disabled while the team traced the attacker’s address. The team said the only funds potentially lost belonged to Risk Labs, the developer behind Across.
Solana became a supported destination for Across in July 2025 through the protocol’s V4 upgrade, its first expansion beyond EVM chains, with the SVM spoke pool built on the Anchor framework handling deposits, fills, and relayer refunds.
Latest update: By July 18, Across had re-enabled Solana deposits and said the protocol was fully operational. The team said in a follow-up X post that no user funds were lost, all in-flight Solana transfers were completed or fully refunded, and relayer losses were contained to Risk Labs. A full post-mortem is expected the following week.
PHX-WBNB Pool Drained of Nearly $90K on BNB Chain
On the smaller end of the week’s incidents, the PHX-WBNB liquidity pool on PancakeSwap V2 was drained of roughly $89,600 in a single transaction on July 13.
Blockchain security firm TenArmor flagged the incident in an X post, reporting a suspicious attack involving PHX on BSC with an estimated loss of about $89.6K. The attacker used a flash loan from Lista DAO’s Moolah protocol to fund the manipulation, cycling hundreds of millions of dollars in WBNB and BTCB through lending venues within a single atomic transaction before repaying the loan.
The exploit leveraged a flaw in PHX’s transfer-fee logic, where a pair-side token burn ran before post-fee amounts were credited back, leaving the pool’s recorded reserves out of sync with actual balances. That mismatch let the next swap calculation release WBNB to the attacker-controlled contract.
The pattern is not new. Earlier this year, the AIDC token was drained of about $121,000 through a similar burn-driven reserve mismatch on PancakeSwap, and the OLPC/LABUBU pool lost roughly $1.1 million to the same broad template.
Latest update: As in earlier incidents of this type, PancakeSwap’s own contracts were not the vulnerability. Traders have been warned that thinly traded BNB Chain tokens with custom fee-on-transfer or burn logic remain a persistent source of single-transaction losses.
The Bigger Picture
Every major loss this week traced back to infrastructure rather than smart contract code. Ostium fell to a compromised oracle signer key. Cascade fell to a vault holding funds users could not withdraw. DeFiTuna’s exploit hit a lending pool through the seams between multiple products. Across’s incident sat inside the relay boundary on Solana. PHX-WBNB was a token-side flaw that turned an AMM pool against itself.
That fits neatly into the shift documented in CertiK’s H1 2026 findings, where wallet compromise was the costliest category of the half at more than $444 million. The attack surface keeps climbing up the stack, away from the code that gets audited and toward the rules, keys, and off-chain infrastructure that mostly do not.
Also Read: BitMine Posts $9.1B Loss as ETH Staking Drives Nearly All Revenue