Morning Edition · Monday, July 27, 2026Published at 1:22 AM EDT · New York
A new proof-of-concept for a roughly $542,000 Lien Finance flaw adds to a month that already includes the $24 million Ostium drain and a $20 million governance takeover of BonkDAO.
The security researchers at DeFiHackLabs published a proof-of-concept for a permissionless bond-registration flaw at Lien Finance that cost roughly $542,000 in the USDC stablecoin. It is the latest entry in a July marked by recurring exploits that the tracker Rekt News has been cataloguing.
The largest single loss this month came from Ostium, a real-world-asset perpetuals protocol on Arbitrum. An attacker used a registered price forwarder and a future-dated, authorized oracle report to fabricate trading profits, triggering a payout that CoinDesk initially reported at about $18 million and that later monitoring put closer to $24 million. The root cause was not a smart-contract bug but a compromised oracle input, the trusted price feed itself.
Two other incidents show the same pattern by different means. BonkDAO on Solana lost about $20 million when an attacker spent roughly $4 million buying voting power, then passed a malicious governance proposal that quietly transferred 4.43 trillion BONK from the treasury, a governance attack rather than a code exploit. On Hedera, Bonzo Lend lost about $9.05 million after an attacker manipulated the price feed for SAUCE tokens through a verification flaw traced to Supra's oracle contracts. A separate $6 million loss at Summer.fi traced back to stale tokens left over from November's Stream Finance collapse rather than a fresh flaw.
What Ostium, Bonzo, and Summer.fi have in common is that the exploited weakness sat in trusted inputs and inherited state, not in the vault logic being drained. Teams in several cases are coordinating with foundations and exchanges to freeze or trace funds.
Oracle providers and audit firms whose services gain demand from the incidents, while rivals of the named oracle face pressure over the supply-chain flaw.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
The Ostium loss is reported at roughly $18 million by CoinDesk and closer to $24 million by later trackers, and the monthly total aggregates distinct incidents with different root causes.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Oracle price feeds and governance vote-buying are becoming the preferred entry points because they let attackers manipulate a protocol's trusted assumptions without breaking its code, which means audits of contract logic alone do not protect depositors. The exposed parties are lenders and perpetuals venues that rely on third-party oracles and on low-turnout token governance. Losses stay elevated until protocols harden price-feed validation and raise the cost of accumulating governance power.
What to watch
Observations to monitor, not financial advice.
Synthesized from: DeFiHackLabs · Rekt News · CoinDesk (Ostium)
Comments
0No comments yet.