Exploits switch from wallet attacks to protocol flaws
Protocol exploits and hacks accounted for $57M in losses for July to date. In June, over $75M was stolen from multisig wallets and protocols, based on DeFi Llama data. The past year saw a mix of baseline activity with smaller thefts and the occasional high-profile bridge or protocol hack.
As Cryptopolitan reported, protocol exploits accounted for one of the biggest cases in the past year, the Kelp DAO hack. Since then, minor DeFi protocols, DEXs and lending pools are still attacked frequently.
Protocol exploits rise based on logic flaw discoveries
In June and July, protocol logic was the main tool behind recent hacks. Apps for trading, predictions, or DEX had several attack vectors. Those included price oracle manipulation, front-end vulnerabilities, liquidity pool hacks, pricing hacks, and fake minting.
Hackers also used malicious governance attacks, as in the case of Barn Bridge and the Bonk DAO.
Other attacks included silent auto-approval, flash loans, donation attacks, broken signature verification, and malicious fake mining.
The recent wave of hacks uses much more varied techniques, suggesting more sophisticated analysis of vulnerabilities. In previous DeFi hacks, the attack points were relatively well-known and affected forked or copied protocols.
The most recent wave of exploits shows AI may be able to discover even more vulnerabilities in the process of handling permissionless transactions.
While DeFi and crypto as a whole have slowed down, the hacks raise the issue of the general reliability of on-chain rails. Platforms are pivoting to trading real-world assets, including equities and debt instruments. So far, hacks are mostly used for tokens, which are easy to liquidate.
As equity trading grows with on-chain protocols, the threat of hacks becomes even more serious. The recent addition of more retail traders with Robinhood’s chain, as well as other RWA markets, suggests protocols must rethink their security and permissionless operations.
Hacks return to Solana, Arbitrum
Protocol exploits are clustering around the most liquid chains. In July, Solana protocols lost over $21M.
Arbitrum, one of the most active DeFi networks, lost over $18M in hacks for the month to date.
Surprisingly, Ethereum lagged with just around $7M in exploits. While Ethereum remains the most liquid network, attackers are targeting other chains, including BNB Chain and Base.
Base surpassed Ethereum hacks, with over $14M lost in July. Over $36M were hacked from BNB Chain. After the hacks, funds were bridged and mixed on Ethereum. The ease of multi-chain hacks suggests AI has assisted hackers in branching out more easily. Even minor chains and protocols are now seen as low-hanging fruit.
Security analysts still noted that AI is also improving Web3 security. In 2026, protocol hacks are fewer compared to the previous year. This may be due to some Web3 protocols closing altogether, but others may be able to prevent protocol exploits by discovering their weak spots before the hackers.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
The seven giants’ “valuation cutting” is nearing its end! Muse and Astra ignite “AI FOMO trading,” tech stocks are ready for a major comeback.
As Meta Muse and OpenAI's GPT-6 Astra are driving a massive wave of AI agents, "AI FOMO trading" (referring to investors rushing to buy or replenish positions in AI-related assets out of fear of missing out on price gains) is making a strong comeback.

Anthropic files for IPO: lost $4.2 billion last year, revenue grew 12x to $4.6 billion, risk section warns of "threats to human survival"
Anthropic's IPO prospectus reveals that its spending on computing power and infrastructure will reach $7.33 billion in 2025, a twofold increase from 2024, accounting for more than half of its total operating expenses of $12.65 billion. The company plans to continue investing over $500 billion in the future. The risk section of the prospectus extends to 80 pages, explicitly warning that its AI models could pose "catastrophic or even existential threats," and may even resist shutdowns or manipulate information.
Meta shocks Wall Street by hiring MongoDB CEO and makes a high-profile entry into enterprise AI business
Meta has established an enterprise AI division called "Meta Enterprise Platform," which Mark Zuckerberg described as "the next important pillar." MongoDB CEO CJ Desai has been recruited to lead it. Analysts noted that Zuckerberg specifically poached a CEO from a publicly listed company to demonstrate the importance of this move. Desai's departure was announced just one day before Investor Day, with the timing surprising the public.
RBA set to hike interest rate to 4.60% in September as inflation remains elevated
