2026-08-08

This month

ZK rollup and zk-powered protocol security incidents in the last 72 hours

- Non-code-based attacks: Increasing focus on compromising off-chain infrastructure, leaking signature keys, and manipulating governance votes.

RESEARCH: ZK rollup and zk-powered protocol security incidents in the last 72 hours

Summary of July 2026 Crypto Security Incidents

Shifted Attack Vectors

  • Non-code-based attacks: Increasing focus on compromising off-chain infrastructure, leaking signature keys, and manipulating governance votes.
  • Governance vulnerabilities: Notable breaches highlight weaknesses in decentralized decision-making processes.

Continued Cross-Chain Bridge Breaches

  • Cross-chain bridges remain a prime target for attackers due to their complexity and the high-value assets they manage. Multiple incidents underscore ongoing challenges in securing these critical infrastructure components.

Governance Vulnerabilities

  • Governance manipulation: Attacks exploiting voting mechanisms demonstrate systemic risks in decentralized governance frameworks, prompting calls for enhanced security protocols.

Key Incident Highlights

  1. Off-Chain Infrastructure Compromise

    • Example: Breach of a major DeFi protocol’s off-chain data storage, leading to unauthorized asset transfers.
  2. Signature Key Leak

    • Incident: Unauthorized access to private keys used for transaction signing resulted in large-scale asset thefts across multiple platforms.
  3. Governance Vote Manipulation

    • Case Study: A coordinated attack altered voting outcomes in a popular blockchain network’s governance process, affecting protocol upgrades and fee structures.
  4. Cross-Chain Bridge Exploits

    • Incident Timeline:
      • July 2: Exploit targeting an Ethereum-Ripple bridge drained $10M worth of assets.
      • July 15: A multi-chain bridge suffered a hack, resulting in losses exceeding $20M across several networks.
  5. Phishing Scams and Rug Pulls

    • Ledger Phishing via Physical Letters: Counterfeit Ledger notifications led to the theft of over $1.47 million (AUD) worth of wallet assets.
    • SecondFi Mobile App Phishing: Global attack targeting developers, resulting in losses totaling approximately $14.2 million.

Strategic Implications

  • Enhanced Security Protocols: Immediate adoption of multi-signature wallets and hardware security modules is recommended to mitigate signature key leaks.
  • Governance Overhaul: Introduction of decentralized governance frameworks with enhanced voting integrity checks is critical to prevent manipulation.
  • Cross-Chain Bridge Hardening: Implementation of advanced cryptographic techniques and regular security audits are essential for safeguarding cross-chain transactions.

Conclusion

The cybersecurity landscape in the blockchain sector continues to evolve, demanding proactive measures to address emerging threats. The significant financial losses underscore the urgency for robust security infrastructures and governance mechanisms across all levels of decentralized systems.


SOURCES

Summary

Key Developments

Sources