Loading...
Loading...
GoPlus July 2026 Web3 & AI Security Report In July 2026, losses from Web3 security incidents surged sharply. A total of 43 major security incidents were recorded during the month, resulting in aggregate losses of approximately $318.9 million. This figure was roughly 4.1 times higher than the losses recorded in June, making July the most damaging month of the year so far. From a structural perspective, losses were overwhelmingly concentrated in exploit-driven attacks. Among the 43 incidents, 37 exploits accounted for approximately $310.8 million in losses. The single largest incident of the month caused $88.6 million in losses, stemming from a cryptographic flaw in the Coldcard hardware wallet. Meanwhile, the top five incidents alone accounted for approximately $234.35 million, representing around 73.5% of total monthly losses. Compared with June, the center of risk shifted significantly in July. The three most damaging categories were governance/proposal attacks at approximately $97.6 million, cryptographic flaws at approximately $88.6 million, and private key or key leakage incidents at approximately $82.5 million. Together, these three categories made up roughly 84% of all recorded losses. Weaponized governance proposals, failures in the underlying cryptographic implementation of hardware wallets, and loss of control over keys tied to cross-chain bridges and hot wallets formed the three most destructive narratives of the month. On the AI security front, July marked a clear turning point. Risk discussions moved beyond prompt injection and content poisoning, extending deeper into the execution layer, data layer, and trust layer. Hugging Face’s disclosure of the first public “agentic attacker” intrusion, GPT-5.6 Sol accidentally deleting a user’s home directory, Grok Build CLI uploading an entire repository including Git history, and Claude share links being indexed by search engines all underscore the same reality: the security boundary of AI systems is no longer the chat interface alone, but the full runtime environment and the data assets connected to it. 1. Web3 Security Overview 1.1 Overall Landscape July recorded 43 major Web3 security incidents with aggregate losses of approximately $318,918,645. Exploit incidents: 37 cases, approximately $310.8 million Large rug pulls: 2 cases, approximately $6.59 million Large phishing incidents: 4 cases, approximately $1.55 million Largest single loss: $88.6 million from the Coldcard wallet incident Top five incidents combined: approximately $234.35 million, or 73.5% of total losses Incidents exceeding $1 million in losses: 17 At the monthly level, July showed a pattern of stable incident volume but sharply concentrated losses. While the number of incidents remained broadly in line with June, total losses expanded by more than four times. Notably, eight incidents each caused losses above $9 million, and two exceeded $75 million, indicating that attackers are increasingly focusing on governance treasuries, cryptographic foundations, and high-value key targets, rather than broadly targeting smaller projects. 1.2 Major Attack Categories The major attack categories in July, ranked by losses, were as follows:
Source:https://x.com/GoPlusSecurity/status/2084276571909812584
Impact Score