👋 Welcome to the July Edition
We shipped Multisig Inspector, a free tool that reads a Safe's config and decodes a transaction before you sign it.
And we joined the ERC-3643 Association, the standards body behind compliant RWA tokenization.
$242M+ stolen in July. A five-year-old hardware wallet bug did more damage than every DeFi exploit combined. Full story in Hack Watch below.
On research, we broke down Securitize's dual-chain stock launch, Robinhood Chain's attack surface after $311M in TVL, and every finding Multisig Inspector surfaces on a real Safe.
Here's the full July roundup.
Multisig Inspector Has Officially Launched
A Safe's threshold means nothing if a signer can't see what they're actually approving. Malicious calldata disguised as a routine transfer, an owner or module added without anyone noticing, an implementation swapped underneath the proxy, none of it shows up unless someone reads the Safe directly.
We built Multisig Inspector to close that gap. One tool reads a Safe's live configuration, owners, threshold, modules, guards. The other decodes a pending transaction and recomputes its hash before you sign.
No wallet connect, nothing stored. Works on any Safe, live and open source now.
Try Multisig Inspector.
Read the full launch post here.
QuillAudits Joins the ERC-3643 Association
Tokenized RWAs are moving from pilots into production. At this level, a flaw in identity or compliance logic isn't a bug. It's a regulatory event.
We didn't show up yesterday. We've published deep-dive research on ERC-3643's architecture, its identity layer, and its compliance mechanics, alongside hands-on audits of live RWA protocols. Joining the Association just makes it official.
What membership actually means for us: contributing to open projects, helping shape security best practices, and working directly with the RWA ecosystem. Securing the standard at the source, not just the projects built on top of it.
From the Quill Research Desk
July's research kept landing on the same conclusion: real capital is moving onto infrastructure faster than anyone is verifying it.
What Securitize's Tokenized Stock Launch Really Reveals Securitize tokenized $295M of its own NYSE stock across Solana and Avalanche on launch day. We mapped six attack vectors, from transfer hook reentrancy to Avalanche's unchecked message destinations. The risk now sits at the seam between chains.
Robinhood Chain Security Risks and Attack Vectors Explained $311M in TVL in under three weeks, 274,241 holders. We broke down the L2 risks every Orbit rollup inherits plus Robinhood's own, an unenforced oracle pause flag and agentic trading with no audit boundary. Every Stock Token is a debt security, not equity.
Introducing Multisig Inspector for Safe Wallets Bybit's signers approved a routine-looking transfer that was actually a delegatecall, and $1.5B moved. We built Multisig Inspector, a free read-only tool that decodes a Safe's config and pending transactions before anyone signs.
How to Check Your Safe Wallet's Security in 60 Seconds A real walkthrough: 7 owners, 4-of-7 threshold, one module absent from the known Safe registry. The finding doesn't mean malicious, it means unverified, and unverified is how Bybit happened.
Hack Watch
July 2026: 24 DeFi protocols hacked, $132.2M stolen, 13 chains. A normal month by this year's standards. Then a 2021 Coldcard firmware bug quietly outweighed every single one of them combined, pushing July's total past $242M+, still climbing. No smart contract. No bridge. No leaked key. Just weak wallet seeds an attacker has been brute-forcing in waves since July 30.
Ostium $23.75M Arbitrum, Jul 15, Price Report Signer Compromise. A compromised off-chain signer let an attacker submit forged, validly signed price reports to Ostium's Verifier contract. Opening and closing a leveraged position against the fabricated price in a five-minute loop drained the OLP vault. Trader margin sat in a separate contract and came out untouched.
BonkDAO $21.2M Solana, Jul 6, Governance Takeover. Quorum on BonkDAO's Realms instance cost $4.4M to buy, cheaper than the $21.2M treasury it guarded. An attacker bought just over 1% of BONK's supply, passed a proposal disguised as a reform pitch, and the treasury transfer fired in the same transaction the vote closed. Zero-second timelock, no secondary sign-off.
Bonzo Finance $9.05M Hedera, Jul 11, Oracle Verifier Zero-Signature Bypass. Supra's price verifier accepted a signature and public key that were both zero, and the pairing check mathematically returned true anyway. SAUCE's price got written twelve orders of magnitude above real value, and the attacker borrowed $6.6M USDC against a $3 deposit in under 20 seconds.
Summer Protocol $6.04M Ethereum, Jul 6, NAV Donation via Stale-Valued Ark. An Ark disabled for new deposits in October 2025 was never fully removed from the vault's NAV calculation. A donated, stale-valued token inflated share price by 9.5%, and the attacker flash-borrowed 65M USDC to redeem against real depositor liquidity.
Weak entropy alone accounted for 45% of July's total losses, all from one 2021 firmware bug. Protocol logic bugs stayed the most frequent class by count but only 14% of dollar losses. Bitcoin absorbed more in losses this month than any other chain, by a wide margin. Read the full July 2026 hack report and track the live incident log on QuillMonitor.
July's losses didn't require a new attack technique. They required a firmware bug from 2021 to finally get noticed, and an attacker patient enough to wait for it. $132.2M lost to 24 DeFi exploits. $110M more from wallets nobody thought to re-check. $1.17B lost so far this year. The baseline isn't improving.
We'll see you in August. Stay paranoid. Audit everything.
Wanna partner up w/ us or want to get your project audited? |
|
|
Have a great day,
Team QuillAudits