July in on-chain investigations.
Less than 5 minutes to read · Forward freely
Last weeks · June 29 – July 27
The patterns we saw.
Our weekly deep-dives covered the period’s most instructive exploits, more than $85M drained across the cases we looked at, set against a first-half total CertiK puts at $1.31B across 344 incidents. Four threads ran through them.
Source: CertiK on $1.31B lost in H1 2026 →
1 · Trusted controls
Almost nothing this month was a broken contract.
AFX Trade lost $24.15M when five compromised validator keys cleared its bridge quorum. Ostium lost up to $24M when whoever controls its price authority delivered a $5,000 Bitcoin print and closed the position near $60,000 seconds later. B² Network lost $3.86M after an attacker took over the upgrade permission on its staking contract. Zellic had audited the AFX bridge, and the code did exactly what it was written to do. What changed hands in each case was a trusted control.
Source: CoinDesk on the AFX Trade bridge compromise →
2 · Governance
Nothing was hacked, and $20M still moved.
BonkDAO’s treasury went to an attacker who spent about $4.4M buying BONK until they cleared the DAO’s 1% quorum, then passed a proposal that had sat live and unremarked for six days. Turnout was 2.9%. The system executed as designed, which is why this one deserves a lawyer’s full attention and gets the explainer below.
Source: The Block on the BonkDAO governance attack →
3 · The first swap
The freeze window closes at the exit, not at the theft.
Summer.fi lost about $6M to a flash-loan vault exploit that Blockaid caught live, and the attacker converted the stolen USDC into DAI on Curve before moving it anywhere. Circle can freeze USDC at address level. Nobody can freeze DAI. That one swap removed the only centralised lever in the case, and it happened while the protocol was still confirming it had been exploited.
Source: CoinDesk on the Summer.fi vault exploit →
4 · Watchers
A control with nobody behind it is documentation.
AFX’s bridge held the attacker’s withdrawal for a 200-second dispute period and released it because no challenge arrived at 21:30 UTC on a Wednesday. Verus lost $7.54M through the same verification flaw that cost it $11.5M in May, 15 days after redepositing recovered funds into the unfixed bridge. Bridges have now been hit in at least eight major exploits in 2026, for a running total of $328.6M.
Source: CoinDesk on three protocols losing $35M hours apart →
CONCEPT OF THE MONTH
Governance attacks, explained.
Plain language for legal and compliance professionals
A DAO holds its money in a treasury that no single person controls. Instead, holders of the project’s token vote on proposals, and a proposal that passes executes automatically on-chain with no signature required from anyone in particular. Two numbers govern that process. Quorum is the minimum weight of tokens that has to participate for a vote to count at all, and the majority is what carries it once quorum is met. Both are usually set as a percentage of token supply, which means both have a market price, and anyone can pay it.
That’s what happened to BonkDAO on 6 July. Between 4 and 5 July, a wallet accumulated roughly $4.4M of BONK across Bybit and Binance, some of it reportedly financed through DeFi lending, until it crossed the DAO’s quorum threshold of 879.95 billion tokens. A proposal titled “BIP #76 – Sowellian BonkDAO” had already been live for six days, unremarkable enough that almost nobody looked at it closely. It passed on 2.9% turnout: seven wallets voting yes, more than 18,000 members not voting at all, and a final weight of 882.38 billion against a threshold of 879.95 billion, a margin so thin it reads as calculated to the token. The proposal instructed the treasury to send its holdings, roughly $20M, to the attacker’s wallet. No contract was exploited, no key was stolen, and nothing needs patching.
There is no vulnerability to point at, so the evidence has to be the accumulation itself: a wallet buying exactly enough of one token, in exactly the right window, to cross a threshold it then used once.
The legal framing decides everything downstream. Ripple’s CTO Emeritus, David Schwartz, called it corporate fraud in the aftermath, and noted that “code is law” isn’t a defence state courts recognise when shared assets move without genuine consent. That’s the argument a recovery case runs on, because the alternative, treating a quorum-gamed vote as valid corporate action, would make every underfunded DAO treasury a standing invitation. Framed as a fraudulent transfer, a civil freezing injunction doesn’t have to wait for a post-mortem on a bug that doesn’t exist.
The accumulation window, the financing, the six quiet days, and the 2.43 billion tokens of headroom over the threshold all read as premeditation rather than opportunism, and all of it is timestamped and permanent. Recovery then turns on where the money went. About $19M sits in a fresh multisig the attacker has branded “BONK 2.0,” and Chainalysis reports it still parked there. A multisig is slower to exit than a mixer and every wallet that touches it becomes visible the moment it acts, so BonkDAO is coordinating with exchanges, bridges, the Solana Foundation and law enforcement while the funds stay put. Governance attacks don’t roll back. They get frozen, or they don’t. If your institution runs token-weighted governance for anything that holds value, the useful exercise this week is working out what your own quorum costs to buy.
Further reading
What a governance attack is · crypto.news
The $20M BonkDAO treasury drain · CoinDesk
Where the $19M went · The Defiant
Our full breakdown for recovery lawyers · recoveris.io/blog
NEW INVESTOR
A major European Bitcoin treasury company invests in Recoveris.

We’ve signed an investment and cooperation agreement with BTCS S.A., Poland’s first publicly listed Digital Asset Treasury Company, listed on NewConnect in Warsaw and, since January 2026, on the Frankfurt Stock Exchange. BTCS becomes our distribution partner, connecting Polish institutions, law firms and individuals to blockchain investigations, Source of Funds reports, incident response and digital asset recovery. Their role is distribution. Casework, methodology and client relationships stay with us, which matters for institutional buyers who need a single accountable party behind a forensic report.
In the same fortnight we cleared SOC 2 Type 2 with Sensiba LLP, covering Security, Availability and Confidentiality on our Platform as a Service system. Type 2 is the harder bar, because auditors verify that controls held up in live operation across a full quarter rather than on a single day. For the banks, VASPs and compliance teams running vendor risk assessments, it’s often the line that decides whether a technology partner clears procurement at all. It now sits behind BIMS, AURA, the Case Intake Platform and Tracker.
NEW ON YOUTUBE
The Recoveris AI Investigator.
Agentic investigations for digital assets are what keeps pace with the scale of the problem. Binance alone received 71,000 law enforcement requests in a single year, and no human team meets that by hiring. So we’re building a system that runs the trace and leaves the judgment with an investigator. Our CEO on why we started, our CTO on how it works, and the platform it all runs inside.

Why Recoveris is building an AI investigator
Marcin Zarakowski, co-founder and CEO. Demand for tracing, provenance and Source of Funds work outgrew the number of people qualified to do it, so we automated the workflow and turned our own casework into a model. Marcin on CoTrace, the capacity ceiling in blockchain forensics, and what tokenized assets do to human-led compliance.
Watch → · Read the companion piece →

Can AI run a blockchain investigation?
Oleksii Koshlatyi, CTO. Our model is a white box and fully deterministic, so we can show exactly why a transaction was flagged, which is what a court and a regulator both require. Oleksii also covers why client data never leaves our closed environment, and why vendor neutrality is turning into a European data sovereignty question.
Watch → · Read the companion piece →

Recoveris BIMS: blockchain investigations at machine speed
The Blockchain Investigations Management System (BIMS) is where the full investigative lifecycle lives: intake, tracing, evidence and freeze requests managed end to end on one visual board, with every action audit-logged so the chain of work stays defensible.
PRODUCT SPOTLIGHT
Tracker: attribution checks without leaving your tracing tool.
Browser extension for investigators
Before following a hop, an investigator has to check whether the address is already attributed, in their own database and in whatever other analytics tools they have access to. It’s repetitive, it’s slow, and a known attribution is easy to miss when it happens to live in a tool nobody opened that day. Tracker is a browser extension that does those checks for you while you work, running quietly in the background on whatever page you’re investigating and pinging you when something matters.
As you trace, it cross-checks each address against your database and Recoveris Intelligence, and surfaces any attribution another analytics tool already holds inside the extension itself. It’s vendor-neutral by design, so you’re not reading one provider’s view of the world. It also captures the metadata of your tracing flow, so a path can be reproduced in another tool and preserved as part of the case record, and exports the blockchain data from an investigation in a standardised form.


Tracker is one connection point into BIMS. Attributions and paths found mid-trace flow straight into the case record, the investigation is managed end to end on the board, and every action is logged so the chain of work holds up later. It runs on Chrome, Edge, Brave, Opera, Arc and other Chromium browsers, onboarded through the Recoveris CRM on scoped, read-only permissions, with optional IP whitelisting for teams behind a VPN.

Why one blockchain analytics tool is never enough. Marcin Zarakowski on why the same wallet can read as clean in one platform and flagged as sanctioned in another, and what Tracker does about it. Watch →
INDUSTRY WATCH
Also worth knowing this month.
Regulation · FATF
FATF hands the freeze layer to the private sector.
On 16 July the Financial Action Task Force published its seventh targeted update on Recommendation 15. Most of the coverage went to the compliance scoreboard, which shows legislation running well ahead of enforcement: 83% of surveyed jurisdictions now have Travel Rule legislation, up from 73%, while around 60% of them have taken no supervisory or enforcement action on it at all, and only 13 of 139 fully met the standard on preventive measures. The sentence worth reading twice sits in the recommendations, where FATF calls on jurisdictions to build operational infrastructure and protocols with private-sector partners to enable the rapid tracing, freezing and seizure of illicit virtual assets. That’s a request for working capability, not another memorandum of understanding.
“Effective implementation of the FATF Standards can no longer be delayed. Governments and the private sector must work together to strengthen preventive measures and close regulatory gaps.”
Giles Thomson, FATF President
The technical finding matters most to anyone whose recovery plan assumes an issuer freeze. Most identified on-chain illicit activity now involves stablecoins, and FATF documents a criminal-linked conglomerate developing a USD-pegged stablecoin engineered to resist freezing and seizure, launched after a third-party issuer froze tens of millions in its wallets. Our own $10.5M Swiss recovery ran issuer-first, with Tether freezing USDT at address level and Bitfinex holding the funds through the criminal proceeding. As that lever degrades, the remaining enforcement surface is the counterparty: the exchange, the bridge, the OTC desk where funds have to touch a service to become useful. Reaching those teams quickly is a private-sector job, and it’s why we broadcast validated freeze requests across 190+ VASPs through VerifyVASP from a single case file.
Legal practice
When blockchain intelligence isn’t enough, with SPH Legal.
Fred Buret and Sam Healey of SPH Legal wrote a joint piece on the evidential challenges behind UK Crypto Wallet Freezing Orders. The core distinction is one that decides cases: attributing a wallet to an exchange, custodian or OTC broker establishes neither control of that wallet nor beneficial ownership of what sits in it. Exchange wallets hold assets for thousands of customers, and legitimate DeFi behaviour reads as suspicious through a conventional AML lens. Where an order rests on mistaken attribution or incomplete wallet analysis, it becomes vulnerable the moment it’s challenged.
Enforcement watch
A forfeiture order the blockchain didn’t honour.
The DOJ charged Rossen Iossifov, already serving 111 months for an earlier fraud, with moving roughly $290,000 in cryptocurrency that a federal court had already forfeited to the government, allegedly from a prison cell. The funds sat in a Kraken account in his name and then moved through multiple exchanges and mixing services. The government’s legal claim to the assets was settled; operational control of the wallet was not. An order restrains funds on paper, and on-chain those funds still sit at a custodian and can still move. Closing that distance means knowing which wallets hold the assets, watching them, and reaching the custodian before the balance is gone.
Victim protection
The FBI updated its warning on recovery scams.
In a 20 July public service announcement, the IC3 described criminals impersonating FBI personnel to run re-targeting fraud against people who have already been scammed, including AI-generated deepfake video of a senior FBI official directing victims to a spoofed IC3 website. The pattern is familiar to us, because fraudsters cloned our own recovery form last year to do the same thing. Worth forwarding to any client who has already lost funds: nobody legitimate contacts a victim unsolicited on Telegram or Facebook, and no serious firm charges a fee to release money it claims to be holding.
EVENTS
Meet us here next.
2026 Virtual Asset Technical Exchange
2 – 3 September · San Antonio, United States
7 – 10 September · Strasbourg, France
10th Global Conference on Criminal Finances and Cryptoassets, Basel Institute
15 – 16 September · Luxembourg
24 September · London, United Kingdom
25 September · Zurich, Switzerland
28 – 30 September · Vienna, Austria
Need an expert on the record?
Working a case that needs a forensic blockchain expert? For a court-admissible tracing report, an expert witness, or technical input on a live recovery matter, reach out to [email protected]. Our investigations team responds within one business day.
Journalists covering crypto crime, DeFi exploits, asset recovery, or sanctions exposure can reach our investigations and corporate affairs teams on the record at [email protected].