July became the second most damaging month for cryptocurrency theft in 2026, with hackers stealing an estimated $247.4 million across a range of platforms and protocols. The attacks, which targeted hardware wallets, bridges, lending protocols, and trading venues, highlighted both the diversity and persistence of vulnerabilities in the sector.
Coldcard exploit dominates monthly losses
The most severe blow came from the Coldcard hardware wallet exploit. Galaxy Research identified three confirmed attack waves affecting about 7,300 Bitcoin wallets, resulting in more than $100 million in stolen BTC. A potential fourth attack could raise the figure to approximately $130 million, with DefiLlama currently estimating damages at around $115 million. This single incident accounted for nearly 46% of the entire haul for July.
Coldcard wallets, designed to protect private keys by keeping them offline, faced criticism after a vulnerability linked to wallet recovery information allowed attackers to breach their defenses. This event underscored that, while cold storage reduces the risk of online attacks, it cannot fully defend against vulnerabilities stemming from wallet hardware or firmware flaws.
Coldcard alone was responsible for roughly half of all digital assets stolen during July, highlighting the increasing sophistication of attacks targeting even hardware-based storage solutions.
Major protocol and platform compromises
Arbitrum suffered two significant breaches in July. On July 22, an AFX-associated bridge fell victim to a private-key compromise, leading to approximately $24.15 million in stolen assets. The attacker converted most of the stolen USDC to Ethereum. Offchain Labs confirmed that Arbitrum’s main bridge infrastructure was not affected.
Just a week before, decentralized trading project Ostium saw $23.75 million drained when its off-chain pricing system was compromised. Attackers fabricated price data, enabling them to execute fraudulent trades against Ostium’s liquidity provider vault. The platform maintained that collateral reserves for traders remained secure and separated from the affected vault.
Bonzo Lend on the Hedera network reported a $9 million loss after a vulnerability in a third-party oracle’s verification system allowed an attacker to manipulate the price of the SAUCE token. The artificially inflated price enabled the attacker to borrow assets far above legitimate collateral value. Bonzo later said that a recovery facility supported by the Hedera Foundation would compensate affected users.
Wider impact on crypto security
Other notable incidents included a $9.7 million hot-wallet compromise suffered by crypto payments provider Triple-A, which impacted infrastructure across several blockchains. DefiLlama categorized this as a hot wallet breach but Triple-A assured that customer funds were segregated and unaffected.
Bridge exploits continued to be a theme, with the Verus-Ethereum Bridge losing $7.53 million via a bridge verification bypass, and Wanchain experiencing a $6.5 million loss stemming from a signature-based attack.
Additional incidents, such as the $8.2 million Crypto DAO exploit and the $1.65 million Allbridge Core attack, compounded losses for the month. Many of these breaches involved manipulating oracle data or exploiting gaps in liquidity infrastructure.
Sector development and new solutions
The ongoing threat landscape shows attackers are expanding beyond legacy smart contract vulnerabilities. Platform security now must account for risks associated with private keys, hardware wallets, bridges, oracles, and extensive operational systems. In parallel with the persistent emergence of sophisticated attacks, platforms like 1stepSwap have started to bridge traditional finance and crypto by bringing real-world assets such as US stocks, gold, and silver onto blockchain networks. Users can now access these assets directly from their wallets, benefitting from automated price optimization and no reliance on multiple intermediaries. This integrated approach may encourage further diversification and speed up response times in addressing major market incidents.
July’s wave of hacks demonstrated that crypto’s attack surface now encompasses hardware vulnerabilities, bridge exploits, compromised oracles, and weaknesses across operational infrastructure, leading to multimillion-dollar losses.
July’s incidents also spotlighted several ongoing recovery and shutdown efforts, such as SecondFi, a Cardano wallet attacked for between $2.4 million and $2.6 million. While most of the attack activity took place in June, the fallout and resolution process extended well into July, ultimately prompting the team to discontinue service.





USDT
AAPL
