Crypto Hacks Stole $247.4M in July 2026, With Coldcard Exploit Driving Nearly Half of Losses
AI Market Summary
July 2026 saw ~$247.4M in crypto theft, making it the second-worst month of the year and highlighting persistent tail risks across custody and DeFi infrastructure. A Coldcard hardware-wallet exploit drove the largest losses (>$100M BTC), while Arbitrum-adjacent incidents (bridge key compromise, offchain price manipulation) and oracle/hot-wallet breaches reinforced vulnerabilities in private keys, oracles, and bridges. The breadth of attack vectors can pressure risk appetite and liquidity.
Impact level
● High
Affected assets
BTC/USDT+0.67%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
July marked the second-worst month of 2026 for crypto theft, with hackers taking an estimated $247.4 million across attacks on hardware wallets, bridges, lending protocols and trading platforms, according to DeFiLlama. The total more than tripled June's roughly $75 million and quadrupled May's $60 million. Only April, when losses reached about $644 million, has been worse this year.
Coldcard exploit dominates July losses
The month's defining incident was a Coldcard hardware wallet exploit. Galaxy Research identified at least three confirmed attack waves impacting roughly 7,300 Bitcoin wallets and stealing more than $100 million in BTC. A suspected fourth wave could lift losses to around $130 million. DeFiLlama currently pegs the incident near $115 million, implying Coldcard accounted for about 46% of all crypto stolen in July.
The breach hit particularly hard because Coldcard is designed to keep private keys offline. The issue was tied to how certain affected versions generated wallet recovery information, underscoring that cold storage reduces online exposure but does not remove risks stemming from wallet hardware or firmware.
AFX and Ostium lose nearly $48 million combined
Arbitrum saw two of July's largest incidents. On July 22, an AFX-related bridge suffered a private-key compromise that led to about $24.15 million in losses; the attacker converted much of the stolen USDC into Ethereum. Offchain Labs said Arbitrum's native bridge was not compromised.
A week earlier, decentralized trading platform Ostium lost $23.75 million after its offchain price infrastructure was compromised. The attacker submitted fabricated price reports and used them to create artificially profitable trades against Ostium's liquidity provider vault. Ostium said trader collateral was segregated and unaffected.
Bonzo Lend hit via third-party oracle
Hedera-based lending protocol Bonzo Lend lost about $9 million on July 11 after an attacker manipulated the price of SAUCE by exploiting a vulnerability in a third-party oracle's verification system. The inflated price boosted the attacker's collateral value, enabling borrowing far beyond its true worth. Bonzo later said impacted user positions would be covered through a recovery facility backed by the Hedera Foundation.
TripleA hot wallets drained
Crypto payments firm TripleA was also targeted. In late July, attackers gained unauthorized access to the company's hot wallets across multiple blockchains. Early estimates put losses at roughly $9.7 million, which DeFiLlama classifies as a hot-wallet compromise. TripleA said customer funds were held separately and were not affected.
Bridges remain a major target
Bridge exploits continued to pile up. The Verus-Ethereum Bridge lost about $7.53 million on July 22 in what DeFiLlama labeled a bridge verification bypass. Wanchain suffered another $6.5 million loss a day earlier through a signature-related exploit.
Smaller incidents added to the month's total, including an $8.2 million Crypto DAO exploit, a $1.65 million Allbridge Core attack, and multiple oracle and liquidity-manipulation events.
One point of clarification involves SecondFi. The Cardano wallet was widely cited in July hack roundups for losses of roughly $2.4 million to $2.6 million, but SecondFi's own timeline says the main attack waves occurred between June 21 and June 23. The fallout, recovery efforts and eventual decision to shut down extended through July.
Overall, July's cases highlight that crypto's attack surface now extends well beyond vulnerable smart contracts. Private keys, hardware wallets, oracle infrastructure, bridges and operational systems all provided pathways to multi-million-dollar losses.