Currencies38403
Market Cap$ 2.28T+0.38%
24h Spot Volume$ 22.12B+2.04%
DominanceBTC56.87%+0.12%ETH10.08%+0.35%
ETH Gas0.26 Gwei
Cryptorank
/

Monthly Crypto Hack Report: $247 Million Stolen in July


Monthly Crypto Hack Report: $247 Million Stolen in July

Share:

AI Overview

In July 2026 attackers stole an estimated $247.4 million in crypto, making it the second-worst month this year after April’s ~$644 million and more than triple June’s ~$75 million. The Coldcard hardware wallet exploit accounted for roughly $115 million (potentially up to $130 million), while major DeFi and infrastructure incidents included an AFX bridge private-key theft of $24.15 million, Ostium oracle manipulation of $23.75 million, Bonzo Lend’s $9 million oracle-based loss and multiple bridge and hot-wallet drains. The spate of hacks highlights expanding attack surfaces beyond smart contracts to hardware wallets, oracles, bridges and operational systems, raising significant security and adoption risks for crypto, DeFi and cross-chain infrastructure.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

July became the second-worst month of 2026 for cryptocurrency theft after hackers stole an estimated $247.4 million. The attacks spanned everything from hardware wallets and bridges to lending protocols and trading platforms.

The total was more than triple the roughly $75 million that was stolen in June and four times May’s $60 million, according to DefiLlama data. Only April, when losses reached approximately $644 million, has recorded more stolen crypto this year.

Monthly sum stolen through crypto hacks (Source: DeFiLlama)

The defining incident was the Coldcard hardware wallet exploit, but July also showed just how attackers continue to target oracle systems, private keys, bridges and operational infrastructure.

Coldcard exploit dominates July losses

Coldcard was responsible for by far the largest theft of the month. Galaxy Research identified at least three confirmed attack waves affecting roughly 7,300 Bitcoin wallets and resulting in more than $100 million in stolen BTC. A suspected fourth wave could raise losses to approximately $130 million. DefiLlama currently estimates the incident at around $115 million.

Using DefiLlama's estimate, Coldcard alone accounted for roughly 46% of all crypto stolen during July.

The incident was particularly painful because Coldcard is a hardware wallet that is designed to keep private keys offline. The vulnerability was linked to how affected versions generated wallet recovery information. This is proof that cold storage can reduce exposure to online attacks, but it does not eliminate risks originating inside wallet hardware or firmware.

AFX and Ostium lose nearly $48 million combined

Arbitrum also experienced two of July's largest security incidents. An AFX-related bridge suffered a private-key compromise on July 22 that resulted in approximately $24.15 million being stolen. The attacker converted a lot  of the stolen USDC into Ethereum. Offchain Labs said Arbitrum's native bridge itself was not compromised.

A week earlier, decentralized trading platform Ostium lost another $23.75 million after its off-chain price infrastructure was compromised.

The attacker submitted fabricated price reports and used them to generate artificially profitable trades against Ostium's liquidity provider vault. Ostium said trader collateral was stored separately and was not affected.

Bonzo Lend hit through third-party oracle

Hedera-based lending protocol Bonzo Lend lost about $9 million on July 11 after an attacker manipulated the price of SAUCE through a vulnerability in a third-party oracle's verification system.

The manipulated price dramatically inflated the value of the attacker's collateral, which allowed assets to be borrowed far beyond the collateral's true value. Bonzo later announced that affected user positions would be covered through a recovery facility backed by the Hedera Foundation.

Triple-A hot wallets drained

Crypto payments company Triple-A was another major infrastructure target.

Attackers gained unauthorized access to company hot wallets across multiple blockchains in late July, with initial estimates placing losses around $9.7 million. DefiLlama classifies the incident as a hot-wallet compromise. Triple-A said customer funds were held separately and were unaffected.

Bridges are a major target

The Verus-Ethereum Bridge lost approximately $7.53 million on July 22 through what DefiLlama classified as a bridge verification bypass. Wanchain suffered another $6.5 million loss a day earlier in a signature-related exploit.

Several smaller incidents added to the month's tally, including an $8.2 million Crypto DAO exploit, a $1.65 million Allbridge Core attack and multiple oracle and liquidity-manipulation incidents.

One major distinction concerns SecondFi. The Cardano wallet lost roughly $2.4 million to $2.6 million and featured in several July hack roundups, but SecondFi's own timeline says the principal attack waves occurred between June 21 and June 23. The fallout, recovery effort and eventual decision to shut down continued throughout July.

July's incidents ultimately show that crypto's attack surface now extends well beyond vulnerable smart contracts. Private keys, hardware wallets, oracle infrastructure, bridges and operational systems all provided attackers with paths to multimillion-dollar losses.

Read the article at Coinpaper

In This News

Coins

$ 64.90K

+0.60%

$ 1.91K

+0.85%

$ 0.202

+7.17%

$ 0.99977

0%

$ 0.0684

+0.17%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

In This News

Coins

$ 64.90K

+0.60%

$ 1.91K

+0.85%

$ 0.202

+7.17%

$ 0.99977

0%

$ 0.0684

+0.17%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

Crypto Wrench Attacks Steal Over $30 Million in 2026

Crypto Wrench Attacks Steal Over $30 Million in 2026

Chainalysis says violent crypto attacks involving kidnappings and home invasions are ...
Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims

Researcher ‘Lives’ Among North Korean Hackers, Discovers 1,640 Victims

In Brief A researcher spent 22 months inside North Korean hacker servers. His logs n...