Crypto Hack Losses Surge 177% to $210 Million in July, Led by Coldcard Wallet Drains
Key Takeaways
- •July cryptocurrency losses totaled approximately $210.3 million across 30 hacks, representing a 177.2% increase from the $75.87 million lost in June.
- •A Coldcard wallet drain of roughly $70 million was the month's largest incident, caused by insufficient entropy in seed phrases generated on Mk3 devices running firmware versions 4.0.1 through 5.0.3.
- •The Coldcard breach ranks as the third-largest crypto theft of 2026, behind only the $292 million KelpDAO and LayerZero bridge exploit and the $285 million Drift Protocol breach.
- •Cross-chain bridges remained a significant attack target, with AFX Trade's Arbitrum bridge losing 24.15 million USDC and Wanchain's Cardano-BNB Chain bridge losing approximately $13 million through a suspected signature-reuse vulnerability.
- •The ten largest incidents accounted for roughly $191 million of the total losses, while the remaining twenty hacks collectively contributed approximately $19.3 million.

Cryptocurrency projects, wallets, and infrastructure providers suffered an estimated $210.3 million in losses across 30 major hacks during July, representing a 177.2% increase from the $75.87 million recorded in June, according to PeckShield's monthly security report.
The blockchain security firm's July tally identified Coldcard-linked wallet drains as the single largest incident at approximately $70 million, followed by AFX Trade and Ostium at roughly $24 million each. Losses spanned multiple attack vectors, including governance system exploits, bridge compromises, oracle manipulation, project-controlled wallet breaches, and privileged smart contract vulnerabilities. The breadth of attack types underscores that no single category of crypto infrastructure was responsible for the monthly surge, with incidents distributed across custodial, DeFi, and cross-chain systems.
Coldcard Drain Ranks as Third-Largest Crypto Theft of 2026
The Coldcard incident emerged as July's most significant security breach after researchers at Block traced as much as 1,082.59 BTC across two clusters of transactions sharing an identical wallet fingerprint.
Coinkite, the manufacturer of Coldcard hardware wallets, issued a warning advising users who generated seed phrases on Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 to treat those wallets as potentially compromised. The underlying vulnerability produced seed phrases with substantially less entropy than intended, meaning an attacker with sufficient knowledge of the setup process could significantly narrow the range of possible recovery phrases. Hardware wallets are widely recommended as a best practice for self-custody because they store private keys offline, making a seed-generation flaw of this nature particularly notable within the security community.
The roughly $70 million loss ranks as the third-largest crypto theft reported in 2026, behind the $292 million KelpDAO and LayerZero bridge exploit and the $285 million Drift Protocol breach. Coinkite has not confirmed that every transaction flagged by Block was attributable to the Mk3 firmware weakness.
Bridges, Oracles, and Governance Exploits Contribute to Monthly Toll
AFX Trade's Arbitrum bridge lost 24.15 million USDC after signatures tied to five hot validators met the required approval threshold. The attacker transferred the stablecoins to Ethereum and converted them into approximately 12,467 ETH. Cross-chain bridges have repeatedly ranked among the most targeted categories in crypto exploits, as their multi-signature and validator architectures can create single points of failure when key management or threshold controls are compromised.
PeckShield revised its estimated loss from the Ostium oracle exploit upward to approximately $24 million, surpassing an initial assessment of up to $18 million. The attacker leveraged authorized, future-dated price reports to generate artificial trading profits against the protocol's USDC liquidity vault.
A malicious governance proposal drained roughly $21.2 million from the BonkDAO treasury. Separately, Wanchain's Cardano-BNB Chain bridge lost approximately $13 million after 515 million NIGHT tokens exited its treasury through transactions linked to a suspected signature-reuse vulnerability.
Additional Incidents Account for Nearly $39 Million
Wallets associated with payments provider Triple-A lost more than $9.7 million across four blockchain networks before the assets were consolidated on Ethereum. Bonzo Lend sustained a $9.05 million oracle exploit, while the Verus Ethereum Bridge lost $7.54 million through an import-validation failure that released assets without corresponding deposits.
WEMIX reported damages of approximately $6.25 million from a contract ownership compromise, and a vault-accounting exploit removed roughly $6.04 million from Summer.fi.
The 10 largest incidents collectively accounted for approximately $191 million, leaving about $19.3 million spread across the remaining 20 hacks recorded in July.