
Coldcard's $115M hardware wallet hack drove July's $247.4M crypto theft tally, with Arbitrum, Ostium, and Bonzo also hit.
Alpha Score of 47 reflects weak overall profile with weak momentum, weak value, strong quality, moderate sentiment.
July was the second-worst month of 2026 for crypto theft. Hackers stole an estimated $247.4 million across hardware wallets, bridges, lending protocols, and trading platforms, according to DefiLlama data.
The total more than tripled June's roughly $75 million and was four times May's $60 million. Only April, which saw approximately $644 million stolen, was worse this year.
A Coldcard hardware wallet exploit drove the month's numbers. Galaxy Research identified at least three confirmed attack waves affecting roughly 7,300 Bitcoin wallets and resulting in more than $100 million in stolen BTC. A suspected fourth wave could raise losses to approximately $130 million. DefiLlama currently pegs the incident at around $115 million.
Using that estimate, Coldcard alone accounts for roughly 46% of all crypto stolen during July. The vulnerability was linked to how affected versions generated wallet recovery information. Coldcard is a hardware wallet designed to keep private keys offline; the incident shows that cold storage reduces exposure to online attacks but does not eliminate risks inside wallet hardware or firmware.
Arbitrum saw two of July's largest incidents. An AFX-related bridge suffered a private-key compromise on July 22 that resulted in approximately $24.15 million being stolen. The attacker converted most of the stolen USDC into Ethereum. Offchain Labs said Arbitrum's native bridge was not compromised.
A week earlier, decentralized trading platform Ostium lost $23.75 million after its off-chain price infrastructure was compromised. The attacker submitted fabricated price reports and used them to generate artificially profitable trades against Ostium's liquidity provider vault. Ostium said trader collateral was stored separately and was not affected.
Hedera-based lending protocol Bonzo Lend lost about $9 million on July 11 after an attacker manipulated the price of SAUCE through a vulnerability in a third-party oracle's verification system. The manipulated price inflated the value of the attacker's collateral, which allowed assets to be borrowed far beyond the collateral's true value. Bonzo later announced that affected user positions would be covered through a recovery facility backed by the Hedera Foundation.
Crypto payments company Triple-A lost roughly $9.7 million after attackers gained unauthorized access to company hot wallets across multiple blockchains in late July. DefiLlama classifies the incident as a hot-wallet compromise. Triple-A said customer funds were held separately and were unaffected.
The Verus-Ethereum Bridge lost approximately $7.53 million on July 22 through what DefiLlama called a bridge verification bypass. Wanchain lost another $6.5 million a day earlier in a signature-related exploit.
Several smaller incidents added to the month's tally, including an $8.2 million Crypto DAO exploit, a $1.65 million Allbridge Core attack, and multiple oracle and liquidity-manipulation incidents.
One major distinction concerns SecondFi. The Cardano wallet lost roughly $2.4 million to $2.6 million and featured in several July hack roundups, but SecondFi's own timeline says the principal attack waves occurred between June 21 and June 23. The fallout, recovery effort, and eventual decision to shut down continued throughout July.
The monthly total shows that crypto's attack surface now extends well beyond vulnerable smart contracts. Private keys, hardware wallets, oracle infrastructure, bridges, and operational systems all provided attackers with paths to multimillion-dollar losses in July.
For ongoing coverage of tokenized asset risks, see our crypto market analysis.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.