Need help? Support
BITCOIN
Tether Dominance USDT.D

July crypto hacks reach $247.4M in losses

Published 474 words 3 min read

TLDR

July 2026 saw about 247.4 million dollars in crypto stolen, making it one of the worst months for hacks this year and driven mainly by a large Coldcard hardware wallet exploit.

  1. DefiLlama data attributes roughly 247.4 million dollars in July thefts, with the Coldcard wallet flaw alone responsible for well over 100 million dollars and thousands of affected Bitcoin wallets.
  2. July attacks show that both cold storage devices and widely used software libraries can fail, turning self custody and DeFi infrastructure into significant risk points for everyday users.
  3. The Coldcard fallout, BTCPay Server vulnerability and ongoing audits suggest a long clean up phase ahead, along with potential tightening of security standards and regulatory scrutiny.

Deep Dive

1. Scale And Main Incidents

According to DefiLlama, July 2026 saw about 247.4 million dollars in crypto stolen, making it the second worst month of the year after April.

The biggest single incident was the Coldcard hardware wallet exploit, where Galaxy Digital and other researchers estimate over 100 million dollars in Bitcoin stolen from around 7,300 wallets, with some analyses hinting at losses that could reach 130 million dollars if all waves are confirmed.

Additional July exploits included hacks on Bonzo Lend, Cardano based wallet SecondFi, Arbitrum based perpetuals platform AFX, and the Verus Ethereum bridge, contributing tens of millions more in losses.

2. Security Lessons For Custody

The Coldcard flaw stemmed from a firmware change that weakened random number generation for seed creation, allowing attackers to reconstruct private keys offline, as detailed in the Coldcard incident coverage.

Separately, a long standing bug in the CryptoJS library enabled the Ill Bloom exploit, where predictable randomness in web wallets led to more than 5.7 million dollars stolen across multiple chains.

Taken together, these incidents show that hardware wallets, browser based wallets and DeFi protocols all depend on subtle cryptographic and software assumptions that can break years after deployment.

What this means

Even secure setups can fail; spreading risk across custody types and favoring well audited, actively maintained tools can reduce single point of failure exposure.

3. What To Watch Next

Coldcard attackers still control a large trove of stolen Bitcoin, and have recently resumed moving funds, increasing the urgency for exchanges and law enforcement to track potential laundering routes.

Bitcoin infrastructure faces additional pressure from an ongoing exploit against BTCPay Server, where developers urged operators to update or even shut down nodes after reports of drained funds in an emergency security notice.

Expect more coordinated audits of wallet software, stricter entropy and security standards, and possible regulatory pushes around hardware certification and self custody risk disclosures.

Conclusion

Julys 247.4 million dollars in crypto hack losses reflect not just opportunistic attacks, but deep weaknesses in core wallet and infrastructure code that took years to surface.

For crypto users, the key shift is that custody and infrastructure choices now carry more visible systemic risk, making ongoing security reviews and diversified setups increasingly important to limit the impact of future exploits.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top