BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

Crypto lost roughly $198.8 million across 34 disclosed hacks in July, plus one incident with an undisclosed amount (35 total). One entry, a firmware bug in Coldcard hardware wallets, accounts

AnonymousCryptoCompass newsroom
August 1, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.
  • Crypto lost roughly $198.8 million across 34 disclosed hacks in July, plus one incident with an undisclosed amount (35 total).
  • One entry, a firmware bug in Coldcard hardware wallets, accounts for $70.2 million of that, over a third of the month’s total, on its own.
  • Grouped by actual cause, wallets and key infrastructure made up 54% of losses ($106.7M), DeFi protocol exploits 25% ($49.7M) despite being the most numerous category by incident count, and bridges 21% ($42.4M).

July’s Toll: Nearly $200 Million, Led by One Bug Nobody Was Watching For

Crypto lost roughly $198.8 million across 34 disclosed hacks in July, plus one incident with an undisclosed loss. One entry alone, a firmware failure in Coldcard hardware wallets, accounts for more than a third of that total by itself: $70.2 million, drained from 1,196 Bitcoin addresses in a 41-minute window on July 30. The next-largest single loss, AFX Trade’s bridge exploit on Arbitrum, was roughly a third the size at $24.15 million.

Where July Sits Against June

July’s roughly $198.8 million in disclosed losses is a sharp jump from June, when 45 recorded incidents totaled $76.51 million. That’s close to a 160% increase, or about 2.6 times June’s total, on a comparable incident count (34 disclosed losses in July against 38 disclosed-with-value incidents in June).

The shape of the damage repeats, too. June’s single largest incident, a $32 million private-key compromise at Humanity spanning Ethereum and BSC, accounted for 41.8% of that month’s entire total by itself. That’s structurally the same story as July’s Coldcard case: for two months running now, one infrastructure or key-level failure, not a protocol-logic bug, has defined the month’s financial toll on its own.

The Three Places the Money Actually Went

Grouping July’s incidents by what actually failed, rather than by the label attached to each one, three categories emerge. A few entries needed reclassifying to get here: Ostium’s loss is filed under “Protocol Logic” in raw form but was actually a compromised oracle signer key, and both Wanchain’s and Verus Ethereum Bridge’s hacks carry that same generic label despite being textbook cross-chain bridge exploits. Sorted by actual root cause:

CategoryIncidentsTotal LossShareWallets & key infrastructure6~$106.7M54%DeFi protocol exploits25~$49.7M25%Bridges4~$42.4M21%

Wallets & key infrastructure ($106.7M)

Coldcard’s firmware bug is the headline case, but it wasn’t alone. Triple-A lost $11.8 million to a hot wallet compromise across Ethereum, Tron, and Arbitrum. Ostium lost $18 million after an attacker compromised the private signing key behind its price oracle on Arbitrum, not through a contract flaw but through the key that was supposed to guard it. WEMIX lost $6.25 million to an owner-key compromise on its own WEMIX3.0 chain. Bankrbot lost $479,885 to a compromised account on Ethereum, a smaller figure but the same underlying failure as the rest of this category: credentials, not code. Zilliqa’s exchange partner suffered a nonce-generation vulnerability of the same general species as Coldcard’s.

DeFi protocol exploits ($49.7M)

The largest incident count, 25 separate protocols, but the smallest dollar share. Oracle and price manipulation shows up repeatedly here: 42DAO ($912,000), Cascade Liquidity Strategy ($1.34 million), Bonzo Lend ($9.05 million), Allbridge Core ($1.65 million via flash loan), Solido Cash ($73,400), and Edel Finance ($403,000) all trace back to a manipulated or misassigned price feed rather than a stolen key. Governance attacks hit BarnBridge ($776,000) and BonkDAO ($20 million), the single largest entry in this category. Flash loans, accounting errors, and input-validation flaws round out the rest, mostly in the tens or hundreds of thousands of dollars per incident, not the tens of millions.

Bridges ($42.4M)

AFX Trade’s $24.15 million loss came from compromised validator signing keys on a bridge it operated itself, Arbitrum’s native bridge was confirmed untouched by Offchain Labs directly. Blockaid traced the stolen USDC as it moved to Ethereum and converted into roughly 12,467 ETH, sitting in a single identifiable wallet rather than a mixer. Verus Ethereum Bridge lost $7.54 million to what several outlets describe as a reused vulnerability from an earlier May incident, a signature-validation flaw that wasn’t fully closed the first time. Wanchain’s Cardano-BNB Chain bridge lost $10 million to a similar signature/replay flaw. TeleSwap’s $735,000 Bitcoin-bridge loss remains the one incident in this group.

What the Split Reveals

DeFi protocol exploits are the most frequent failure mode in July by a wide margin, 25 of 35 incidents, but they’re responsible for barely a quarter of the dollar losses. Over half of July’s total traces to compromised keys or credentials rather than broken contract code.

Blockaid co-founder and CEO Ido Ben-Natan named this exact pattern in the context of the Coldcard case specifically: most 2026 losses, in his framing, come from compromised keys and operational security failures, not smart contract bugs. That’s a real distinction worth holding onto, but not an absolute ranking of severity.

  • Key-based attacks tend to grant an attacker everything a wallet or bridge holds at once.
  • A contract bug is usually bounded by what one specific function can move.

The two failure modes aren’t equally dangerous per-incident by coincidence; they’re structurally different in what they expose.

How Many Coldcard Wallets Are Still Exposed?

Coinkite has told Coldcard users who generated a seed on affected firmware to migrate their funds, but the company itself has acknowledged it cannot reliably tell which wallets were exposed without direct testing. CZ’s public call to split funds across multiple wallets was a response to that same uncertainty, not a comment on Coldcard specifically failing, his point was that any single device, however trusted, is still a single point of failure.