July crypto losses climbed to $210.3 million across 30 recorded incidents. The COLDCARD firmware flaw became the third-largest crypto theft of the year. The biggest exploits hit hardware, dev
- July crypto losses climbed to $210.3 million across 30 recorded incidents.
- The COLDCARD firmware flaw became the third-largest crypto theft of the year.
- The biggest exploits hit hardware, developer machines and oracles rather than smart contract code.
- AFX Trade offered its attacker a share of the stolen funds to return the rest.
PeckShield’s July 2026 report puts crypto losses at $210.3 million across 30 separate hacks, a 177.2% jump from the $75.87 million stolen in June. The month’s damage did not come from the kind of smart contract bug that audits are built to catch. It came from a hardware wallet’s firmware, a developer tricked by a fake job offer, a price oracle fed fake timestamps, and a governance vote bought on the open market. Four incidents accounted for most of the total, which fits a pattern security firms have been flagging all year: fewer attacks, and far more surgical ones.
Where July’s $210.3M went
COLDCARD$70MAFX Trade$24.15MOstium$23.75MBONK$20MWanchain$13MTriple-A$10MBonzo Lend$9.05MVerus$7.5MWemix Network$6.25Msummer.finance$6M
Bar length scaled to the largest loss. Estimates from PeckShield, Blockaid and Halborn.
The COLDCARD sweep drained $30 million in ten minutes
Coinkite’s COLDCARD hardware wallet accounted for roughly $70 million of July’s losses by PeckShield’s count, a figure that lines up with Galaxy Research tracing about 1,083 BTC across 1,196 addresses, though Chainalysis has so far confirmed a narrower on-chain sweep of around $38 million. Even at the lower figure it ranks third among all crypto thefts recorded this year, behind the Drift and KelpDAO/LayerZero exploits. The problem sat in the firmware. The device’s true random number generator was bypassed and quietly fell back to a predictable software source, which cut the entropy behind seed generation on the affected Mk3 devices from the expected 128 bits down to roughly 40. At that level, keys stop being practically unguessable and become something a well-resourced attacker can reconstruct through brute force.
The sweep on July 30 and 31 was fast and rehearsed. Chainalysis reported that the attacker had already mapped which wallets held the most value and went after the largest single-signature balances first, pulling around $30 million in the opening ten minutes. Self-custody rests on one assumption, that the cryptography running on the device is sound. A user here could keep the seed offline, verify every address and follow every rule, and still lose the wallet, because the flaw lived below anything they could control.
AFX Trade lost control of its bridge through a fake job offer
AFX Trade, a perpetuals protocol on Arbitrum, lost $24.15 million after one of its developers was targeted by a fake recruiter. Posing as a hiring manager from a firm called Oddium Lab, the attacker got the developer to clone what looked like a legitimate code repository on July 9. The repo carried a malicious Git configuration that ran a hidden payload during a routine workflow, handing the attacker a foothold on the machine. Nothing about the Arbitrum network itself failed. Offchain Labs co-founder Steven Goldfederwas quick to point out that the Layer-2’s base layer stayed secure throughout, and the same held for Ostium, which runs on the same network. The breach happened on the developer’s own machine.
Once inside the development environment, the attacker pulled the keys behind the bridge’s hot validators. Five validator signatures were enough to meet the roughly two-thirds threshold the bridge required, so the smart contract read the withdrawal as entirely legitimate and executed it on command. Nothing had to be broken. AFX Trade then did what a growing number of protocols now do after a breach: it offered the thief a 30% bounty worth about $7.2 million in exchange for returning the other 70%.
How Ostium’s attacker wrote Bitcoin down to $5,000
Ostium’s $23.75 million loss came from its price feed. The attacker got hold of a private signing key for one of the platform’s oracles and pushed future-dated timestamps through a registered forwarder called PriceUpKeep. That let them write a false Bitcoin price of $5,000 into the contract, open heavily leveraged positions against that fiction, and then settle them at the real market price near $60,000. The gap became pure profit, paid out of the platform’s liquidity vault to positions that never earned it.
Halborn Security noted a detail that turned a vulnerability into an open door. The PriceUpKeep infrastructure had been left out of Ostium’s active bug bounty scope. White-hat researchers had no incentive to look at it, so nobody did, and the attacker walked an unwatched path straight to the price feed.
BONK DAO voted its own treasury away
The BONK DAO incident on Solana skipped the code entirely. There was no bug to exploit. The attacker spent about $4 million buying BONK on exchanges, then used that stake to control almost the entire vote. Turnout was so thin that wallets tied to the attacker made up roughly 99.9% of the votes cast, and the proposal moving about $20 million of treasury tokens to their own wallet passed cleanly. Every step was valid under the DAO’s own rules. The theft was legal in the narrow sense that the protocol worked exactly as written.
Wallet firmware COLDCARD · $70M
The random number generator was bypassed, entropy on the drained Mk3 devices fell to about 40 bits, and private keys became reconstructible by brute force.
Developer machine AFX Trade · $24.15M
A fake recruiter’s malicious repo compromised a developer’s machine; stolen validator signatures cleared a bridge withdrawal the contract read as legitimate.
Price oracle Ostium · $23.75M
A stolen signing key wrote Bitcoin down to $5,000, opened leverage, and settled near $60,000 out of the liquidity vault.
Governance BONK DAO · $20M
Attackers bought enough BONK to swing the DAO and passed a proposal that emptied the treasury into their own wallets.
Audits stopped being where the money leaks
For years the security conversation centered on smart contract audits, on the assumption that a clean codebase meant a safe protocol. July’s numbers argue otherwise. Web3 security researcher Victor Okpukpan pointed out on X that the large exploits are drifting away from on-chain code and toward key management, developer workspaces and oracle pathways. CertiK’s mid-year reportput numbers to the same shift: wallet compromises cost $444.5 million across just 33 incidents in the first half of 2026, overtaking smart contract exploits as the single most expensive attack category, even though code vulnerabilities still produced far more incidents. The four biggest July incidents fit that reading, and none of them required finding a flaw in a deployed contract.
What a firmware flaw does to the self-custody case
The COLDCARD breach lands hardest on retail holders who chose hardware wallets precisely to avoid trusting anyone else. If a foundational chip or firmware error can undo perfect personal security, the argument for holding your own keys weakens for anyone without the technical depth to audit their own device. That pressure points in one direction for part of the market, toward regulated custodians and spot Bitcoin ETFs, where the security burden sits with an institution rather than the individual.
Protocols now budget for paying attackers back
The AFX Trade offer is becoming standard practice rather than an exception. Negotiating the return of stolen funds has moved from rare improvisation into written incident-response plans, and some firms now treat a percentage payout to attackers as a recovery cost. What no one has settled is the legal status of those payments. US and European regulators have not drawn a clear line between a ransom and a lawful settlement, and how they eventually classify a bounty paid to a known thief will decide whether the tactic that saved AFX Trade most of its money stays available to the next protocol that needs it.
The post July Crypto Hacks Total $210M, Led by COLDCARD Breach appeared first on ETHNews.