July 2026 became the second most serious month for cryptocurrency theft, with hackers stealing an estimated US$247.4 million.
The attack range covers hardware wallets, cross-chain bridges, lending agreements, and trading platforms. According to relevant data, the total amount stolen in July was more than three times the approximately $75 million in June and four times the $60 million in May. Only April of this year saw a higher theft amount recorded, when the loss was about $644 million.
Coldcard vulnerability led July losses
Coldcard was undoubtedly the largest theft of the month. Relevant research has confirmed at least three organized waves of attacks that affected approximately 7300 Bitcoin wallets and resulted in the theft of more than $100 million in BTC. A suspected fourth wave of attacks could raise the damage to about $130 million. It is currently estimated that the incident involved approximately US$115 million. Based on this calculation, the Coldcard case alone accounted for approximately 46% of all cryptocurrency stolen in July.
This incident is particularly distressing because Coldcard is a hardware wallet designed to save private keys offline. The vulnerability is related to the way the affected version generates wallet recovery information. This proves that cold storage can reduce the risk of online attacks, but it does not eliminate risks that stem from inside wallet hardware or firmware.
AFX and Ostium combined losses of nearly US$48 million
The Arbitrum also suffered two major security incidents in July. On July 22, approximately $24.15 million was stolen from an AFX-related cross-chain bridge due to a leaked private key. The attacker exchanged a large number of stolen USDC for Ethereum. Relevant sources said that the Arbitrum native bridge itself was not attacked.
A week ago, decentralized trading platform Ostium lost another $23.75 million due to a breach of its offline pricing infrastructure. The attackers submitted forged price reports and used them to make artificially profitable transactions against Ostium's liquidity provider vaults. Ostium said traders 'collateral was kept separately and unaffected.
Bonzo Lend was attacked by a third-party oracle
Bonzo Lend, a loan agreement based on Hedera, lost approximately US$9 million on July 11 because the attacker manipulated the price of SAUCE through a vulnerability in the third-party oracle verification system. The manipulated prices significantly increased the value of the attacker's collateral, allowing him to lend assets far in excess of the actual value of the collateral. Bonzo later announced that affected user positions would be compensated through a payback mechanism backed by the Hedera Foundation.
Triple-A hot wallet stolen
Crypto-payment company Triple-A is another major target of infrastructure attacks. In late July, attackers gained unauthorized access to the company's hot wallets on multiple blockchains, resulting in preliminary estimates of losses of approximately $9.7 million. Relevant data classified the incident as a hot wallet leak. Triple-A said client funds were kept separately and were not affected.
Cross-chain bridges remain the main target
The cross-chain bridge between Verus and Ethereum lost approximately $7.53 million on July 22, an incident classified as a bridge verification bypass attack. Wanchain also lost $6.5 million the day before due to signature-related flaws. In addition, there have been several small-scale incidents, including an $8.2 million Crypto DAO attack, a $1.65 million Allbridge Core attack, and multiple oracle and liquidity manipulation incidents.
One noteworthy special case is SecondFi. The Cardano wallet lost approximately $2.4 million to $2.6 million and appeared in a summary of multiple July hacking incidents, but SecondFi's own timeline suggests that the main wave of attacks occurred between June 21 and 23. The entire process of subsequent impact, restoration work and the final decision to close lasted throughout July.
These events in July finally showed that the attack surface of cryptographic assets now extends far beyond fragile smart contracts. Private keys, hardware wallets, oracle infrastructure, cross-chain bridges, and operating systems all provide attackers with ways to cause millions of dollars in damage.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH