EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

July 2026 cryptocurrency hacking incident: Wallet, DeFi and cross-chain bridges lost nearly $200 mil

2026-08-02 00:26:02
Bookmark

Lost nearly US$200 million in July, with an unnoticed vulnerability taking the lead.

Cryptocurrency suffered a total of 34 publicly disclosed hacking incidents in July, resulting in losses of approximately US$198.8 million, and an undisclosed amount (a total of 35 incidents). Among them, firmware vulnerabilities in Coldcard's hardware wallet accounted for US$70.2 million, more than one-third of the total loss for the month.

By actual cause, wallet and key infrastructure accounted for 54%($106.7 million) of losses, and DeFi protocol vulnerabilities accounted for 25%($49.7 million)-although this was the most frequent category by number of incidents, while cross-chain bridges accounted for 21%($42.4 million).

July losses: Nearly $200 million, led by an undetected vulnerability.

Cryptocurrency lost a total of approximately $198.8 million in July, involving 34 publicly disclosed hacking attacks and an undisclosed amount. Firmware failures in Coldcard's hardware wallet alone accounted for more than one-third of the total losses: $70.2 million, which was stolen from 1196 Bitcoin addresses in just 41 minutes on July 30. The second largest single loss was AFX Trade's cross-chain bridge vulnerability on Arbitrum, which amounted to approximately US$24.15 million, only one-third of the former.

July vs. June

Publicly disclosed losses of approximately US$198.8 million in July increased significantly from June, with 45 recorded incidents in June totaling US$76.51 million. This is a close to 160% increase, about 2.6 times the June total, and the number of comparable events (losses were publicly disclosed in July 34 and events with a clear amount in June 38) also supports the comparison.

The structure of the loss is the same. The largest incident in June-a $32 million private key leak from the Humanity Project spanning the Ethereum and BNB chains-alone accounted for 41.8% of the month's total. This is exactly the same structure as the Coldcard case in July: For two consecutive months, infrastructure or key-level failures, rather than protocol logic flaws, separately defined the financial losses for the month.

Three directions for the actual loss of funds

July events are classified based on the actual failure cause rather than the event label, and can be classified into three categories. Some of these items need to be reclassified: Ostium's loss was originally classified as "protocol logic", but was actually due to the leak of the oracle signature key; and the Wanchain and Verus Ethereum Bridge attacks, although bearing the same common label, were actually textbook-style cross-chain bridge vulnerabilities. Classification by actual root cause is as follows:

Category| number of events| total loss| Proportion of
Wallet and Key Infrastructure| 6 |Approximately $106.7 million| 54%
DeFi protocol vulnerability| 25 |Approximately $49.7 million| 25%
Cross-chain Bridge| 4 |Approximately $42.4 million| 21%

Wallet and Key Infrastructure (US$106.7 million)

Coldcard's firmware vulnerability is headlines, but it is not an isolated case. Triple-A lost $11.8 million due to a hot wallet leak involving Ethereum, Wave Field and Arbitrum. Ostium lost $18 million after attackers obtained the private key signature of its price oracle on Arbitrum-not through a contract vulnerability, but through a key that was supposed to protect it. WEMIX lost $6.25 million due to owner key disclosure on its own WEMIX 3.0 chain. Bankelbot lost a small amount of $479,885 due to an account breach on Ethereum, but the fundamental failure was the same as other incidents in its category: a credential issue, not a code issue. Zilliqa's exchange partners suffered a random number generation vulnerability similar to Coldcard.

DeFi protocol vulnerabilities (US$49.7 million)

This is the category with the largest number of incidents (25 independent protocols), but the smallest proportion of amounts. Oracle machines and price manipulation are repeated here: 42DAO ($912,000), Cascade Liquidity Strategy ($1.34 million), Bonzo Lend ($9.05 million), Allbridge Core ($1.65 million via flash loan), Solido Cash ($73,400) and Edel Finance ($403,000) all originated from manipulated or misallocated price feeds rather than stolen keys. Governance attacks hit BarnBridge ($776,000) and BonkDAO ($20 million), the latter being the single largest loss in the category. Lightning loans, calculation errors and input verification vulnerabilities make up the rest, with most incidents costing tens or hundreds of thousands of dollars rather than tens of millions of dollars.

Cross-chain bridge (US$42.4 million)

AFX Trade lost $24.15 million due to the disclosure of the signature key of the verifier on the cross-chain bridge it operated. Arbitrum Native Bridge was directly confirmed by Offchain Labs that it was not affected. Blockaid traced the stolen USDC to be transferred to Ethereum and converted into approximately 12,467 ETH pieces, stored in an identifiable wallet rather than a currency mixer. The Verus Ethereum Bridge lost $7.54 million, which multiple media outlets claimed was taking advantage of a duplicate vulnerability (signature verification flaw) that was not fully fixed in an incident in May. Wanchain's Cardano-BNB chain bridge lost $10 million due to a similar signature/replay vulnerability. TeleSwap's Bitcoin Bridge lost $735,000, the only incident in the category with undisclosed details.

Pattern revealed by data

DeFi protocol vulnerabilities were the most common failure mode in July, accounting for 25 of 35 incidents, but only about a quarter of U.S. dollar losses. More than half of July's losses resulted from key or credential leaks, not contract code flaws. Ido Ben-Natan, co-founder and CEO of Blockaid, clearly pointed out this pattern when talking about the Coldcard case: In his view, most of the losses in 2026 came from key leaks and operational security failures, rather than smart contract vulnerabilities. This is a real difference worth noting, but not an absolute severity ranking.

Key-based attacks often allow an attacker to obtain all assets held in a wallet or bridge at once. Contract vulnerabilities are usually limited to the extent that a specific function can be transferred. These two failure modes do not accidentally have different risks for each incident, but they have structural differences in what they expose.

How many Coldcard wallets are still exposed?

Coinkite has told Coldcard users that funds should be migrated if seeds are generated on affected firmware, but the company acknowledges that it cannot reliably determine which wallets have been exposed through direct testing. CZ's public call to spread funds across multiple wallets is directed at this uncertainty, not at Coldcard's own failure-his view is that any single device, no matter how trustworthy, is still a single point of failure.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP