In July, crypto asset losses reached US$210.3 million, with the COLDCARD vulnerability ranking first.
In July, a total of 30 security incidents occurred in the cryptocurrency field, and the total loss amount climbed to US$210.3 million. Among them, the COLDCARD firmware vulnerability became the third largest encryption theft case this year. Unlike in the past, the biggest attacks this month did not target smart contract code, but targeted hardware devices, developer machines and oracle machines.
AFX Trade offered attackers a share condition to recover the remaining funds
According to the July 2026 report released by PeckShield, the loss of cryptographic assets due to hacking this month reached US$210.3 million, a surge of 177.2% from US$75.87 million in June. However, this month's losses did not stem from smart contract vulnerabilities that audits could discover, but from firmware flaws in hardware wallets, developers being deceived for false recruitment, bogus timestamps being injected into bogus machines, and governance votes to buy tickets on the open market. Four major incidents accounted for the majority of the total damage, in line with a trend that security companies have emphasized repeatedly throughout the year: fewer attacks, but more targeted each attack.
Overview of loss distribution of US$210.3 million
COLDCARD: US$70.0 million
AFX Trade: US$24.15 million
Ostium: US$23.75 million
BONK DAO: US$20 million
Wanchain: US$13 million
Triple-A: US$10 million
Bonzo Lend: US$9.05 million
Verus: US$7.5 million
Wemix Network: US$6.25 million
summer.finance: US$6 million
(Note: The column length is scaled to the maximum loss. Data sources: PeckShield, Blockaid, Halborn)
COLDCARD attack: $30 million was stolen in ten minutes
According to PeckShield statistics, Coinkite's COLDCARD hardware wallet accounted for approximately $70 million in losses this month. Galaxy Research traced approximately 1083 BTC items scattered across 1196 addresses, while Chainalysis confirmed approximately $38 million in cash flow on the chain. Even on a lower scale, the incident ranks third among all crypto thefts this year, behind Drift and KelpDAO/LayerZero incidents. The problem lies in the firmware: the device's true random number generator was bypassed and quietly downgraded to a predictable software random source, causing the seed generation entropy of the affected Mk3 device to drop from the expected 128 bits to about 40 bits. At this level, the key is no longer unguessable and an attacker with sufficient resources can rebuild the key through brute force.
The July 30 and 31 attacks were quick and methodical. Chainalysis reported that the attacker had mapped out in advance which wallets held the most assets, prioritized attacking the address with the largest single balance, and stole approximately $30 million within the first ten minutes. Self-hosting is based on one core assumption: the encryption algorithm running on the device is secure. Even if users save seeds offline, verify every address, and follow all rules, they may still lose their wallets because the vulnerability lies at the bottom level beyond the user's control.
AFX Trade: Fake recruitment leads to cross-chain bridges out of control
AFX Trade, a perpetual contract agreement on Arbitrum, lost $24.15 million after a developer was attacked by a fake recruiter. The attacker posed as a hiring manager for a company called Oddium Lab and lured developers into cloning a seemingly legal code warehouse on July 9. The repository contains malicious Git configurations that execute hidden loads in regular workflows, allowing attackers to gain access to the developer's machine. The Arbitrum network itself has not failed. Steven Goldfeder, co-founder of Offchain Labs, quickly pointed out that the basic layer of the second-layer network remains secure at all times, as does Ostium, which runs on the same network. The attack occurred on the developer's own machine.
After entering the development environment, the attacker extracted the private key of the cross-chain bridge hot validator. Five verifier signatures are enough to reach the two-thirds threshold required for bridging, so the smart contract treats the withdrawal request as fully legal and executes it. The entire process does not require breaking any code. AFX Trade then followed what more agreements do after an attack: offering attackers a 30% reward (approximately $7.2 million) in exchange for the return of the remaining 70% of the funds.
How Ostium attackers drove down the price of Bitcoin to $5000
Ostium lost $23.75 million due to its price-feeding mechanism. The attacker obtained the private key of the platform oracle and pushed the future timestamp through a registered repeater called PriceUpKeep. This allowed them to inject a fake Bitcoin price of $5000 into the contract, open highly leveraged positions based on this fictitious price, and then settle at a real market price of close to $60,000. The spread becomes net profit and is paid out from the platform's liquidity vault to positions that have never made a profit. Halborn Security pointed out that one detail turned the vulnerability into an open door: PriceUpKeep infrastructure was excluded from Ostium's active vulnerability bounty. White-hat researchers had no incentive to check it, so no one cared about it, and the attacker followed an unmonitored path directly to the price-feeding mechanism.
BONK DAO: Voted to hand over your vault
The BONK DAO event on Solana completely bypasses the code. No need to exploit any loopholes. The attackers spent approximately $4 million to buy BONK tokens on the exchange, and then used those voting rights to control almost the entire voting process. The turnout rate was extremely low, with wallets associated with attackers accounting for approximately 99.9% of the vote, and a proposal to transfer approximately $20 million in treasury tokens to attackers 'wallets passed smoothly. Each step conforms to the DAO's own rules. Strictly speaking, the theft was legal because the agreement worked exactly as it was written.
Detailed explanation of each attack type
Wallet firmware· COLDCARD ·US$70 million
The random number generator is bypassed, the entropy of the affected Mk3 device is reduced to about 40 bits, and the private key can be reconstructed through brute force.
Developer machine· AFX Trade ·US$24.15 million
A malicious code warehouse from a fake recruiter compromised the developer machine; a stolen verifier signature made cross-chain bridge withdrawals deemed legal by the contract.
Price oracle· Ostium ·US$23.75 million
The stolen signature key wrote the Bitcoin price to US$5000, opened a leveraged position, and then settled from a liquidity vault at a price close to US$60,000.
Governance vote· BONK DAO ·US$20 million
The attacker bought enough BONK tokens to vote on the DAO, and passed a proposal to empty the treasury funds into his wallet.
Audits are no longer the focus of funding leaks
For years, security discussions have centered around smart contract audits, assuming that a clean code base means safe protocols. But July data suggests otherwise. Web3 security researcher Victor Okpukpan pointed out on the X platform that large attacks are moving away from on-chain code to key management, developer workplaces and oracle paths. CertiK's semi-annual report also confirms this shift: in the first half of 2026, 33 wallet security incidents alone caused US$444.5 million in losses, surpassing smart contract vulnerabilities to become the highest cost attack category per single attack, although code vulnerabilities still cause more incidents. The four largest incidents in July met this judgment, and none required searching for vulnerabilities in deployed contracts.
Impact of firmware vulnerabilities on self-hosting
The COLDCARD incident hit retail owners hardest-they chose hardware wallets precisely to distrust anyone. If underlying chip or firmware errors can disrupt perfect personal security measures, the argument for holding private keys is weakened for users who lack the technical ability to audit their own devices. This pressure has shifted some of the market towards regulated custodians and spot Bitcoin ETFs, shifting the security burden from individuals to institutions.
Agreement begins to set aside budgets for paying attackers
AFX Trade's proposal is moving from exception to routine practice. Negotiating the recovery of stolen funds has shifted from a rare temporary measure to a written Incident Response Service plan, with some companies viewing paying a certain percentage of the amount to attackers as a recovery cost. However, the legal status of these payments has not yet been determined. U.S. and European regulators have yet to clearly distinguish between ransom and legal settlements, and how they ultimately define the bounty paid to known thieves will determine whether the means used to save most of AFX Trade's funds will still apply to the next deal that requires it.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BONK
BTC