July's $247 Million Crypto Hack Wave Reveals a Troubling New Reality: Cold Storage Isn't Enough
July 2026 became the second-worst month for cryptocurrency theft this year, with hackers stealing an estimated $247.4 million across hardware wallets, bridges, lending protocols, and trading platforms. The total was more than triple June's $75 million in losses and four times May's $60 million, according to DeFiLlama data. Only April, when losses reached approximately $644 million, has recorded more stolen crypto in 2026.
What Made July So Catastrophic for Crypto Security?
The defining incident was the Coldcard hardware wallet exploit, which dominated the month's losses. Galaxy Research identified at least three confirmed attack waves affecting roughly 7,300 Bitcoin wallets and resulting in more than $100 million in stolen BTC, with a suspected fourth wave potentially raising losses to approximately $130 million. DefiLlama currently estimates the Coldcard incident at around $115 million, meaning it alone accounted for roughly 46% of all crypto stolen during July.
What made Coldcard particularly significant was that it shattered a common assumption in the crypto community. Coldcard is a hardware wallet specifically designed to keep private keys offline, away from internet-connected devices. The vulnerability was linked to how affected versions generated wallet recovery information, proving that cold storage can reduce exposure to online attacks but does not eliminate risks originating inside wallet hardware or firmware itself.
Beyond Coldcard, July's attack surface extended far beyond vulnerable smart contracts. Arbitrum, a popular scaling solution for Ethereum, experienced two of the month's largest security incidents. An AFX-related bridge suffered a private-key compromise on July 22 that resulted in approximately $24.15 million being stolen, with the attacker converting much of the stolen USDC stablecoin into Ethereum. Offchain Labs, which operates Arbitrum, clarified that Arbitrum's native bridge itself was not compromised.
How Did Attackers Target Infrastructure Beyond Smart Contracts?
A week before the AFX bridge incident, decentralized trading platform Ostium lost another $23.75 million after its off-chain price infrastructure was compromised. The attacker submitted fabricated price reports and used them to generate artificially profitable trades against Ostium's liquidity provider vault. Ostium noted that trader collateral was stored separately and was not affected.
Oracle systems, which provide real-world price data to blockchain applications, became a major attack vector. Hedera-based lending protocol Bonzo Lend lost about $9 million on July 11 after an attacker manipulated the price of SAUCE through a vulnerability in a third-party oracle's verification system. The manipulated price dramatically inflated the value of the attacker's collateral, allowing assets to be borrowed far beyond the collateral's true value. Bonzo later announced that affected user positions would be covered through a recovery facility backed by the Hedera Foundation.
Crypto payments company Triple-A was another major infrastructure target. Attackers gained unauthorized access to company hot wallets across multiple blockchains in late July, with initial estimates placing losses around $9.7 million. DefiLlama classifies the incident as a hot-wallet compromise, and Triple-A said customer funds were held separately and were unaffected.
The Verus-Ethereum Bridge lost approximately $7.53 million on July 22 through what DefiLlama classified as a bridge verification bypass. Wanchain suffered another $6.5 million loss a day earlier in a signature-related exploit. Several smaller incidents added to the month's tally, including an $8.2 million Crypto DAO exploit, a $1.65 million Allbridge Core attack, and multiple oracle and liquidity-manipulation incidents.
Steps to Understanding Crypto's Expanding Attack Surface
- Hardware and Firmware Vulnerabilities: Even offline storage devices like Coldcard can be compromised through flaws in how they generate recovery information, proving that physical isolation from the internet is not a complete security solution.
- Infrastructure Compromises: Attackers increasingly target operational systems like price feeds, bridges, and hot wallets rather than smart contract code, shifting the security burden from developers to infrastructure operators.
- Oracle Manipulation: Third-party price-reporting systems can be exploited to artificially inflate collateral values, allowing attackers to borrow far more than their actual holdings warrant.
- Private Key Exposure: Compromised private keys across bridges and payment systems remain a critical vulnerability, even when user funds are stored separately from operational wallets.
One notable clarification concerns SecondFi, a Cardano wallet that lost roughly $2.4 million to $2.6 million and featured in several July hack roundups. SecondFi's own timeline indicates the principal attack waves occurred between June 21 and June 23, with the fallout, recovery effort, and eventual decision to shut down continuing throughout July.
July's incidents ultimately demonstrate that crypto's attack surface now extends well beyond vulnerable smart contracts. Private keys, hardware wallets, oracle infrastructure, bridges, and operational systems all provided attackers with paths to multimillion-dollar losses. This shift represents a fundamental challenge for the industry: securing decentralized finance requires protecting not just code, but the entire ecosystem of hardware, infrastructure, and human operations that support it.