Crypto thieves stole $247.4 million from digital asset platforms in July 2026, the second-largest monthly haul this year behind April’s $644 million, according to DeFiLlama.
The sharp increase was driven primarily by the high-profile Coldcard exploit, which alone accounted for more than $100 million in stolen Bitcoin and highlighted that even hardware wallet ecosystems remain vulnerable to sophisticated attacks.
Data from DeFiLlama shows July’s losses were exceeded only by April, when hackers stole approximately $644 million from crypto platforms. July’s total represented a dramatic increase from the $75 million stolen in June and the $60 million recorded in May, signaling a troubling resurgence in cyberattacks targeting the digital asset ecosystem.
Security researchers say the latest figures reinforce concerns that attackers are becoming increasingly capable of exploiting both decentralized finance protocols and infrastructure traditionally viewed as secure.
Coldcard exploit dominates July’s losses
The biggest contributor to July’s Crypto theft figures was the Coldcard exploit, which compromised roughly 7,300 Bitcoin wallets through three confirmed waves of attacks.
According to research from Galaxy Digital, the attackers stole at least $100 million worth of Bitcoin during the confirmed incidents. The firm’s analysts also identified signs of a suspected fourth wave that could push the overall losses to approximately $130 million if confirmed.
Meanwhile, DeFiLlama’s hack tracking platform currently estimates the exploit resulted in around $115 million in stolen funds, making it by far the largest individual security breach recorded during the month.
The incident has drawn particular attention because Coldcard products are widely recognized within the Bitcoin community for emphasizing offline key management and hardware-based protection. The breach has therefore prompted fresh discussions about the evolving sophistication of cybercriminals and the importance of securing every layer of wallet infrastructure.
Security experts have repeatedly warned that attackers continue adapting their methods as the cryptocurrency market matures, often targeting overlooked software components, supply-chain weaknesses, or user interactions rather than relying solely on direct attacks against blockchain networks.
As blockchain security specialist Taylor Monahan, security researcher at MetaMask, has previously noted:
“The biggest vulnerability is almost always the human.”
Her observation continues to resonate as many recent attacks combine technical exploits with operational weaknesses to maximize damage.
Security experts warn no storage method is completely risk-free
The latest wave of Crypto theft has reignited debate over whether cold storage alone provides sufficient protection for digital assets.
Research platform CryptoRank said the July attacks demonstrate that even offline-focused storage solutions cannot eliminate every technological risk.
In a post published on X, the firm stated:
“July showed that even cold storage does not eliminate technological risks, which can put thousands of wallets at risk simultaneously.”
The warning reflects a broader industry consensus that security must extend beyond simply choosing a hardware wallet. Experts increasingly recommend layered defenses, including firmware verification, secure backups, multi-signature wallet configurations, and careful transaction validation.
Chainalysis has similarly argued in previous cybersecurity reports that attackers continue refining increasingly sophisticated techniques as digital assets become more valuable and institutional participation grows. The blockchain analytics firm has repeatedly emphasized that stronger operational security and continuous monitoring are becoming essential across the crypto industry.
The renewed focus on infrastructure security comes at a time when institutional adoption of Bitcoin continues expanding, raising the stakes for wallet providers and custodians responsible for safeguarding billions of dollars in digital assets.
Several other major hacks added to July’s damage
Although the Coldcard exploit dominated headlines, several other significant incidents also contributed to July’s Crypto theft total.
Among the most notable was a $24 million exploit targeting AFX, an Arbitrum-based perpetual futures exchange. The breach ranked as the month’s second-largest attack and underscored the persistent risks facing decentralized finance platforms.
Elsewhere, decentralized lending protocol Bonzo Lend suffered losses of approximately $9 million following an oracle manipulation exploit on the Hedera network.
Cardano-based wallet SecondFi also reported around $2.6 million in stolen ADA after attackers exploited a wallet-related vulnerability, ultimately leading to the project’s shutdown.
In another notable incident, hackers stole approximately $7.5 million through the Verus Ethereum Bridge, highlighting ongoing security challenges surrounding cross-chain bridge infrastructure—a sector that has historically remained one of the most attractive targets for cybercriminals.
Collectively, these attacks demonstrate that Crypto theft remains a widespread challenge affecting multiple blockchain ecosystems rather than a single network or protocol.
Industry faces renewed pressure to strengthen defenses
The sharp increase in Crypto theft during July is likely to intensify pressure on wallet providers, developers, exchanges, and decentralized finance projects to improve security standards before vulnerabilities can be exploited.
As digital assets continue attracting mainstream investors and institutional capital, cybersecurity experts expect attackers to become even more sophisticated in identifying weaknesses across wallet software, bridges, smart contracts, and supporting infrastructure.
While blockchain technology itself has generally proven resilient, many of the industry’s largest losses continue to stem from flaws in applications, operational processes, and implementation rather than failures of the underlying networks.
With Crypto theft already reaching nearly a quarter of a billion dollars in July alone, the latest figures serve as another reminder that security remains one of the industry’s most pressing challenges. Whether through stronger code audits, improved wallet protections, or enhanced user education, reducing future losses will require coordinated efforts across the entire cryptocurrency ecosystem.