A new report has revealed that hackers stole $247.4 million in cryptocurrency in July 2026, making it the second-worst month of the year for crypto thefts, behind April’s $644 million total, according to DefiLlama data.
The figure more than tripled the $75 million lost in June and the $60 million recorded in May.
The primary driver was a major exploit targeting Coldcard hardware wallets. Confirmed losses exceed $38 million, though Galaxy Research estimates the total impact could reach $110 million as attacks continue.
The attacker systematically swept 500 distinct victim wallets over the course of 25 minutes, prioritizing the largest holdings first. Cumulative value stolen skyrocketed to roughly $30 million within the first 10 minutes, and three of the 10 largest victim wallets each held over $636K (10 BTC).
The early targeting of high-value wallets, including a single $1.8 million victim, suggests that the attacker studied the victim wallet population in advance, rather than sweeping indiscriminately.
Also, Galaxy Digital reported that attackers drained at least $100 million in Bitcoin from roughly 7,300 wallets across three confirmed attack waves.
A suspected fourth wave could push total losses from the incident toward $130 million, while DefiLlama’s tracker places the figure at approximately $115 million.
The vulnerability stemmed from a firmware issue affecting seed generation on certain Coldcard models, which reduced the effective randomness of recovery phrases and allowed private keys to be reconstructed offline without physical access to the devices. Many of the affected wallets had remained dormant for years.
The episode has drawn attention because Coldcard devices are designed for cold storage, keeping private keys offline and away from internet-connected systems.
Research platform CryptoRank noted that the month demonstrated how technological risks can still place thousands of wallets at risk simultaneously, even when assets are held in hardware wallets intended for maximum security.
July also saw several other significant incidents. These included a $24 million theft from the Arbitrum-based perpetual exchange AFX involving a bridge exploit, a $9 million oracle-related attack on the DeFi protocol Bonzo Lend, $7.5 million stolen via the Verus Ethereum Bridge, and $2.6 million taken from the Cardano-based wallet SecondFi due to a wallet flaw.
The concentration of losses in a single hardware wallet vulnerability has prompted renewed discussion within the industry about the limits of self-custody assumptions and the importance of rigorous firmware auditing.
Coinkite, the maker of Coldcard, has issued guidance urging affected users to generate new seeds and migrate funds where necessary.
Notably, with more than $30 million already stolen through mid-2026, this year is on pace to surpass 2025’s record $58 million total. Chainalysis noted that home invasions have climbed from 26% of documented incidents in 2023 to 37% in 2026, allowing criminals to compel immediate transfers in controlled environments.
Attacks targeting family members have grown from near zero in 2021 to 25-30% of cases.
Amidst the numerous attacks last month, Cryptocurrency exchange Bybit has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB) intelligence agency, the Lazarus Group, and 20 unidentified “John Doe” defendants.
The suit stems from the February 21, 2025, cyberattack that drained approximately $1.5 billion in Ethereum and staked Ether over 400,000 ETH and stETH from the Dubai-based platform, marking the largest cryptocurrency theft on record.
Bybit announced the action on August 7–8, 2026, stating that it has also secured a preliminary injunction freezing identified stolen assets held by the John Doe defendants. The court order prohibits the transfer, sale, or dissipation of those assets while the litigation proceeds.
As of early August, the broader July totals underscore that sophisticated attackers continue to identify and exploit weaknesses across both on-chain protocols and offline storage solutions.
Outlook
The July figures point to a worsening security environment for the cryptocurrency industry, with attackers increasingly exploiting vulnerabilities across both decentralized protocols and hardware-based self-custody solutions.
The scale of the Coldcard incident is particularly significant because it challenges the assumption that keeping assets offline automatically eliminates major cybersecurity risks.
Looking ahead, the industry is likely to place greater emphasis on firmware security, independent code audits, vulnerability disclosure, and faster migration procedures when flaws are discovered.
Hardware-wallet providers may also face growing pressure to strengthen seed-generation processes and improve mechanisms for identifying potentially compromised wallets.






