Crypto Thefts Surge in July, Coldcard Exploit Drives $247 Million Losses

Crypto Thefts Surge in July, Coldcard Exploit Drives $247 Million Losses

Significant cryptocurrency thefts totalled $247.4 million during July 2026, primarily due to the Coldcard exploit which resulted in losses affecting over 7,300 wallets. This represents a substantial increase compared to preceding months, exceeding June’s theft volume of $75 million and May’s $60 million. April recorded the highest theft volume this year at $644 million.

The Coldcard exploit was identified as the most significant single incident, reportedly causing losses of at least $100 million across a multitude of wallets. DefiLlama, a data aggregator and hack tracker, has been monitoring these attacks closely. The platform tracks incidents involving numerous protocols including Bonzo Lend, SecondFi, AFX and the Verus Ethereum Bridge.

Further exploits occurred during July, impacting additional decentralized finance (DeFi) protocols. These included an attack on Bonzo Lend resulting in a stolen $9 million. Similarly, SecondFi reported losses of $2.6 million, while AFX suffered a theft of $24 million. The Verus Ethereum Bridge also experienced security breaches with $7.5 million taken.

According to CryptoRank’s X post, these events highlight the continued vulnerability of cold storage solutions, even those considered secure. The firm reported that July showcased how cold storage does not eliminate technological risks, exposing thousands of wallets simultaneously. Galaxy Digital and other firms within the digital asset financial services sector are likely assessing these threats.

The total losses attributed to the Coldcard exploit are estimated to be potentially $130 million, suggesting a possible fourth wave of activity. Data from DefiLlama indicates that multiple wallets lost an additional estimated $130 million. These figures represent significant financial disruption within the cryptocurrency landscape. The situation underscores ongoing security challenges for the sector.


Written by Daniel Brooks
Security Desk

Share