Crypto losses hit a staggering $210 million in July 2026, marking a 177% increase from June. This surge, recorded over 30 major hacks, highlights a disturbing trend: most attacks exploited well-known vulnerabilities rather than inventive new methods.

Details Behind the Biggest Breaches

The largest single incident targeted Coldcard hardware wallets, exploiting a critical entropy-generation flaw found in its Mk2 and Mk3 firmware versions. This flaw, relying on predictable inputs instead of true hardware randomness, put roughly $70 million at risk. Users who created seeds with the vulnerable firmware must urgently generate new seeds and move their assets, as the patch only prevents future weaknesses without fixing compromised keys.

Several major hacks originated from manipulated price oracles. AFX Trade reported a $24 million loss through a USDC custody bridge on Arbitrum, while Ostium suffered a similar hit. Both fell victim to false data fed into their price feeds, leading to erroneous payouts. This class of oracle attacks remains a persistent threat due to the reliance on single-source price feeds.

Industry Reactions and Implications

These incidents shows the urgent need to reexamine foundational security architectures. Governance loopholes, such as low voting quorums without timelocks, and inadequate message encoding security also contributed to losses exceeding $20 million in some cases. The BonkDAO’s $21.2 million governance bypass and $20.5 million drained from Wanchain and Verus bridges exemplify this challenge.

As hacks keep exploiting known weaknesses, the industry faces mounting pressure to implement long-overdue fixes. The Coldcard breach serves as a stark warning for hardware wallet users to stay vigilant and ensure their devices are updated. Failures at the oracle level also highlight systemic risks tied to decentralized finance infrastructure.

This material is informational and not financial advice.