July Security Beat: Keys Over Code (Again?)

August 10, 2026
Quantstamp Announcements

Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email.

Here's the month in security 👇

Category Loss Incidents
Private key / entropy / hot-wallet compromise ~$149.3M 4
Price-oracle manipulation ~$36.1M 5
Malicious governance proposal ~$22.1M 2
Bridge signature / verification bypass ~$14.0M 2
Other protocol logic, flash-loan, AMM ~$18.5M 16
Total (Jul 1 to 31) ~$240M 29

Hack of the month: Coldcard, ~$115M.

In a sweep during the final days of July, an attacker drained roughly $115M in BTC from Coldcard hardware wallets. A firmware defect caused key generation to fall back from the dedicated hardware random-number generator to predictable software inputs (the chip's serial number and clock registers), which cut the seed space down to roughly four billion possibilities. The attacker regenerated candidate seeds on their own hardware, derived the resulting addresses, and matched them against the public chain. Early reporting put the loss near $70M while the drain was still in progress; the final tally reached about $115M, and there is no self-test an owner can run to check exposure. It is the single largest event of the month, about 48% of July's total losses.

Source | CoinDesk · Bitcoin Magazine

AFX Bridge, ~$24.15M (Jul 22).

The Arbitrum-based perpetuals venue lost about $24.15M when its bridge signing keys were compromised, and withdrawals were authorized with no matching deposits.

Source | CoinDesk · The Block

Ostium, ~$23.75M (Jul 15).

The Arbitrum trading protocol lost about $23.75M after an attacker seized an oracle key and pushed future-dated price data into the protocol's own feed, minting artificial profits. Ostium paused trading.

Source | CoinDesk · Halborn

BonkDAO, ~$21.3M (Jul 6).

An attacker pushed a malicious proposal through governance and executed it against the treasury, draining about $21.3M and pressuring the BONK token.

Source | The Crypto Times

Off-chain: Web2 broke the same way. 

July's biggest traditional-security incidents traced back to the same root cause, a single compromised credential or key. The Bank of Baroda lost roughly 1 TB of customer and internal data after one employee email account was compromised, and Swiss rail manufacturer Stadler Rail was breached by the Everest gang through a supplier's data-exchange platform, refused a $12.3M ransom, and had about 271,000 files leaked. Paidwork exposed roughly 23M users, and KDDI up to 12M customers. In a preview of where this is heading, attackers compromised the Hugging Face AI model repository through an autonomous AI agent, an attack surface that barely existed a year ago.

Source | BleepingComputer · Reuters · Hugging Face

The pattern across the month.

July's most expensive lessons, onchain and off, were on the security of keys and the quality of randomness. This is the same failure class that ran through June, only larger. Treat randomness sources, key custody (especially hot signers on bridges and oracles), governance execution paths, and third-party access as first-class parts of the review, and monitor as if a key will eventually leak, because in July many did. 

Disclaimer

This report aggregates publicly reported information as of the publication date and may be revised as investigations evolve and post-mortems are released. Recommendations are general guidance. Verify against primary sources before acting on any specific claim.

About This Series

Quantstamp publishes the Security Beat monthly. We've conducted 1,300+ audits and secured $500B+ in digital assets across 250+ clients, including Ethereum Foundation, Aave, Polymarket, Ethena, Visa, OpenSea, Maker, Curve, Compound, and Lido. If you'd like to chat about anything security or request an audit, check out quantstamp.com.

Quantstamp Announcements
August 10, 2026

Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email.

Here's the month in security 👇

Category Loss Incidents
Private key / entropy / hot-wallet compromise ~$149.3M 4
Price-oracle manipulation ~$36.1M 5
Malicious governance proposal ~$22.1M 2
Bridge signature / verification bypass ~$14.0M 2
Other protocol logic, flash-loan, AMM ~$18.5M 16
Total (Jul 1 to 31) ~$240M 29

Hack of the month: Coldcard, ~$115M.

In a sweep during the final days of July, an attacker drained roughly $115M in BTC from Coldcard hardware wallets. A firmware defect caused key generation to fall back from the dedicated hardware random-number generator to predictable software inputs (the chip's serial number and clock registers), which cut the seed space down to roughly four billion possibilities. The attacker regenerated candidate seeds on their own hardware, derived the resulting addresses, and matched them against the public chain. Early reporting put the loss near $70M while the drain was still in progress; the final tally reached about $115M, and there is no self-test an owner can run to check exposure. It is the single largest event of the month, about 48% of July's total losses.

Source | CoinDesk · Bitcoin Magazine

AFX Bridge, ~$24.15M (Jul 22).

The Arbitrum-based perpetuals venue lost about $24.15M when its bridge signing keys were compromised, and withdrawals were authorized with no matching deposits.

Source | CoinDesk · The Block

Ostium, ~$23.75M (Jul 15).

The Arbitrum trading protocol lost about $23.75M after an attacker seized an oracle key and pushed future-dated price data into the protocol's own feed, minting artificial profits. Ostium paused trading.

Source | CoinDesk · Halborn

BonkDAO, ~$21.3M (Jul 6).

An attacker pushed a malicious proposal through governance and executed it against the treasury, draining about $21.3M and pressuring the BONK token.

Source | The Crypto Times

Off-chain: Web2 broke the same way. 

July's biggest traditional-security incidents traced back to the same root cause, a single compromised credential or key. The Bank of Baroda lost roughly 1 TB of customer and internal data after one employee email account was compromised, and Swiss rail manufacturer Stadler Rail was breached by the Everest gang through a supplier's data-exchange platform, refused a $12.3M ransom, and had about 271,000 files leaked. Paidwork exposed roughly 23M users, and KDDI up to 12M customers. In a preview of where this is heading, attackers compromised the Hugging Face AI model repository through an autonomous AI agent, an attack surface that barely existed a year ago.

Source | BleepingComputer · Reuters · Hugging Face

The pattern across the month.

July's most expensive lessons, onchain and off, were on the security of keys and the quality of randomness. This is the same failure class that ran through June, only larger. Treat randomness sources, key custody (especially hot signers on bridges and oracles), governance execution paths, and third-party access as first-class parts of the review, and monitor as if a key will eventually leak, because in July many did. 

Disclaimer

This report aggregates publicly reported information as of the publication date and may be revised as investigations evolve and post-mortems are released. Recommendations are general guidance. Verify against primary sources before acting on any specific claim.

About This Series

Quantstamp publishes the Security Beat monthly. We've conducted 1,300+ audits and secured $500B+ in digital assets across 250+ clients, including Ethereum Foundation, Aave, Polymarket, Ethena, Visa, OpenSea, Maker, Curve, Compound, and Lido. If you'd like to chat about anything security or request an audit, check out quantstamp.com.

Quantstamp Announcements

June Security Beat: Keys Over Code

$75.32M was lost across 32 crypto incidents in June, up from May's $59.52M. No coordinated campaign carried the month, but one targeted operation did. A targeted social-engineering attack against Humanity Protocol reached the keys behind the $H token and drained $32M, roughly 42% of every dollar lost in June. Quantstamp led the independent investigation and traced the tooling to a phishing campaign previously seen targeting macOS users. Offchain, a fresh npm supply chain wave hit Red Hat's packages on the first day of the month, and a PeopleSoft zero-day was exploited for two weeks before Oracle said a word. Here's the month in security 👇

Read more
Quantstamp Announcements

May 2026 Security Beat

$59.52M was lost across 29 crypto incidents, down sharply from April's ~$635M. No single hack carried the month. The bigger story happened off-chain, where a self-propagating npm worm called Mini Shai-Hulud kept resurfacing in new waves through the month, ultimately spanning more than 1,000 malicious package versions across the npm ecosystem.

Read more
Quantstamp Announcements

April 2026 Security Beat: Same Actors, New Targets

April was undoubtedly a rocky month in security. $635M was lost across 28 crypto incidents. The Axios npm package was compromised on day one, exposing an estimated 600,000 installs in three hours. Vercel was breached through a third party. Three major CVEs under active exploitation. Here's the month in security 👇

Read more