Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email.
Here's the month in security 👇
Hack of the month: Coldcard, ~$115M.
In a sweep during the final days of July, an attacker drained roughly $115M in BTC from Coldcard hardware wallets. A firmware defect caused key generation to fall back from the dedicated hardware random-number generator to predictable software inputs (the chip's serial number and clock registers), which cut the seed space down to roughly four billion possibilities. The attacker regenerated candidate seeds on their own hardware, derived the resulting addresses, and matched them against the public chain. Early reporting put the loss near $70M while the drain was still in progress; the final tally reached about $115M, and there is no self-test an owner can run to check exposure. It is the single largest event of the month, about 48% of July's total losses.
Source | CoinDesk · Bitcoin Magazine
AFX Bridge, ~$24.15M (Jul 22).
The Arbitrum-based perpetuals venue lost about $24.15M when its bridge signing keys were compromised, and withdrawals were authorized with no matching deposits.
Source | CoinDesk · The Block
Ostium, ~$23.75M (Jul 15).
The Arbitrum trading protocol lost about $23.75M after an attacker seized an oracle key and pushed future-dated price data into the protocol's own feed, minting artificial profits. Ostium paused trading.
BonkDAO, ~$21.3M (Jul 6).
An attacker pushed a malicious proposal through governance and executed it against the treasury, draining about $21.3M and pressuring the BONK token.
Source | The Crypto Times
Off-chain: Web2 broke the same way.
July's biggest traditional-security incidents traced back to the same root cause, a single compromised credential or key. The Bank of Baroda lost roughly 1 TB of customer and internal data after one employee email account was compromised, and Swiss rail manufacturer Stadler Rail was breached by the Everest gang through a supplier's data-exchange platform, refused a $12.3M ransom, and had about 271,000 files leaked. Paidwork exposed roughly 23M users, and KDDI up to 12M customers. In a preview of where this is heading, attackers compromised the Hugging Face AI model repository through an autonomous AI agent, an attack surface that barely existed a year ago.
Source | BleepingComputer · Reuters · Hugging Face
The pattern across the month.
July's most expensive lessons, onchain and off, were on the security of keys and the quality of randomness. This is the same failure class that ran through June, only larger. Treat randomness sources, key custody (especially hot signers on bridges and oracles), governance execution paths, and third-party access as first-class parts of the review, and monitor as if a key will eventually leak, because in July many did.
Disclaimer
This report aggregates publicly reported information as of the publication date and may be revised as investigations evolve and post-mortems are released. Recommendations are general guidance. Verify against primary sources before acting on any specific claim.
About This Series
Quantstamp publishes the Security Beat monthly. We've conducted 1,300+ audits and secured $500B+ in digital assets across 250+ clients, including Ethereum Foundation, Aave, Polymarket, Ethena, Visa, OpenSea, Maker, Curve, Compound, and Lido. If you'd like to chat about anything security or request an audit, check out quantstamp.com.
%20(3).png)
%20(2).png)
.png)
%20(2).png)








