July’s transformation into the second-worst month in 2026 in terms of cryptocurrency thefts, after the exploitation of Coldcard played a key role in pushing total losses to $247.4 million.
According to DefiLlama data, this figure represents the highest monthly level this year after April’s losses of $644 million. It also came far higher than June’s losses of $75 million, and May’s losses of $60 million.
What happened with Coldcard?
The exploitation of Coldcard was the biggest attack of the month, with at least $100 million in Bitcoin stolen from 7,300 wallets across three confirmed waves of attacks, according to Galaxy Digital.
The company itself noted that a suspected fourth wave could raise total losses to around $130 million. Meanwhile, the DefiLlama breach tracker estimated losses related to the attack at $115 million.
Why does this attack matter?
The main takeaway from the incident is that cold storage does not eliminate technical risks entirely. This is what the research platform CryptoRank highlighted, saying that July showed that even cold wallets can face technical risks that could affect thousands of wallets at the same time.
For users, this incident once again underscores the importance of reviewing wallet-related security procedures, relying on multiple layers of protection, and not assuming that the storage type alone is sufficient to secure digital assets.
Other breaches in July
Coldcard was not the only attack during the month. July also saw several notable breaches, including:
• A $9 million breach against the decentralized finance protocol Bonzo Lend.
• A $2.6 million theft from a SecondFi wallet built on Cardano.
• A $24 million theft from the perpetual contracts platform AFX built on Arbitrum.
• A $7.5 million theft via the Verus Ethereum Bridge.
These figures show that the security landscape in the cryptocurrency sector is still vulnerable to large-scale attacks, even when it comes to infrastructures assumed to be more secure, such as cold wallets.
