Coldcard exploit pushes July losses to $247M as second-worst month of 2026

cointelegraphPublished on 2026-08-07Last updated on 2026-08-07

Abstract

July 2026 was the second-worst month of the year for cryptocurrency thefts, with hackers stealing $247.4 million. This surge was primarily driven by the Coldcard exploit, which involved multiple attack waves resulting in losses estimated between $100 million and $130 million in Bitcoin from thousands of wallets. This incident highlighted that even cold storage carries significant technological risks. Other major July hacks included attacks on Bonzo Lend ($9M), SecondFi ($2.6M), AFX ($24M), and the Verus Ethereum Bridge ($7.5M).

July emerged as the second-worst month of 2026 for cryptocurrency thefts, largely due to the recent Coldcard exploit.

Hackers stole $247.4 million in crypto in July, the most this year after the $644 million stolen in April, according to DefiLlama data. The total was more than triple the $75 million stolen in June and the $60 million stolen in May.

The Coldcard exploit was the month’s biggest exploit, with at least $100 million in Bitcoin (BTC) stolen from 7,300 wallets across three confirmed attack waves, according to Galaxy Digital. The company also identified a suspected fourth wave that could bring total losses to about $130 million. DefiLlama’s hack tracker estimates losses tied to the Coldcard exploit at $115 million.

“July showed that even cold storage does not eliminate technological risks, which can put thousands of wallets at risk simultaneously,” research platform CryptoRank said in a Thursday X post.

Other notable July exploits included a $9 million hack against decentralized finance protocol Bonzo Lend, $2.6 million stolen from Cardano-based wallet SecondFi, $24 million stolen from Arbitrum-based perpetual exchange AFX and $7.5 million stolen through the Verus Ethereum Bridge.

Magazine: Inside the ‘fake police raid’ that forced a $1M Bitcoin transfer

Related Questions

QAccording to the article, what made July 2026 the second-worst month for cryptocurrency thefts?

AJuly 2026 became the second-worst month for cryptocurrency thefts largely due to the recent Coldcard exploit, which was the month's biggest exploit.

QHow much cryptocurrency was stolen in July 2026, and how does this compare to the thefts in May and June of the same year?

AHackers stole $247.4 million in crypto in July 2026. This total was more than triple the $75 million stolen in June and the $60 million stolen in May.

QWhat was the estimated loss range from the Coldcard exploit according to the information provided by Galaxy Digital?

AAccording to Galaxy Digital, the Coldcard exploit resulted in at least $100 million stolen from 7,300 wallets across three confirmed attack waves, with a suspected fourth wave potentially bringing total losses to about $130 million.

QWhat point did research platform CryptoRank make about the Coldcard exploit in their statement?

ACryptoRank stated that the July exploits showed that even cold storage does not eliminate technological risks, which can put thousands of wallets at risk simultaneously.

QBesides the Coldcard exploit, name two other significant hacks that occurred in July 2026 as mentioned in the article.

ATwo other significant July 2026 exploits mentioned are: a $9 million hack against decentralized finance protocol Bonzo Lend, and a $24 million theft from Arbitrum-based perpetual exchange AFX.

Related Reads

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

The CLARITY Act proposes a critical federal regulatory framework for the U.S. crypto market. Currently, a lack of clear rules creates uncertainty, hinders innovation, and leaves consumers exposed. The Act would clearly divide regulatory jurisdiction between the SEC and CFTC, mandate disclosures and insider restrictions for projects, and bring exchanges and other intermediaries under a comprehensive oversight system akin to traditional finance. This clarity is urgently needed as crypto has evolved from a niche interest into a major industry with institutional involvement. Clear, lasting rules would protect consumers by requiring proper audits, custody of client assets, and anti-fraud measures for registered platforms, helping prevent failures like FTX. Regulatory ambiguity currently punishes compliant U.S. firms with high costs while rewarding offshore competitors who bypass rules, creating a race to the bottom. The Act addresses national security by applying existing anti-money laundering rules to crypto intermediaries and distinguishes between legitimate privacy and illicit concealment. It also resolves banking sector concerns by prohibiting interest payments on stablecoin balances while permitting transaction-based rewards. For developers, it establishes liability based on intent and direct assistance to crime, not for unforeseeable downstream misuse of open-source software. Regarding securities law, the Act introduces a risk-based framework. Assets begin under SEC oversight when a network is centralized, transitioning to CFTC commodity regulation if it becomes sufficiently decentralized, with clear definitions to avoid constant litigation. Without the Act, regulatory uncertainty driven by shifting agency interpretations will persist, discouraging long-term investment in the U.S. and pushing development offshore, reducing American oversight and economic leadership. Support for the bipartisan bill comes from lawmakers, law enforcement (like the Fraternal Order of Police), and major financial institutions. Ultimately, the CLARITY Act is essential to establish a stable, sensible regulatory environment that fosters responsible innovation, enhances consumer protection, and ensures U.S. leadership in shaping the future of financial technology.

marsbit1h ago

a16z Crypto: Marc Andreessen and Chris Dixon Explain Why the 'CLARITY Act' Is Urgently Needed

marsbit1h ago

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

Citi maintains a "Buy" rating on SanDisk with a $2500 price target despite a post-earnings stock drop. This target, implying an 85.1% upside from the August 5th close of $1350.50, hinges on the firm's view that SanDisk merits a higher valuation than traditional NAND cyclical stocks. Although SanDisk reported strong Q4 FY26 results with revenue up 51% sequentially and robust full-year data center growth (+437%), its stock fell sharply on August 6th. Investors are concerned about potential NAND price growth moderation and guidance that failed to meet elevated market expectations. Citi's bullish thesis centers on SanDisk's new long-term "New Business Model" (NBM) agreements. These contracts, covering a significant portion of its NAND bit output for FY27 and FY28, represent minimum revenue commitments of approximately $94 billion backed by financial guarantees. This structure aims to increase revenue and cash flow predictability. The report links this visibility to AI data center demand, driven by the expansion of inference workloads requiring more storage. Citi estimates data center storage capacity demand will grow about 35% in CY27. However, the analysis notes long-term contracts cannot eliminate the NAND cycle. Risks include potential oversupply from industry capacity expansion, competition, and macroeconomic headwinds. The $2500 target essentially bets that AI demand and these contracts can reduce earnings volatility enough to support a premium valuation (~11x CY27E EPS). Key factors to watch are the execution of the $94B commitments, pricing mechanisms, actual data center demand, and industry supply dynamics.

marsbit1h ago

Citi's Interpretation: Why Does Citi Still Give SanDisk a Target Price of $2500 After Earnings Report Despite a Significant Stock Price Drop?

marsbit1h ago

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

Institutional cryptocurrency trading is increasingly shifting towards dark pools and over-the-counter (OTC) desks, with data from sFOX showing such venues accounted for 15% of total monthly volume by June, up from negligible levels in April. In July, 77.7% of institutional capital on sFOX's platform was routed through OTC desks, while only 18.4% went to public exchanges. A key driver is institutions' need to conceal large orders to avoid revealing trading patterns, preventing front-running and minimizing price impact. Firms like Jane Street and Citadel use dark pools and order-splitting across multiple venues to execute trades discreetly. This structural shift mirrors earlier developments in equities and forex markets. As a result, public order books now reflect only a fraction of actual market activity, eroding the once-significant advantage retail traders had in tracking large wallets and exchange flows. The proliferation of prime brokers and aggregation platforms is also rapidly closing simple arbitrage opportunities. The market may evolve toward a brokerage model for retail, similar to traditional stocks. Two scenarios emerge: an optimistic one where retail gains from narrower spreads and better order routing, and a pessimistic one where transparency declines faster than benefits trickle down, leaving smaller investors in the dark. Regardless, traders must adapt by not relying solely on exchange volume, comparing total execution costs, and using limit orders in thin markets. While reduced volatility from hidden large trades may seem positive, it comes at the cost of obscured market signals and institutional intent.

marsbit1h ago

Dark Pools Prevail, Whales Vanish: How Credible Are Public Market Signals?

marsbit1h ago

Trading

Spot
活动图片