$210 Million Lost as Crypto Hacks Exploit Known Weaknesses
Crypto suffered a massive $210.3 million loss to 30 major hacks in July 2026, a 177.2% increase from June's already concerning $75.87 million, according to PeckShieldAlert's monthly tally.
The single largest incident came from Coldcard, whose manufacturer Coinkite disclosed a critical entropy-generation flaw affecting Mk2 and Mk3 firmware, resulting in losses of roughly $70 million.
Three other hacks involved oracles that got fed false information: AFX Trade lost around $24 million through its Arbitrum-based USDC custody bridge; Ostium, an Arbitrum-based perpetuals exchange, lost a similar amount after an attacker gained access to its private key controlling its price oracle signer;
Bonzo Lend, Hedera's largest DeFi lending protocol, lost $9.05 million after an attacker deposited a small amount of SAUCE tokens and submitted a manipulated price update through a third-party Supra oracle contract.
Another notable hack was BonkDAO's loss, which didn't involve broken code but rather an attacker submitting a governance proposal that appeared to reward 'YES voters' but contained a hidden clause transferring 4.43 trillion BONK tokens to an attacker-controlled address.