July 2026 saw the cryptocurrency sector lose $210.3 million across 30 recorded hacks, a 177% surge from June’s $75.87 million. The damage was dominated by four surgical exploits, none of which relied on finding flaws in smart contract code. Instead, attackers targeted hardware wallet firmware, developer machines, oracle signing keys, and governance voting mechanisms—a shift that security firms have been tracking all year.
The largest single loss, estimated at $70 million, came from a COLDCARD hardware wallet firmware flaw. The device’s true random number generator was bypassed, reducing seed entropy on affected Mk3 devices from 128 bits to roughly 40. That made keys reconstructible by brute force. Within the first ten minutes of the July 30–31 sweep, the attacker pulled about $30 million by targeting the highest-value wallets.
AFX Trade, a perpetuals protocol on Arbitrum, lost $24.15 million after a developer was tricked by a fake recruiter into cloning a malicious repository. The resulting payload compromised the developer’s machine and yielded enough validator signatures to authorize a bridge withdrawal that the smart contract saw as legitimate. The protocol later offered the attacker a 30% bounty to return the remaining funds.
Ostium suffered a $23.75 million loss through its price oracle. An attacker with a stolen signing key wrote a false Bitcoin price of $5,000 into the contract, opened massively leveraged positions, and then settled them at the real market price near $60,000. The oracle infrastructure had been excluded from the project’s bug bounty scope, leaving it unmonitored.
The fourth headline exploit hollowed out the treasury of BonkDAO on Solana. An individual spent roughly $4 million to acquire enough BONK tokens to control nearly all votes during a period of low participation. A governance proposal to transfer $20 million in treasury tokens to the attacker’s wallet then passed cleanly—every step valid under the DAO’s own rules. No smart contract was breached; the vulnerability lay entirely in low turnout and cheap vote buying.
These incidents reinforce a broader trend. Security firm CertiK reported that wallet compromises cost $444.5 million in the first half of 2026, overtaking smart contract exploits as the most expensive attack category. The BONK and Ostium cases show that governance frameworks and operational infrastructure—private keys, oracles, and developer workspaces—are now the leading attack surfaces.