← Editorial Bitcoin

July's $210 million in crypto hacks reveal pattern of preventable failures

The industry suffered $210.3 million in losses to 30 major hacks in July 2026—a 177% jump from June—with most exploiting known security weaknesses rather than novel attack vectors.

· -8

Cryptocurrency suffered $210.3 million in losses to 30 major hacks during July 2026, representing a 177.2% increase from June's $75.87 million, according to PeckShieldAlert's monthly tally. What stands out is not merely the total but the recurring nature of the vulnerabilities exploited—most attacks targeted security flaws the industry has known about for years.

The largest incident involved Coldcard, whose manufacturer Coinkite disclosed a critical entropy-generation flaw affecting Mk2 and Mk3 firmware. The weakness meant affected seeds relied on predictable inputs rather than genuine hardware randomness. Losses linked to this exploit have climbed to roughly $70 million, making it the third-largest crypto theft of the year to date behind the Drift Protocol exploit and the KelpDAO/LayerZero incident. Users of affected devices must generate entirely new seeds and migrate funds, as firmware patches protect only future key generation and cannot repair already-weakened seeds.

Three of July's ten biggest hacks traced back to the same category of failure: a price oracle that accepted false information and paid out based on it. AFX Trade lost roughly $24 million through its Arbitrum-based USDC custody bridge, with the team confirming the incident was isolated to that specific bridge. Ostium, an Arbitrum-based perpetuals exchange, suffered a similar loss of approximately $24 million when an attacker gained access to the private key controlling its price oracle signer. Using a registered PriceUpKeep Forwarder, the attacker submitted authorized but future-dated price reports that Ostium's contracts accepted as genuine because they carried a valid signature. The attacker opened positions at artificially manipulated low prices and closed them at market rate, repeating the cycle with increasingly larger positions and routing most proceeds through Tornado Cash. Most damning is that Ostium's own post-mortem confirmed the exploited component was a known vulnerability.

How this piece reads Sell tone -8
Site call on Bitcoin Buy score 37.2

These two are not the same thing, and one does not produce the other. The left is how this single article reads, from its tone alone. The right is the site’s own call on the asset, from indicators and analysis. Press tone feeds no score and no signal: on the only corpus this site has measured, daily tone tracked the move that had already happened and showed no measurable link with what followed.

More on Bitcoin All pieces →

Rewritten from the headline, the teaser and the one-line summary the qualification step produced — that is all the material there is, and nothing is added to it. The source link is kept on file so any item can be checked, and is not published here.