July was marked as a taxing month for cryptocurrency security, with cybercriminals securing an eye-watering $247.4 million from various digital platforms. This thief’s banquet exposed the sector’s multifaceted weaknesses, impacting everything from hardware wallets to trading venues.
How Did Coldcard Fail?
The Coldcard hardware wallet breach emerged as the leading heist, severely denting the industry. Galaxy Research documented that over 7,300 Bitcoin wallets were compromised, resulting in thefts exceeding $100 million. If a suspected fourth breach is confirmed, total damages could surge to $130 million, showcasing Coldcard’s vulnerabilities as vaults for BTC fell apart under targeted exploits.
A flaw in the wallet’s recovery feature left Coldcard exposed, emphasizing risks even in offline storage solutions. Cold storage, once considered a safe haven, proved imperfect against internal vulnerabilities.
What Went Wrong for Other Protocols?
Arbitrum was not spared, with two significant breaches within the month. A private-key breach on July 22 led to a $24.15 million loss, while a separate hack into the off-chain pricing system drained $23.75 million from Ostium. The Arbitrum team assured that key bridge infrastructure remained intact despite the double hit.
Meanwhile, Bonzo Lend suffered a $9 million setback as a price manipulation scheme took advantage of a third-party oracle, permitting borrowing far exceeding accepted collateral norms.
Other issues peppered the month including:
- Crypto payments firm Triple-A faced a $9.7 million loss due to a hot-wallet breach.
- Bridge verification bypasses at Verus-Ethereum resulted in $7.53 million disappearing.
- Wanchain was down $6.5 million from a signature-based attack.
- Crypto DAO and Allbridge Core fell prey to attacks totaling nearly $9.85 million.
Complex attacks showed that sector vulnerabilities have diversified. Attacks span across smart contract exploits, hardware weaknesses, bridge loopholes, and liquidity infrastructure manipulations.
Recent events underscored the need for robust security measures as recovery efforts continue. SecondFi, a Cardano-related project, remained in the spotlight due to a large-scale breach estimated at $2.4 to $2.6 million. With substantial cleanup efforts extending into July, the team eventually shuttered its operations, signaling the severe lasting impacts of these cyber attacks.



