July was the second-worst month for crypto theft in 2026, with $247 million drained across hacks. The single biggest line item was the Coldcard hardware-wallet incident: estimated losses there escalated from roughly $70 million to more than $100 million as investigators widened their scope.
Why it matters
Cold storage has long been treated as the gold standard of self-custody, the layer that supposedly immunises holders from exchange blowups and hot-wallet drains. The Coldcard incident punctures that assumption. When thousands of users depend on the same firmware, signing library, or supply chain, a single vendor-level vulnerability becomes an industry-wide event, not a single user's mistake.
The escalation from $70M to $100M-plus is the second-order signal worth watching. Initial loss estimates from a major hack almost always grow as more affected wallets are identified, which means the headline figure may still be moving higher.
Market impact
The month's total sits behind only one other 2026 period for cumulative theft, putting July in the same tier as the year's worst single-month breach. Hardware-wallet vendors will face renewed scrutiny over firmware-attestation, supply-chain audits, and the speed of patched-build rollouts. For users, the read is uncomfortable but clear: diversifying custody across multiple vendors and wallet types is no longer optional hygiene.
Source: [source](http://telegraph.controller.bot/files/8336652911/AgACAgIAAxkBAAJGr2p0k3FhkS-snvqtoFV72UcfwdhhAALYHWsb8nqpS_24ejasr067AQADAgADeQADPQQ)
Frequently asked questions
-
How much was stolen in crypto hacks in July 2026?
Investors lost $247 million to crypto hacks in July 2026, making it the second-worst month for crypto theft so far this year.
-
What was the Coldcard hardware-wallet incident?
The Coldcard incident was the single largest contributor to July's losses. Estimated damages escalated from around $70 million to more than $100 million as investigators widened their scope.
-
Does the Coldcard hack mean cold storage is no longer safe?
The incident showed that cold storage does not eliminate technological risks. A vendor-level vulnerability can put thousands of wallets at risk simultaneously when users depend on the same firmware.
-
Why was July 2026 the second-worst month for crypto theft?
July's $247M in losses ranked as the second-largest monthly total of 2026, driven largely by the Coldcard incident alongside other security breaches across the ecosystem.
-
How can users protect themselves from similar hardware-wallet hacks?
Diversifying custody across multiple hardware-wallet vendors, monitoring firmware updates, and avoiding concentration in a single brand can reduce exposure to vendor-level vulnerabilities.