Crypto lost $247 million to theft in July 2026, making it the second-worst month for stolen funds so far this year, according to data highlighted by Cryptorank. The bulk of that damage traces back to a single point of failure: a hardware wallet that was supposed to make self-custody safer. The incident has reignited a familiar but uncomfortable conversation about crypto security breaches and just how many things can go wrong before a private key ever gets stolen.
Summary
Key takeaways
- Roughly $247 million was stolen from crypto users in July 2026, the second-worst month on record for theft this year.
- A flaw in Coldcard hardware wallets exposed about $116 million (1,816 BTC) across more than 5,200 addresses, according to TRM Labs.
- North Korean-linked group UNC1069 has been using Google’s Gemini AI for reconnaissance, phishing content, and deepfake impersonation of crypto figures.
- Tokenized US Treasuries have grown to a $15.3 billion supply, led by USYC, BUIDL, and USDY.
- DeFi total value locked has dropped about 54% from its recent peak while real-world asset market capitalization has surged more than 550% since 2025.
July 2026 Crypto Thefts Highlight Infrastructure Vulnerabilities
The July losses show that securing a private key is no longer the whole game. A single flaw buried deep in wallet firmware was enough to put tens of thousands of dollars’ worth of Bitcoin at risk for thousands of separate users, all at once, without anyone touching their devices.
Coldcard Hardware Wallet Exploit Drives Major Losses
The single largest contributor to July’s theft total was an exploit tied to Coldcard, a Bitcoin-only hardware wallet made by Canadian manufacturer Coinkite. According to blockchain intelligence firm TRM Labs, attackers drained approximately 1,816 BTC, worth about $116 million, from more than 5,200 addresses in four suspected waves that began on July 30.
The root cause wasn’t a stolen device or a leaked PIN. Coinkite’s own security advisory traced the problem to a firmware integration error that caused affected units to rely on a predictable software random-number generator instead of the hardware-based source they were designed to use when creating wallet seeds. The flaw affected firmware versions 4.0.1 through 4.1.9 on Coldcard Mk2 and Mk3 devices, a window that stretched back to March 2021 — meaning the vulnerability sat undetected for more than five years before Coinkite disclosed it.
The technical damage was severe. Seeds generated on vulnerable Mk2 and Mk3 devices carried only about 40 bits of effective entropy instead of the promised 128 bits, according to Coinkite’s advisory. Vulnerable Mk4, Mk5, and Q devices fared somewhat better at roughly 72 bits, still far short of the intended standard. A properly randomized 128-bit seed is effectively unbreakable by brute force; at 40 bits, the field of possibilities shrinks to around one trillion combinations — searchable by specialized computing systems once attackers understand how the seed-generation process worked.
Bobby Gray, founder of TEXITcoin, told crypto.news that the incident reflects a failure of trust rather than a failure of Bitcoin itself. “Coldcard sat on a broken seed generator for five years, and it still cost people $116 million,” Gray said. He added that “some of these wallets were generating seeds with as little as 40 bits of entropy instead of the 128 they promised.”
Notably, not every Coldcard user was exposed. Gray pointed out that people who added their own independent dice-roll entropy during setup were untouched by the reported attacks. “The people who bothered adding their own dice rolls for extra entropy walked away untouched, while the people who just trusted the device to handle it got wiped out,” he said. Coinkite’s advisory backs this up: users who entered at least 50 fair, private, independent dice rolls are not considered at risk from the flaw alone, with 50 to 98 rolls adding at least 128 bits of entropy and 99 or more adding roughly 256 bits. Coinkite has since released patched firmware, but anyone with a vulnerable seed created before the fix needs a complete wallet migration — the flaw lived at the moment of seed creation, not in the device’s ongoing operation.
Complexity of Crypto Transaction Security
Why does this matter beyond one hardware brand? Because it exposes how many layers now sit between a user and a secure transaction. A modern crypto transfer can depend on a hardware wallet, its firmware, wallet software, a frontend interface, smart contracts, bridges, oracles, RPC providers, and third-party code libraries. Each additional link is another potential point of compromise, which means protecting a private key alone no longer guarantees the safety of the entire transaction chain.
The Coldcard case illustrates this dynamic clearly: a flaw at the hardware-wallet level was able to compromise thousands of otherwise unrelated users simultaneously, even though none of them made an individual mistake. That’s the uncomfortable lesson behind July’s numbers — infrastructure built specifically to improve security can itself become a systemic point of failure.
AI-Enabled Attacks Escalate Existing Crypto Threats
Attackers are increasingly turning to artificial intelligence not to invent new attack types, but to run old ones faster, at greater scale, and more convincingly. That shift is changing the economics of social engineering across the crypto industry.
UNC1069’s Use of AI in Phishing and Deepfake Attacks
One of the clearest examples involves UNC1069, a North Korean-linked hacking group that targets the cryptocurrency sector. The group has reportedly used Google’s Gemini AI model for crypto-focused reconnaissance, researching wallet data, generating social-engineering material, and attempting to develop code aimed at stealing digital assets. UNC1069 has also deployed deepfake images and videos impersonating known figures in the crypto industry to trick targets into installing a malicious Zoom SDK.
AI’s Role in Accelerating Traditional Attack Vectors
AI does not necessarily create entirely new categories of vulnerability. What it does is make phishing, reconnaissance, impersonation, and malware development significantly easier to scale — turning what used to require a skilled team into something a smaller group can automate. That adds another layer of risk on top of an already complex security stack, at exactly the moment when hardware-level flaws like Coldcard’s are showing how much damage a single weak link can cause.
This is one of the two moments in the current cycle where the stakes become clear: infrastructure vulnerabilities and AI-accelerated social engineering are converging, and neither problem cancels the other out. A patched firmware bug doesn’t protect against a convincing deepfake video, and better phishing awareness doesn’t fix a broken random-number generator.
Shifting Dynamics in Crypto Liquidity and Asset Tokenization
While security incidents dominate headlines, a quieter structural shift is underway in where on-chain capital actually sits. Traditional DeFi liquidity is shrinking just as tokenized real-world assets expand rapidly, and the two trends appear to be connected.
Growth of Tokenized US Treasuries as On-Chain Liquidity
The supply of tokenized US Treasuries has climbed to $15.3 billion, led by three key tokens: USYC, BUIDL, and USDY. Their appeal rests on a fairly simple pitch — investors get to keep their capital liquid on-chain while gaining exposure to short-term US government debt, rather than parking funds idle in stablecoins that generate no yield of their own.
That proposition becomes especially attractive when crypto-native yields lose their edge. As more capital flows into these instruments, tokenized Treasuries are increasingly positioned to become a base layer for collateral and liquidity across on-chain finance, rather than just another niche category of real-world assets.
Decline of DeFi TVL and Rising Real-World Asset Market
The numbers behind this shift are stark. DeFi total value locked has fallen roughly 54% from its recent peak, while the market capitalization of real-world assets has risen more than 550% since 2025. Part of the DeFi decline comes down to falling prices for ETH and other tokens that make up a large share of total value locked. But weaker activity across DeFi has also compressed yields on lending protocols and similar products, pushing capital toward lower-risk alternatives offering comparable returns, such as short-term US Treasuries brought on-chain.
The second driver is simply the pace of tokenization itself, fueled by new instruments launching and the networks that issue them expanding their reach. Why this matters for the broader market: the deeper tokenized assets become embedded in lending, collateral, and liquidity markets, the more DeFi protocols will find themselves competing not just with rival crypto platforms, but with traditional-finance yields that have effectively moved on-chain.
FAQ
What caused the large crypto thefts in July 2026?
The Coldcard hardware wallet exploit was the largest contributor, exposing vulnerabilities even in infrastructure specifically built to strengthen self-custody security.
How does AI impact crypto security attacks?
AI accelerates and scales traditional attack methods like phishing and deepfake impersonation, but it does not appear to create entirely new categories of vulnerability.
What is driving the growth of tokenized US Treasuries?
Their appeal comes from offering on-chain liquidity combined with exposure to short-term US government debt, which becomes especially attractive when crypto-native yields are less competitive.
Why is DeFi TVL declining while real-world assets grow?
Falling asset prices and weaker DeFi yields are pushing capital toward lower-risk tokenized products like US Treasuries, while the real-world asset market keeps expanding through new instruments and broader network adoption.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

