The number, and its error bars
Several trackers published July totals in the first days of August, and they do not agree. Figures circulating include roughly $210 million across 30 incidents, about $242 million on a broader inclusion basis, and around $110 million where a tracker counted only DeFi protocol losses and treated the hardware wallet theft separately.
Conisec does not average these into a single number. Each tally is a reported figure produced under a stated methodology, and the spread is the finding: what counts as an incident is not standardised.
What actually drove it
Where the trackers do agree is on composition. The month was dominated not by novel smart-contract exploits but by key and wallet infrastructure failures — chiefly the Coldcard entropy disclosure, which alone accounted for a larger loss than every DeFi exploit in the month combined on most counts.
Reported breakdowns put wallets and key infrastructure at roughly 54% of losses, DeFi protocol exploits at about 25%, and bridges at about 21%.
Why that split is the story
This mirrors the pattern in our own Incident Tracker, where key compromise is the single largest attack class across 25 historical records — larger than reentrancy, oracle manipulation and business-logic flaws put together.
The industry’s security spending and public attention remain weighted toward smart contract auditing. The losses are not.
Sources
- QuillAudits, July 2026 Crypto Hacks: $242M+ Lost as a Hardware Wallet Bug Outweighed Every DeFi Exploit (1 Aug 2026)
- MetaMask, Crypto Security Report: July 2026 (1 Aug 2026)
Not advice. Conisec reports for information only. Nothing in this article is financial, legal, tax or security advice. Verify against the primary sources linked above before acting on anything.