July 2025 Security Incident Breakdown
Published 7/31/2026, 10:08:09 PM
The $172.7M figure for July 2025 hacks appears to be a specific estimate within a broader range of reported security losses, as other data points suggest hacking incidents for that month totaled approximately $139M to $142M across 17 major attacks [Source: https://medium.com/nefture/139m-gone-the-5-most-devastating-crypto-hacks-of-july-2025-8e3b4f5c6d7a]. While the exact $172.7M figure is contested, the cumulative impact of 2025's security breaches—totaling $3.4 billion stolen—has significantly accelerated hardware wallet audits and shifted the industry toward "adversarial auditing" and continuous firmware verification [Source: https://cecuro.io/blockchain-security-auditing-2026].
July 2025 Security Incident Breakdown
The month was defined by mid-sized exploits rather than a single outlier event. Major incidents included:
| Project | Amount Lost | Exploit Type |
|---|---|---|
| CoinDCX | $44.2M | Insider vulnerability / compromised credentials |
| GMX V1 | $42.0M | Smart contract exploit (partially recovered) |
| BigONE Exchange | $27.0M | Supply chain attack on CI/CD pipeline |
| WOO X | $14.0M | Phishing and device compromise |
Acceleration of Hardware Wallet Audits
The surge in wallet-related losses—estimated at $1.71 billion in the first half of 2025 alone—forced a transition from periodic audits to integrated, closed-loop security systems [Source: https://www.certik.com/resources/report/hack3d-h1-2025].
- Adversarial Auditing: Major manufacturers began auditing competitors to identify systemic risks. Ledger’s security team (Ledger Donjon) discovered a voltage glitching vulnerability in the Trezor Safe 3 in March 2025 and a laser fault injection vulnerability in the Trezor Safe 7’s TROPIC01 chip in January 2026 [Source: https://blog.trezor.io/tropic01-vulnerability-disclosure-june-2026].
- Continuous Verification: Security firms like SlowMist and Hacken reported a shift toward continuous firmware auditing and supply chain security assessments rather than one-off project reviews [Source: https://cecuro.io/blockchain-security-auditing-2026].
- Market Response: Hardware wallet sales grew by 31% year-over-year in 2025, while institutional adoption of cold storage solutions surged by 50% as a direct response to exchange and hot-wallet vulnerabilities [Source: https://www.chainalysis.com/blog/2025-crypto-crime-mid-year-update/].
Current Security Status of Major Hardware Wallets
| Wallet | Recent Security Findings | Reported Risks |
|---|---|---|
| Trezor | Addressed TROPIC01 chip vulnerability (June 2026) involving physical laser attacks. | ⚠ Potential for physical secret extraction via laser fault injection [Source: https://blog.trezor.io/tropic01-vulnerability-disclosure-june-2026]. |
| Ledger | Maintained focus on Secure Element (SE) chips; active in cross-vendor auditing. | ⚠ Targeted by "postal phishing" campaigns in April 2025 and Feb 2026 using leaked customer data [Note: not independently confirmed]. |
| Keystone | Promoted air-gapped QR signing to mitigate remote exploit trends. | ⚠ Security status not independently verified during recent audit cycles. |
Conclusion
While the specific $172.7M figure for July is not universally confirmed, the broader 2025 security crisis has undeniably accelerated hardware wallet audits. The industry has moved toward a "proactive disclosure" culture where manufacturers audit one another, and biometric integration reportedly appeared in 60% of new 2025 models to combat physical and phishing-based threats [Note: not independently confirmed]. Despite these advancements, the discovery of physical side-channel attacks in 2026 highlights that even hardware solutions require ongoing, rigorous scrutiny.