The cryptocurrency industry faced another harsh reminder of its vulnerabilities in July 2025, as hackers stole an estimated $142 million across 17 separate incidents. Centralized exchanges, decentralized platforms, and back-end infrastructure all came under attack, with the largest breaches targeting CoinDCX, BigONE, and WOO X.
According to blockchain security firm PeckShield, July’s losses represented a 27% increase from June, which recorded $111 million in thefts, although the figure remains 46% lower year-over-year compared to July 2024, when $266 million were stolen. The pattern underscores a persistent reality: while on-chain defenses and smart contract audits have improved, cybercriminals are increasingly exploiting off-chain weaknesses—the human and operational layers behind the technology.
CoinDCX: The Month’s Most Devastating Breach
The most significant incident occurred on July 18, when Indian exchange CoinDCX suffered a $44 million loss in what CEO Sumit Gupta described as a “sophisticated server breach.”
Investigations later revealed that the attack reached deep into the exchange’s internal server infrastructure, bypassing traditional external defenses. The breach had a human dimension as well: authorities arrested a CoinDCX employee, raising the possibility of insider involvement or at least operational lapses that left the exchange vulnerable to social engineering.
The hack forced CoinDCX to overhaul its access protocols and internal monitoring systems, serving as a stark reminder that exchange security must extend beyond blockchain audits to encompass rigorous operational control.
BigONE and WOO X Highlight Supply Chain and Human Risks
Just two days earlier, on July 16, global crypto exchange BigONE lost $27 million when attackers compromised third-party hot wallet infrastructure. This event highlighted a growing industry concern: the security chain is only as strong as its weakest external link. Even if a platform’s internal servers are well-protected, its reliance on vendors and external service providers can create attack vectors that bypass primary defenses.
Then, on July 24, trading platform WOO X fell victim to a social engineering and phishing attack that resulted in the theft of $14 million. Unlike conventional smart contract exploits, this breach originated from a human vulnerability.
Rob Behnke, chairman of blockchain security firm Halborn, explained that attackers successfully compromised a team member’s device, then pivoted into the development environment. By leveraging the implicit trust in internal systems, the attackers executed multiple malicious transactions over a two-hour window before the platform froze withdrawals.
Funds were stolen across several chains, including Bitcoin (BTC), Ethereum (ETH), BNB, and Arbitrum (ARB). WOO X later restored affected accounts using its treasury reserves, illustrating the increasingly common practice among exchanges to shield users from direct losses in the aftermath of a successful breach.
The Shift Toward Off-Chain Exploitation
July’s wave of hacks reinforces a growing trend in crypto security: the battlefield has shifted from smart contracts to operational infrastructure.
In the early days of decentralized finance, attackers often hunted for poorly written or unaudited smart contracts. Today, as blockchain audits and real-time monitoring have raised the bar, hackers are focusing on the off-chain layer. This includes:
- Internal servers and cloud environments
- API keys and hot wallet management systems
- Employee devices and operational workflows
By exploiting human trust and process weaknesses, attackers can bypass the very security that decentralized ledgers provide. Social engineering and phishing campaigns are now at the core of high-value attacks, allowing criminals to penetrate environments that smart contract audits cannot reach.
Behnke noted that this evolution forces exchanges and DeFi platforms to adopt a zero-trust architecture, implement continuous endpoint monitoring, and train employees regularly to resist sophisticated manipulation.
July in Context: Losses Rising but Less Severe Than 2024
While $142 million in losses is significant, the context matters. Compared to the $266 million stolen in July 2024, the market is showing relative improvement in terms of annualized security outcomes. The largest breach last year—the $230 million WazirX hack—overshadowed the rest of the market.
This year, losses are more distributed across multiple incidents, which may indicate that while systemic collapses are less frequent, persistent smaller-scale attacks are becoming the norm.
The 27% month-over-month increase from June is still cause for concern. Peaks in criminal activity often coincide with periods of rising market liquidity, when exchanges hold higher balances and users engage more actively with trading platforms. The trend also aligns with the launch of new tokens and multi-chain integrations, which expand the attack surface for opportunistic hackers.
Industry Lessons and the Road Ahead
The events of July offer several insights for the crypto industry, though they are best understood in a narrative context rather than a checklist.
First, the incidents demonstrate that exchange security is no longer just about blockchain integrity. The success of attacks on CoinDCX, BigONE, and WOO X shows that the human and operational layers are now primary targets. Whether it is an insider breach, a vendor compromise, or a phishing attack, the enemy increasingly exploits trust rather than code.
Second, the market’s resilience depends on proactive treasury management. In each major incident, platforms restored affected balances using internal reserves. While this approach helps maintain user confidence, it also raises questions about the long-term sustainability of absorbing recurring losses without structural changes to prevent them.
Finally, July serves as a warning and an opportunity. Exchanges and DeFi platforms can no longer rely solely on perimeter defenses. Zero-trust frameworks, social engineering drills, and real-time operational monitoring are essential to match the sophistication of modern attackers. For users and investors, the message is equally clear: vigilance remains a permanent requirement in a sector where innovation and risk evolve in tandem.
This article is provided solely for informational and educational purposes and does not constitute financial or investment advice, a recommendation, or an offer or solicitation to buy or sell any financial instrument or digital asset. See our Financial Disclaimer.
This article was generated with the support of AI and reviewed by the Editorial Team. For more information, see our Terms of Service.


