Crypto security losses hit about $215 million in August as price manipulation became the biggest threat

Crypto security losses hit about $215 million in August as price manipulation became the biggest threat

N
News Editor
2026-09-02 12:41:00
A monthly report from blockchain security firm ZeroShadow Technology said the crypto sector lost about $215 million to security incidents in August 2026, with attack activity staying elevated and risk shifting away from traditional smart contract bugs. The report, based on data compiled by several blockchain security monitoring platforms, put losses tied to hacking attacks and contract flaws at roughly $173.5 million, while phishing accounted for about $41.5 million. More than 16 protocol-related incidents were recorded during the month, pushing August well above July’s $97 million and making it the third-worst month of 2026 by losses so far. The report said the attack mix changed in a visible way. Price manipulation overtook conventional contract exploits as the leading source of damage, led by the roughly $75 million Tectonic incident on Cronos. Governance abuse and upstream dependency flaws also featured prominently, including the $8.5 million Term Finance case and a Cosmos EVM bug that affected six chains and caused $5.7 million in losses. ZeroShadow said the shift shows attackers moving toward governance privilege abuse, oracle and pricing manipulation, and shared component vulnerabilities, rather than relying only on exploitable code in contracts.

The crypto sector lost about $215 million to security incidents in August 2026, according to a monthly report by ZeroShadow Technology that cited statistics from several blockchain security monitoring platforms. The firm said attack frequency stayed high during the month, while price manipulation and governance weaknesses emerged as the main sources of risk.

Crypto security losses hit about $215 million in August as price manipulation became the biggest threat 2

Losses tied to hacking attacks and contract-related flaws totaled about $173.5 million. Phishing attacks accounted for about $41.5 million. The report counted more than 16 protocol-related security incidents in August. Compared with the $97 million recorded in July, total losses rose sharply, making August the third-highest-loss month of 2026 so far.

Attack patterns shifted in August

ZeroShadow said the structure of attacks changed in a notable way during the month. Price manipulation became the biggest threat, with the Tectonic incident alone accounting for about $75 million in losses.

The report also pointed to a cluster of governance exploits and upstream dependency flaws. Term Finance lost $8.5 million in a governance attack, while a Cosmos EVM module vulnerability led to $5.7 million in losses across six chains.

In the firm’s view, the path of attacks is moving away from pure smart contract code exploits and toward non-code vectors such as governance privilege abuse, oracle price manipulation, and vulnerabilities in shared upstream components. That shift, the report said, puts pressure on existing audit and defense frameworks.

Hacking incidents: seven cases highlighted in the report

Tectonic on Cronos lost about $75 million in a price manipulation attack

On Aug. 30, Tectonic, the largest lending protocol on Cronos, was hit by a price manipulation attack that caused roughly $75 million in losses.

According to the report, the attacker pushed the price of TONIC, Tectonic’s governance token, up by about 100x in roughly 20 minutes, then used the inflated token as collateral to borrow out other assets. Cronos halted block production across the chain on an emergency basis. Before the halt took effect, the attacker managed to bridge out only about $6 million to Ethereum, while roughly $68 million remained in related addresses.

Crypto.com’s CEO said the company’s app and exchange were not affected. Tectonic’s total value locked fell from about $121.7 million to about $3 million after the incident.

More Markets on Flow EVM lost about $9.3 million

On Aug. 31, about $9.3 million was drained from More Markets’ lending reserves on Flow EVM.

The attacker used Ankr Staked FLOW, a liquid staking token, together with Aave V3’s E-mode to overborrow about 15.5 million WFLOW from the mFlowWFLOW lending reserve. The report said the incident brought total hacker losses for August to $139.7 million.

Term Finance governance exploit caused about $8.5 million in losses

On Aug. 23, the treasury of DeFi fixed-rate lending protocol Term Finance suffered a governance attack worth about $8.5 million.

After securing majority voting control over the protocol’s governance token, the attacker stole about 2,843 ETH from Meta Vaults, worth about $6.87 million by the report’s estimate, along with $1.68 million in USDC. That represented about 68% of assets held by the liquidity pool. The report said the incident was rooted in a governance authorization flaw rather than a smart contract code bug.

Crypto security losses hit about $215 million in August as price manipulation became the biggest threat 3

The target was the Term Strategy Vaults built on Yearn V3 architecture. Standard Yearn vaults were not affected. Term Labs has shut down all Meta Vaults and revoked DAO governance permissions.

Cosmos EVM module bug hit six chains and caused about $5.7 million in losses

Between Aug. 20 and Aug. 25, attackers exploited an integer underflow vulnerability in the Cosmos EVM module, hitting six blockchain networks and causing about $5.7 million in losses.

The report said attackers underflowed account balances to the maximum value, then reversed the operation and withdrew the inflated balances. MANTRA lost 720.9 million tokens, worth about $3.6 million. TAC lost nearly 3 billion TAC, while KiiChain lost about 148 million KII.

Cosmos Labs released a patch on Aug. 19, but the first attack happened about 20 hours later. KiiChain and others criticized Cosmos Labs for not notifying affected chains in advance.

Moonwell on Base lost about $8.7 million in another price manipulation case

On Aug. 27, lending protocol Moonwell on Base was hit by a price manipulation attack that caused about $8.7 million in losses.

The attacker manipulated the price of low-liquidity token MAMO, inflated the collateral value, and then borrowed beyond the protocol’s intended limits. The report said several security firms confirmed the scale of the loss. Post-incident analysis cited in the report said the attack did not require a smart contract bug because the protocol priced collateral directly from thin spot-market liquidity.

Realio Network lost about $6.2 million after signing key exposure

On Aug. 25, web app realio.fund, operated by RWA blockchain project Realio Network, was hacked, causing about $6.2 million in losses.

The report said the attacker used leaked signing keys stored by the platform rather than exploiting a smart contract flaw. The incident spanned five blockchains: Ethereum, BNB Chain, Algorand, Stellar, and Realio’s native network.

Of the stolen funds, about 113.7 million RIO, or 91.4%, came from reserve vaults across chains, while about 10.7 million RIO, or 3.27%, came from user wallets. Realio suspended platform access and froze customer wallet transfers after the attack. The cross-chain bridges on Algorand and Stellar will remain closed indefinitely.

Because market liquidity was limited, the attacker managed to cash out only about 3.7% of the stolen assets. Most of the funds remained in wallets controlled by the attacker, according to the report.

MAYAChain exploit caused about $1.7 million in losses

On Aug. 18, cross-chain liquidity protocol MAYAChain suffered an attack worth about $1.7 million.

Crypto security losses hit about $215 million in August as price manipulation became the biggest threat 4

The attacker used six linked software vulnerabilities to create fake account balances and stole about 20.83 BTC from protocol pools, worth about $1.34 million by the report’s estimate, along with other assets. The incident forced MAYAChain to halt trading. Settlement token CACAO fell nearly 89%, and total liquidity pool value dropped by about $11 million. MAYAChain suspended network operations on Aug. 19.

Phishing and rug pulls: five cases listed

The report also listed five representative phishing and rug pull incidents from August.

  • On Aug. 13, a victim on Arbitrum with an address beginning 0xa707 signed a phishing email and lost $549,744 in USDC.
  • On Aug. 22, a victim with an address beginning 0x7Ba7 lost about $2 million after copying the wrong address from a poisoned transaction history.

“Trump Digital Gold” GOLD token rug pull

On Aug. 29, a scam group controlled the website realtrumpcoins.com and the account @realtrumpcoins1, then maliciously issued the GOLD token while claiming support from Trump-related parties, the report said.

GoPlus disclosed that the group made about $8.2 million. The token’s market capitalization briefly rose to about $60 million before a rapid selloff sent it down about 99%. On-chain data showed that team-linked addresses at one point controlled about 82.45% of the token supply. Fifteen related wallets sold 224.5 million GOLD and received about $330,000, fueling rug pull concerns.

Tornado Cash expired-domain phishing attack

Between Aug. 18 and Aug. 20, the official Tornado Cash domain, tornado.cash, was re-registered and hijacked after expiring, then used to host a spoofed phishing site. The report put losses from the incident at about $2.3 million.

One Ethereum user accessed the old site through an outdated browser bookmark and lost 1,010 ETH over 12 hours, worth about $2.3 million at the time. The domain was re-registered after the original development team failed to renew it because of U.S. OFAC sanctions. Separate on-chain data also confirmed that another user lost 810 ETH.

Hyperliquid user hit by phishing through a Google ad

On Aug. 13, a Hyperliquid user appears to have entered a fake Hyperliquid website through a Google search advertisement and then lost about $550,000 in USDC to a phishing attack.

On-chain analysis showed the attacker moved the funds in three transactions. The report said the case highlighted the risk of a phishing pattern built on search ads, brand impersonation websites, and wallet approvals.

Three changes the report highlighted in August

ZeroShadow summarized August’s blockchain security landscape around three points: price manipulation became the biggest threat, governance flaws entered a stage of scaled exploitation, and attacks showed stronger signs of planning.

According to the report, price manipulation replaced traditional contract exploits as the main driver of losses. Attackers used low-liquidity tokens as entry points for manipulation and worked around code-audit defenses. At the same time, governance privilege abuse evolved from isolated cases into a broader structural risk, with governance design flaws becoming a direct target.

The report also said upstream dependency bugs exposed a single-point-of-failure risk in ecosystems built on shared modules, because a patch delay in one component could trigger a chain reaction across multiple networks. Phishing tactics changed as well. Expired-domain hijacking emerged as a new attack vector, and fake-token promotion through compromised X accounts continued at scale. The report described pre-positioned attacks and patch front-running as tactics that are now appearing more often.

ZeroShadow’s security recommendations

For individual users

  • Review and revoke wallet approvals regularly, and watch for expired-domain hijacking and phishing links.
  • Use official bookmarks when accessing frequently used protocols instead of relying on search engines or redirects from expired domains.
  • Keep high-value assets in separate wallets to isolate risk.

For project teams

  • Apply tighter governance permission controls, and use higher voting thresholds plus delayed execution for DAO proposals.
  • Use multiple pricing sources for oracle-based valuation to stop low-liquidity tokens from being used in price manipulation attacks.
  • Build security alerting and patch response processes for upstream dependency components.
  • Maintain 24/7 anomaly monitoring and circuit-breaker mechanisms.

For the industry

  • Push for security standards around governance mechanisms.
  • Step up industry-level research on defenses against price manipulation attacks.
  • Set up faster alerting and patch synchronization for upstream dependency vulnerabilities.
  • Expand APT threat intelligence sharing and blacklist database development.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.