Beosin says Web3 lost about $76.15 million to 29 major security incidents in August

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August

N
News Editor
2026-09-08 10:32:18
Beosin’s security team said Web3 projects and users lost about $76.15 million across 29 major security incidents in August 2026, with contract and network flaws remaining the main source of damage. The report counted 18 incidents tied to contract or network vulnerabilities and two linked to private key leaks, while DeFi protocols and individual users accounted for the biggest losses by value. The largest realized loss came from a personal wallet compromise on Aug. 13, when address 0x13e3....179e lost about $25.6 million in WBTC, cbBTC, LDO, USDS, CRV and other assets after a private key leak. Beosin also highlighted the Tectonic exploit on Cronos, where an attacker manipulated the price of TONIC to borrow against inflated collateral, with roughly $6 million bridged out to Ethereum before Cronos halted block production and later rolled back the chain. The report also examined Harmony’s replay attack and Term Finance’s governance exploit, arguing that Web3 risk is spreading beyond code bugs into governance design, operations and user-side security.

Web3 security incidents caused about $76.15 million in losses in August 2026, with 29 major cases recorded during the month, according to Beosin’s security team. The report said contract vulnerabilities remained the main driver of losses.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 2

Of the total, 18 incidents were tied to contract or network vulnerabilities, while two resulted from private key leaks. Beosin said smart contract security and private key management are still weak points across Web3.

Largest incidents recorded in August

On Aug. 13, personal address 0x13e3....179e lost WBTC, cbBTC, LDO, USDS, CRV and other crypto assets after a private key leak. Beosin put the loss at about $25.6 million, making it the largest realized loss of the month.

On Aug. 30, Tectonic, a lending protocol on Cronos, was hit because of a contract vulnerability, with estimated losses of about $74 million. Cronos then took emergency action, halted the network and rolled back transactions. The attacker still managed to move about $6 million to Ethereum through cross-chain transfers.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 3

Beosin also noted that Harmony saw about 4 billion ONE minted through a flaw. The nominal loss exceeded $4 million, but the forged token state was removed through a rollback, so the amount was not included in the final loss tally.

Which targets and chains took the biggest hit

The victims covered public blockchains, lending protocols, wallet apps, token contracts, bridges and individual users. DeFi projects posted the largest losses by category at $33.09 million. Individual addresses lost about $28.4 million through private key leaks or phishing.

By number of attacks, token contracts ranked first with 10 incidents. DeFi contracts followed with nine.

Ethereum saw the largest losses among chains, at more than $48.58 million across 15 incidents. Beosin said most attacks on DeFi protocols and phishing attacks aimed at whales were still concentrated on Ethereum. BNB Chain ranked second by incident count, though the losses there were smaller because the targets were mainly token contracts. Security incidents also hit Cronos, Base, Harmony, Bitcoin and Solana, showing that attacks are spreading across multiple chains.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 4

Tectonic and Moonwell: collateral prices were manipulated

Beosin treated Tectonic and Moonwell as two representative price manipulation cases. Both are on-chain lending protocols. In each case, the attacker manipulated the price of thinly traded collateral assets, inflated the stated value of the collateral and then borrowed outsized amounts against it.

In the Tectonic attack, the exploiter pushed the price of TONIC, the protocol’s governance token, up by 100x and obtained roughly $74 million in borrowing capacity before taking out assets including USDT. Cronos responded by halting block production across the chain. Before the halt took full effect, the attacker bridged about $6 million to Ethereum. Cronos later carried out a rollback in an effort to recover losses.

Beosin identified the attacker’s profit-taking address on Ethereum as 0xc404160B79BD8905061a1cAecBeCa2EEab3f72DD. As for fund flows, about 2,659 ETH remained at 0xc4041, while 140.1 ETH was transferred to 0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c and then dispersed to several newly created addresses.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 5

Moonwell suffered about $8.7 million in losses after an attacker manipulated the price of the illiquid MAMO token and borrowed cbBTC against it.

Beosin said neither case was rooted in a smart contract coding bug. The issue was that the protocols priced collateral directly from weak spot market liquidity, which led to false collateral valuations. To reduce this risk, the report said protocols can pull data from multiple oracles and add checks for sharp price moves.

Harmony: a replay attack in the sharding system

Harmony is a sharded Layer 1 that runs four shards and transfers assets between them through a receipt-based asynchronous cross-shard system. Under that design, the source shard creates a cryptographic receipt for an outbound transaction, and the destination shard verifies the receipt and its Merkle proof against a signed source block header before recording it. Each receipt is supposed to be used only once.

The flaw in this case sat in a legacy part of Harmony’s sharding system. The chain had been checking whether a cross-shard receipt had already been used by reading two fields, CXMerkleProof.ShardID and BlockNum. Those fields were outside the signed block header, which meant an attacker could alter them without breaking the existing verification flow.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 6

In the attack, the exploiter obtained a cross-shard receipt and modified the ShardID and BlockNum fields so the verification logic treated it as a fresh receipt. The destination shard accepted the altered receipt and recorded it again, while the original shard did not deduct the corresponding assets.

Beosin described the incident as a textbook replay attack. Its recommendation was direct: any field used as a one-time-use marker must be part of the signed header, and validators should read shard ID and block number from an authenticated block header rather than from unauthenticated fields inside the proof structure.

Term Finance: governance captured at low cost

Beosin also reviewed the exploit against Term Finance, a DeFi fixed-rate lending protocol. Each of its vaults is an ERC-4626 vault based on Yearn V3 code. Governance for those vaults is structured as a veto system rather than a standard approval vote. When a curator proposes a parameter change, LP token holders are given a window to object.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 7

The report said the setup had two serious weaknesses:

  • No absolute vote or capital floor. The passage conditions, isSupportThresholdReached() and isMinParticipationReached(), only checked relative ratios and did not require a minimum absolute number of votes.
  • Very low participation. Almost no depositors wrapped their tmvETH vault shares into gtmvETH governance tokens, leaving the total supply of governance tokens extremely small.

That let the attacker mount a governance attack at minimal cost. Beosin broke the process into four steps:

  1. Acquire voting power: the attacker spent about 0.5 ETH to obtain about 0.485 tmvETH and wrapped it 1:1 into 0.485 gtmvETH.
  2. Submit a malicious proposal: when the proposal was created, total governance token supply was only 0.535 gtmvETH, meaning the attacker’s 0.485 gtmvETH represented 90.66% of the total.
  3. Vote and execute: the attacker was the only voter and cast a supportive vote. With no opposition, support cleared the 50% threshold, and the attacker’s voting power also exceeded the minVotingPower threshold calculated from the very low supply.
  4. Withdraw assets: once the proposal passed, the malicious action was executed and WETH was taken from the vault.

Using the same method, the attacker compromised six Term Finance vaults and caused about $8.5 million in losses.

Beosin outlined three controls for on-chain governance risk: set absolute vote or capital thresholds instead of relying only on relative ratios; give timelocks a guardian or a cancellation path so malicious proposals can be stopped during the delay period; and monitor governance participation in real time, with alerts or automated protections when token supply or turnout falls unusually low.

Beosin says Web3 lost about $76.15 million to 29 major security incidents in August 8

How Beosin sees the broader threat picture

Beosin said the deepest security trend in Web3 during 2026 is the systemic expansion of the attack surface. Vulnerabilities are showing up not only in code, but also in day-to-day operations, user interaction flows, on-chain governance and business logic. In that environment, a few audits or a single security tool are not enough to cover operational security, governance design and logic flaws.

The report added that attacks on DeFi contracts and individual users remained frequent. Contract bugs and token approvals can both be abused, so developers and operators should review contract security again and submit core business contracts to repeated audits by multiple parties.

For users, Beosin said they should regularly use block explorers or approval revocation tools to review and cancel unused approvals, while keeping up with common and emerging phishing tactics.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.