August Security Overview: $215M in Losses, Structural Shift in Attack Methods
Data from several blockchain security monitoring platforms shows August 2026 racked up about $215 million in crypto security losses. Hacker attacks and contract vulnerabilities made up $173.5 million, while phishing attacks added $41.5 million. There were more than 16 protocol-related security incidents. That is a sharp jump from July's $97 million, and it puts August as the third-worst loss month of 2026. The way attackers operated changed too. Fast. Price manipulation turned into the biggest danger, led by the single Tectonic incident at $75 million. Governance weaknesses also broke through, with Term Finance losing $8.5 million, while upstream dependency exploits appeared as well, including the Cosmos EVM bug that hit six chains and caused $5.7 million in losses. So the attack path is shifting away from plain smart contract code bugs and toward governance abuse, oracle manipulation, and flaws in upstream dependencies. That puts old-school audits and defenses under real pressure.

Hacker Attacks: 7 Notable Incidents, Price Manipulation and Governance Flaws at Core
Tectonic Protocol Price Manipulation on Cronos
On August 30, an attacker sent TONIC—the governance token of Cronos's biggest lending protocol, Tectonic—up by about 100x in roughly 20 minutes. Then came the real move: those inflated tokens were posted as collateral to borrow other assets. Cronos paused block production. Before that halt kicked in, the attacker was able to bridge only about $6 million to Ethereum, while about $68 million remained in related addresses. The Crypto.com CEO said the app and exchange were unaffected. Tectonic's TVL collapsed from around $121.7 million to about $3 million.
More Markets Flow EVM Liquid Staking Attack
On August 31, More Markets had its lending reserves on Flow EVM drained for about $9.3 million. The attacker used Ankr Staked FLOW tokens together with Aave V3's E-mode, then over-borrowed about 15.5 million WFLOW from the mFlowWFLOW lending pool. That pushed August's total hacker attack losses to $139.7 million.

Term Finance Governance Attack
On August 23, the DeFi fixed-rate lending protocol Term Finance was hit by a governance attack on its vaults. The attacker secured majority voting rights in the governance token, then stole about 2,843 ETH, roughly $6.87 million, plus $1.68 million in USDC from Meta Vaults. That accounted for around 68% of the pool's assets. This was not a smart contract code bug. It came from a flaw in governance authorization. The target was Term Strategy Vaults built on Yearn V3 architecture, while standard Yearn vaults were left untouched. Term Labs shut down all Meta Vaults and revoked DAO governance permissions.
Cosmos EVM Module Exploit Affecting Six Chains
From August 20 to 25, attackers exploited an integer underflow bug in the Cosmos EVM module, hitting six blockchain networks. The method was ugly and effective: account balances were underflowed to maximum values, then the operations were reversed so the inflated balances could be withdrawn. The breakdown is specific. MANTRA lost 720.9 million tokens, about $3.6 million. TAC lost nearly 3 billion TAC. KiiChain lost about 148 million KII. Cosmos Labs released a patch on August 19, but the first attack landed about 20 hours later. KiiChain then criticized Cosmos Labs for failing to notify affected chains ahead of time.

Moonwell Price Manipulation Attack
On August 27, the Base lending protocol Moonwell was hit through price manipulation, losing about $8.7 million. The attacker pushed up the price of the illiquid MAMO token, used that to overvalue collateral, and borrowed excess funds. Several security firms confirmed the loss. After the fact, analysis showed something uncomfortable: no smart contract vulnerability was needed. The protocol was valuing collateral straight from thin spot liquidity.
Realio Network Private Key Leak
On August 25, the RWA blockchain project Realio Network saw its web application realio.fund hacked, with losses near $6.2 million. The attacker used a leaked signing key stored on the platform. Not a smart contract bug. The breach stretched across five blockchains: Ethereum, BNB Chain, Algorand, Stellar, and Realio's native network. The stolen funds included about 113.7 million RIO, or 91.4%, from reserve vaults across chains, plus about 10.7 million RIO, or 3.27%, from user wallets. Realio paused platform access and froze customer wallet transfers. Cross-chain bridges to Algorand and Stellar were shut indefinitely. Because market liquidity was thin, the hacker managed to cash out only about 3.7% of the stolen assets, with most of the funds still sitting in attacker-controlled wallets.

MAYAChain Multi-Vulnerability Exploit
On August 18, the cross-chain liquidity protocol MAYAChain was attacked through six linked software bugs that created fake account balances. The result: about 20.83 BTC, roughly $1.34 million, and other assets were drained, for a total near $1.7 million. Trading had to be halted. CACAO, the settlement token, plunged nearly 89%, and total liquidity pool value fell by about $11 million. MAYAChain paused network operations on August 19.
Rug Pulls and Phishing: 5 Notable Incidents, Evolving Tactics
On August 13, a victim whose address starts with 0xa707 signed a phishing email on Arbitrum and lost $549,744 in USDC. Then on August 22, a victim at address 0x7Ba7 copied the wrong address from a contaminated transaction record and lost about $2 million.

The "Trump Digital Gold" GOLD token rug pull went like this: on August 29, a scam ring took over realtrumpcoins.com and the @realtrumpcoins1 account, then pushed out GOLD tokens while claiming Trump endorsement. The token's market cap briefly jumped to about $60 million before crashing around 99%. On-chain data showed team addresses held about 82.45% of total supply, and 15 linked wallets sold 224.5 million GOLD for about $330,000, triggering rug pull accusations. The group's profit is estimated at about $8.2 million.
Tornado Cash expired domain phishing was another ugly one. Between August 18 and 20, the privacy mixer's official domain, tornado.cash, expired and was taken over, and hackers put up a fake phishing site. An Ethereum user who opened the old site through an outdated browser bookmark lost 1,010 ETH, about $2.3 million, in 12 hours. The domain was picked up by someone else after the original team did not renew it because of US OFAC sanctions. Another user reportedly lost 810 ETH.

A Hyperliquid user was also caught by Google ad phishing. On August 13, that user allegedly landed on a fake Hyperliquid site through a Google search ad and lost about $550,000 in USDC in a phishing attack. On-chain analysis found the attacker moved the funds in three transactions. It is a blunt reminder of the danger created when search ads, brand impersonation, and wallet approvals are mixed together.
Summary and Recommendations: Structural Shift Requires Upgraded Defenses
August 2026 exposed three big changes in blockchain security: price manipulation became the top threat, governance weaknesses started getting exploited at scale, and attacks looked increasingly "premeditated." The structure of these attacks changed. Price manipulation overtook the usual contract bug as the main source of losses, using illiquid tokens to get around code audits. Governance abuse also moved beyond isolated cases and started looking like a systemic risk, with design flaws in governance mechanisms turning into fresh targets. Upstream dependency exploits showed how a delayed patch can set off a chain reaction across several chains at once, exposing the "single point of failure" danger in shared modules. Phishing changed too. Expired domain hijacking opened a new entry route, while X account hijacks used for fake token promotion kept spreading. And attackers themselves are leveling up: preplanned setups and patch-race tactics now look a lot like the new normal.

ZeroTech Security's advice is split three ways. For individuals: regularly review and revoke wallet approvals, stay alert to expired domain hijacking and phishing links, use official bookmarks when accessing protocols, avoid redirects from search engines or expired domains, and keep high-value assets in separate wallets. For projects: tightly restrict governance permissions, raise voting thresholds and add time-locks for DAO proposals, use multi-source oracle validation to reduce price manipulation through illiquid tokens, build upstream dependency security alerts and patch-response procedures, and maintain 24/7 anomaly monitoring with circuit breakers. For the industry: push security standards for governance mechanisms, step up defense research against price manipulation, create fast alerting and patch synchronization for upstream dependency vulnerabilities, and improve APT threat intelligence sharing along with blacklist database building.

