August Cryptocurrency Security Incident Report: Total Loss of $215 Million, Price Manipulation and Governance Vulnerabilities as Major Attack Methods
Zero Time Technology's monthly security incident highlights are here! According to statistics from multiple blockchain security monitoring platforms, the security situation in the cryptocurrency sector in August 2026 showed characteristics of "high attack frequency, with price manipulation and governance vulnerabilities as the main risks." The total loss due to security incidents in the month was approximately $215 million, with losses related to hacker attacks and contract vulnerabilities amounting to about $173.5 million, and phishing attacks causing losses of approximately $41.5 million. A total of over 16 security incidents related to protocols occurred, with the total loss in August significantly increasing from $97 million in July, making August the third highest month for losses in 2026 so far.
The methods of attack showed significant changes: price manipulation attacks became the biggest threat of the month, with a single Tectonic incident causing approximately $75 million in losses; governance vulnerability attacks (Term Finance lost $8.5 million), upstream dependency component vulnerabilities (Cosmos EVM vulnerabilities caused losses of $5.7 million across six chains), and other multi-dimensional attacks occurred concurrently. The attack paths are accelerating the shift from smart contract code vulnerabilities to non-code level attack methods such as governance authority abuse, oracle price manipulation, and upstream dependency component vulnerabilities, posing new challenges to traditional security auditing and defense systems.
Hacker Attacks
Typical security incidents 7
• Price Manipulation Attack on Tectonic Protocol on Cronos Chain
Date: August 30
Loss Amount: Approximately $75 million
Incident Details: The attacker inflated the price of the governance token TONIC of the largest lending protocol Tectonic on the Cronos chain by about 100 times within approximately 20 minutes, then borrowed other assets using the overvalued token as collateral. The Cronos network urgently paused the entire chain's block production, and the attacker transferred approximately $6 million to Ethereum before the chain was halted, with about $68 million remaining in the related address. Crypto.com CEO confirmed that its application and exchange were not affected. Tectonic's TVL plummeted from approximately $121.7 million to about $3 million.
• More Markets Flow EVM Liquidity Staking Attack
Date: August 31
Loss Amount: Approximately $9.3 million
Incident Details: More Markets' lending reserves on Flow EVM were drained of approximately $9.3 million. The attacker utilized Ankr Staked FLOW liquidity staking tokens, combined with Aave V3's E-mode (efficiency mode) feature, to over-borrow approximately 15.5 million WFLOW tokens from the mFlowWFLOW lending reserves. This attack increased the total losses from cryptocurrency hacker attacks in August to $139.7 million.
• Governance Authority Attack on Term Finance
Date: August 23
Loss Amount: Approximately $8.5 million
Incident Details: The DeFi fixed-rate lending protocol Term Finance's treasury suffered a governance attack, where the attacker gained majority voting rights of its governance tokens and stole approximately 2,843 ETH (about $6.87 million) and $1.68 million USDC from Meta Vaults, accounting for about 68% of the assets held in the liquidity pool. This incident stemmed from governance authorization flaws rather than smart contract code vulnerabilities. The attack targeted the Term Strategy Vaults based on the Yearn V3 architecture, while standard Yearn vaults were unaffected. Term Labs has closed all Meta Vaults and revoked DAO governance rights.
• Cosmos EVM Module Vulnerability Chain Attack
Date: August 20-25
Loss Amount: Approximately $5.7 million
Incident Details: An integer underflow vulnerability in the Cosmos EVM module was exploited by attackers, leading to attacks on six blockchain networks between August 20 and 25. Attackers underflowed account balances to the maximum value and then reversed operations to transfer inflated balances out. In terms of specific losses, MANTRA lost 720.9 million tokens (about $3.6 million), TAC lost nearly 3 billion TAC, and KiiChain lost about 148 million KII. Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later, with KiiChain and others criticizing Cosmos Labs for not notifying the affected chains in advance.
• Price Manipulation Attack on Moonwell Protocol
Date: August 27
Loss Amount: Approximately $8.7 million
Incident Details: The lending protocol Moonwell on the Base chain suffered a price manipulation attack, where the attacker manipulated the price of the illiquid MAMO token to over-borrow against the inflated collateral value. Multiple security agencies confirmed the scale of this loss. Several post-incident analysis reports indicated that this attack could be executed without smart contract vulnerabilities------the protocol directly priced collateral from weak spot liquidity.
• Signature Key Leak Attack on Realio Network
Date: August 25
Loss Amount: Approximately $6.2 million
Incident Details: The RWA blockchain project Realio Network's web application realio.fund was attacked by hackers. The attackers exploited the leak of signature keys stored on the platform to carry out the attack, rather than smart contract vulnerabilities. The attack spanned five blockchains: Ethereum, BNB Chain, Algorand, Stellar, and Realio's native network. Approximately 113.7 million RIO (91.4%) of the stolen funds came from reserves across chains, while about 10.7 million RIO (3.27%) came from user wallets. After the attack, Realio has suspended platform access and frozen customer wallet fund transfers, and the cross-chain bridges for Algorand and Stellar will be closed indefinitely. Due to insufficient market liquidity, the hacker only liquidated about 3.7% of the stolen assets, with most remaining in the attacker's controlled wallet.
• MAYAChain Chain Vulnerability Attack
Date: August 18
Loss Amount: Approximately $1.7 million
Incident Details: The cross-chain liquidity protocol MAYAChain was attacked, with the attacker exploiting six interconnected software vulnerabilities to create false account balances, stealing approximately 20.83 BTC (about $1.34 million) and other assets from the protocol's fund pool. The incident led to the suspension of trading on the MAYAChain network, with the settlement token CACAO plummeting nearly 89%, and the total value of the liquidity pool decreasing by about $11 million. MAYAChain suspended network operations on August 19.
Rug Pull / Phishing Scams
Typical security incidents 5
(1) On August 13, a victim with an address starting with 0xa707 signed a phishing email on Arbitrum, resulting in a loss of $549,744 in USDC.
(2) On August 22, a victim with an address starting with 0x7Ba7 lost approximately $2 million due to copying an incorrect address from contaminated transfer records.
(3) "Trump Digital Gold" GOLD Token Rug Pull
Loss Amount: Approximately $8.2 million (profits disclosed by GoPlus)
Incident Nature: On August 29, a scam group controlled the website realtrumpcoins.com and the @realtrumpcoins1 account, maliciously issuing GOLD tokens and claiming support from Trump. The token's market value once surged to about $60 million, then was quickly sold off, plummeting by about 99%. On-chain data shows that the related team address once controlled about 82.45% of the token supply, with 15 associated wallets selling 224.5 million GOLD, earning about $330,000, raising suspicions of a rug pull.
(4) Tornado Cash Expired Domain Phishing Attack
Loss Amount: Approximately $2.3 million
Incident Nature: From August 18 to 20, the official domain of the well-known privacy mixing tool Tornado Cash, tornado.cash, was hijacked by hackers due to expiration and failure to renew. The hackers set up a high-fidelity phishing page to carry out the scam. An Ethereum user lost 1,010 ETH, worth about $2.3 million, in batches within 12 hours after accessing the old version of the website through an outdated browser bookmark. The domain was registered by others after the original development team failed to renew it due to US OFAC sanctions. On-chain data also confirmed that another user lost 810 ETH.
(5) Hyperliquid User Phishing Attack via Google Ads
Loss Amount: Approximately $550,000
Incident Nature: On August 13, a Hyperliquid user was suspected of entering a counterfeit Hyperliquid website through a Google search ad, subsequently falling victim to a phishing attack, with approximately $550,000 USDC transferred to the attacker's controlled wallet. On-chain analysis showed that the attacker completed the fund transfer through three transactions. This incident also exposed the risks of the phishing attack model combining search engine ads, brand impersonation websites, and wallet authorizations.
Summary
The blockchain security situation in August 2026 showed three significant changes: price manipulation became the biggest threat, governance vulnerabilities entered a phase of large-scale exploitation, and attacks exhibited "premeditated" characteristics.
This month's attack methods underwent structural changes. Price manipulation attacks replaced traditional contract vulnerabilities as the main source of losses, with attackers using illiquid tokens as entry points for price manipulation, bypassing code audit defenses. Governance authority abuse has evolved from sporadic incidents to systemic risks, with flaws in governance mechanism design becoming new targets for attackers. Upstream dependency component vulnerabilities leading to delays in single patches have triggered chain reactions across multiple chains, exposing the "single point of failure" risk in shared module ecosystems.
Phishing scams have shown new evolutionary directions: expired domain hijacking has become a new attack entry point, and X account intrusions promoting fake tokens continue to operate on a large scale. Attackers' methodologies are also upgrading------premeditated layouts and patch race tactics have become the new norm.
The Zero Time Technology security team recommends:
• Individuals: Regularly check and revoke wallet authorizations, be wary of expired domain hijacking and phishing links; use official bookmarks to access commonly used protocols, avoiding redirects through search engines or expired domains; use independent wallets to isolate risks for high-value assets.
• Project Parties: Strictly control governance authority, set higher voting thresholds and delayed execution mechanisms for DAO governance proposals; implement multi-source verification for oracle pricing to prevent illiquid tokens from being used for price manipulation; establish security early warning and patch response mechanisms for upstream dependency components; establish 7×24-hour abnormal monitoring and circuit breaker mechanisms.
• Industry: Promote the establishment of security standards for governance mechanisms; strengthen industry-level defense research against price manipulation attacks; establish rapid warning and patch synchronization mechanisms for upstream dependency vulnerabilities; enhance APT threat intelligence sharing and blacklist database construction.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Tracking Cryptocurrency May Be Included in Exporters' Currency Revenue Control

Backpack Adds Micron, SanDisk Shares as Margin Collateral

What is Hedera Hashgraph and how does HBAR work?

Agentic Payment Research Report: From Payment Pathways to Ecological Landscape

What is Chainlink and how does the LINK oracle network work?

Wyoming Adopts Chainlink for FRNT On-Chain Reserve Verification

Crypto Will Eventually Merge with AI Finance

From Glamsterdam to Hegotá: What Will Ethereum Address in Its Next Phase After Scaling?

The Similarities and Differences of Meme from a Long-Cycle Perspective

TAC Report Reveals Cosmos EVM Vulnerability Attackers Cashed Out Approximately $1 Million

Cronos' Single-Player Philosophy: Theft Is No Big Deal, Just Roll Back

China's Blockchain BaaS Market Expected to Reach 2.07 Billion Yuan by 2025, Ant Group Leads with 32.4% Market Share

AI Networking (Broadcom/AVGO) and Space Tech (RKLB): The Impact of TradFi Megatrends on the Cryptocurrency Market

SNDK Stock Trading Rewards: Share $100K on WEEX

When AI Agents Gain On-Chain Execution Authority: Who Verifies the Information They See and the Commands They Issue?

How Much of the $1.5 Billion Can Be Recovered? The Realistic Boundaries and Industry Insights of Bybit's Lawsuit Against North Korea

Breaking the 'Blame-Shifting Narrative' and Secret Governance: A Structural Bloodletting in Tokenomics and the Governance Challenge Behind Sun Yuchen's Lawsuit Against WLFI

MultiversX to pause transactions for 24 minutes during Supernova upgrade

Does YZi Labs Have Dreams?

CryptoQuant: Trend Reversal Signal After 8 Months... Is the Bear Market Over?

Bitcoin leads Ethereum and Solana in decentralization, ARK finds

Korean Won Stablecoin May Reduce Capital Outflow Concerns

Bitcoin: What convinces Americans to buy BTC?

Can On-Chain Rollbacks Recover Stolen Assets?

G20 Evaluates Contribution of Digital Assets to Economic Growth and Improves Regulatory Framework

Important News from Last Night and This Morning (September 1 - September 2)

Tuven Chain: A New Solution to the Gas Fee Payment Dilemma and Analysis of Related Security Risks

Belgian Police Target Crypto Wallets Linked To Offshore Piracy

How recovery of 61 BTC unlocked a potential $432M treasure hunt for early Bitcoin users











