HomeArticles › $215 Million Gone in August, and One Attack Accounted for More Than Half of It

$215 Million Gone in August, and One Attack Accounted for More Than Half of It

· 4 September 2026 · 7 min read · Security
Breakdown chart of $215 million in August 2026 crypto losses by attack type, led by price manipulation

Crypto hacks August 2026 totals are in: $215 million of confirmed losses, with DeFi absorbing $144.6 million and a single price-manipulation attack accounting for $120.4 million.

Crypto hacks in August 2026: the breakdown by attack type

Attack typeLosses
Price manipulation$131.6m
Phishing$41.5m
Code vulnerabilities$20.6m
Wallet compromise$11.8m
Governance$8.5m

The ordering here is the story. For most of DeFi's history, the top line was code vulnerabilities — reentrancy bugs, flawed math, unchecked external calls. In August 2026 code bugs came fourth, at less than a sixth of the price manipulation figure.

That shift reflects a decade of audits, formal verification and bug bounties actually working. Contract code is meaningfully harder to break than it was in 2021. What has not been fixed is the layer above the code: the assumption that a token's on-chain price is a reliable input.

Tectonic: a hundredfold in twenty minutes

On 30 August an attacker inflated the price of TONIC, the token behind the Tectonic lending protocol on Cronos, roughly 100 times its prior level inside twenty minutes. With the token now nominally worth a hundred times more, they borrowed against it as collateral and walked away with what the protocol's books recorded as legitimate loans.

The impact figure was $120.4 million. Two details kept it from being much worse. The Cronos network halted, which stopped the attack in progress — a decision that will be argued about for years, because a chain that can be halted is not a chain that is credibly neutral, and a chain that cannot be halted loses $120 million. And only about $6 million had crossed the bridge to Ethereum before the pause, which is why the recovery figure for the month is as high as it is.

The mechanism is not novel. It is the same one used against Mango Markets in 2022 and against a long list of smaller protocols since. Take a token with thin liquidity, buy it aggressively enough to move the reported price, use the inflated price as collateral, borrow real assets, leave. The contract behaves exactly as written throughout. Nothing is hacked in the conventional sense.

The same attack, twice more, smaller

Moonwell on Base, 27 August, $8.7 million. Price manipulation of MAMO, an illiquid token accepted as collateral, enabled unauthorised borrowing. Same pattern, different chain, one-fourteenth the size.

Term Finance, 23 August, $8.5 million. A governance exploit, distinct in method. The attacker hijacked DAO voting mechanisms instead of manipulating a price. This is the attack class that most people assume is theoretical, and it produced a real eight-figure loss.

Coinsbuy, $7.9 million and Fogo, $3.9 million round out the named incidents.

Why illiquid collateral keeps doing this

The vulnerability is structural and it is not hard to describe.

A lending protocol needs to know what your collateral is worth. It asks an oracle. The oracle reports a price derived, ultimately, from trading on some venue. If that venue's order book for the token is thin, then the cost of moving the reported price is low relative to the amount that can then be borrowed against it.

The economics are brutal. If moving a token's price a hundredfold costs an attacker $2 million in buy pressure and unlocks $120 million of borrowing capacity, the attack has a sixtyfold return and requires no bug at all.

The fixes are all known and all unpopular: cap the total borrowable against any single illiquid asset, use time-weighted average prices over windows long enough to make manipulation expensive, require multiple independent oracle sources, or simply refuse to accept low-liquidity governance tokens as collateral. Every one of these reduces the protocol's headline TVL and makes its own token less useful. That is why they keep not getting implemented until after the incident.

Phishing is quietly the more important number

$41.5 million to phishing, plus $11.8 million to wallet compromise, is $53.3 million taken from individuals rather than protocols.

Nobody writes post-mortems about phishing. There is no clever exploit to diagram, no governance forum thread, no protocol treasury vote on reimbursement. There is a person who signed a transaction they should not have signed, and money that is gone with no recourse.

For an individual holder, this category is far more relevant than the Tectonic headline. You will almost certainly never be exposed to a price manipulation attack on a lending protocol. You are exposed to a malicious signature request every time you connect a wallet to a site.

The practical defences have not changed in five years and are still not widely followed: use a hardware wallet for anything you would miss, read what you are signing instead of the label on the button, revoke old approvals periodically, and treat any unexpected message about your funds as hostile.

The year so far

CertiK's H1 2026 report documented $1.32 billion in losses across 344 incidents. The comparison to 2025 is deceptive at the headline level: 2025's total was inflated by the single $1.45 billion Bybit theft. Strip that outlier out and the underlying rate of loss in 2026 is running higher than 2025's, not lower.

That is an uncomfortable finding for an industry that has spent heavily on security. It is also consistent with the shift in attack type. Money spent on audits buys protection against code bugs. It buys nothing against an attacker who uses the protocol exactly as designed.

What would actually change the numbers

Three things, none of which is a security product.

Collateral discipline. Hard caps on borrowing against thin-liquidity assets would have prevented Tectonic, Moonwell and a long list of prior incidents. It is a parameter change, not a technology problem.

Oracle design that assumes hostility. Time-weighted pricing and multi-source aggregation make manipulation expensive, not impossible. Expensive is enough.

Wallet interfaces that explain transactions. The single largest source of individual losses is people approving things they do not understand. That is an interface failure, and interface failures are fixable.

Until those change, the monthly totals will keep looking like August's: one enormous price manipulation incident, a scatter of smaller ones using the identical method, and a steady background hum of phishing that nobody reports on.

What the recovery rate actually tells you

The $110.7 million frozen or returned out of $215 million lost is the highest recovery share the sector has posted in a monthly report for some time, and it deserves an honest explanation rather than a celebration.

Most of it traces to one decision: halting the Cronos network mid-attack. Only about $6 million of Tectonic's $120.4 million had crossed the bridge to Ethereum before the pause, which means the great majority of it never moved anywhere an attacker could spend it. A chain that has stopped producing blocks cannot process the next transaction.

This is not a security improvement. It is a property of a chain with enough operator concentration to be paused by agreement, and it is precisely the property that Ethereum and Bitcoin do not have and are not designed to have. A recovery rate driven by pausability is a recovery rate available only to chains that can be paused.

Read the number that way and it says less about the industry getting better at recovering funds, and more about which chains the funds happened to be on.


About this report. Loss figures, attack-type breakdowns and incident details come from CertiK's August 2026 monthly report as covered by The Crypto Times, and CertiK's H1 2026 report. Recovery figures reflect amounts frozen or returned as of publication and may change.

Not investment or security advice. Descriptions of attack methods here are for awareness. Consult a qualified security professional for protocol design decisions.

Frequently asked questions

How much was lost to crypto hacks in August 2026?

CertiK counted $215 million in confirmed losses, of which DeFi protocols absorbed $144.6 million. About $110.7 million was later frozen or returned, leaving roughly $104 million permanently gone.

What was the largest crypto exploit in August 2026?

The Tectonic attack on Cronos, on 30 August, at $120.4 million. An attacker inflated the TONIC token roughly 100-fold in twenty minutes and borrowed against the inflated collateral before the network halted.

Sources

Read next