August Cryptocurrency Security Incident Report: Total Loss of 215 Million USD, Price Manipulation and Governance Vulnerabilities as Major Attack Methods

CN
PANews
Follow
1 hour ago

The monthly highlights of security incidents from Zero Time Technology have begun! According to statistics from multiple blockchain security monitoring platforms, the security landscape in the cryptocurrency field in August 2026 showed characteristics of "high attack frequency maintained, with price manipulation and governance vulnerabilities as major risks." The total loss caused by security incidents that month was approximately $215 million, with losses related to hacking attacks and contract vulnerabilities amounting to about $173.5 million, and phishing attacks causing around $41.5 million in losses. There were over 16 security incidents related to protocols, and the total losses in August significantly increased compared to $97 million in July, making August the third-highest month in terms of losses in 2026 to date.

The attack methods exhibited significant changes: price manipulation attacks became the biggest threat of the month, with a single Tectonic incident causing losses of about $75 million; governance vulnerability attacks (Term Finance lost $8.5 million), upstream component dependency vulnerabilities (Cosmos EVM vulnerabilities caused losses of $5.7 million across six chains), and other multifaceted attacks occurred simultaneously. The attack paths are accelerating the shift from smart contract code vulnerabilities to non-code layer attack methods, such as governance privilege abuse, oracle price manipulation, and upstream component dependency vulnerabilities, posing new challenges to traditional security auditing and defense systems.

Regarding Hacking Attacks

Typical security incidents 7

• Cronos Chain Tectonic Protocol Price Manipulation Attack

Time: August 30

Loss Amount: Approximately $75 million

Incident Details: In about 20 minutes, the attacker raised the price of the governance token TONIC of the largest lending protocol Tectonic on the Cronos chain by about 100 times, and subsequently borrowed other assets using the overvalued token as collateral. The Cronos network urgently suspended all block production on the chain, and the attacker only cross-chain transferred about $6 million to Ethereum before the suspension, with approximately $68 million remaining in related addresses. Crypto.com CEO confirmed that its application and exchange were not affected. Tectonic's Total Value Locked (TVL) plummeted from about $121.7 million to about $3 million.

• More Markets Flow EVM Liquidity Staking Attack

Time: August 31

Loss Amount: Approximately $9.3 million

Incident Details: More Markets' lending reserves on Flow EVM were drained of about $9.3 million. The attacker utilized Ankr Staked FLOW liquidity staking tokens combined with Aave V3's E-mode (efficiency mode) feature to excessively borrow about 15.5 million WFLOW tokens from the mFlowWFLOW lending reserves. This attack increased the total losses from cryptocurrency hacker attacks in August to $139.7 million.

• Term Finance Governance Privilege Attack

Time: August 23

Loss Amount: Approximately $8.5 million

Incident Details: The DeFi fixed-rate lending protocol Term Finance's vault was subjected to a governance attack. After the attacker gained majority voting power of its governance token, they stole approximately 2,843 ETH (about $6.87 million) and $1.68 million USDC from Meta Vaults, accounting for about 68% of the liquidity pool's held assets. This incident stemmed from governance authorization flaws rather than smart contract code vulnerabilities. The attack targeted Term Strategy Vaults based on the Yearn V3 architecture, while standard Yearn vaults were unaffected. Term Labs has closed all Meta Vaults and revoked DAO governance privileges.

• Cosmos EVM Module Vulnerability Chain Attack

Time: August 20-25

Loss Amount: Approximately $5.7 million

Incident Details: An integer underflow vulnerability in the Cosmos EVM module was exploited by attackers, leading to attacks on six blockchain networks between August 20 and 25. The attackers brought account balances to the maximum value and then reversed operations to transfer inflated balances out. In terms of specific losses, MANTRA lost 720.9 million tokens (about $3.6 million), TAC lost nearly 3 billion TAC, and KiiChain lost about 148 million KII. Cosmos Labs released a patch on August 19, but the first attack occurred about 20 hours later, and KiiChain and others criticized Cosmos Labs for not notifying affected chains in advance.

• Moonwell Protocol Price Manipulation Attack

Time: August 27

Loss Amount: Approximately $8.7 million

Incident Details: The lending protocol Moonwell on the Base chain was subjected to a price manipulation attack, where attackers manipulated the price of the illiquid MAMO token to excessively borrow against overvalued collateral. Multiple security agencies confirmed the scale of this loss. Several post-incident analysis reports indicated that this attack could be executed without requiring a smart contract vulnerability—the protocol directly priced collateral from weak spot liquidity.

• Realio Network Signature Key Leak Attack

Time: August 25

Loss Amount: Approximately $6.2 million

Incident Details: The web application realio.fund of the RWA blockchain project Realio Network was hacked. The attacker exploited the leaked signature keys stored on the platform to carry out the attack, rather than using a smart contract vulnerability. The attack spanned five blockchain networks: Ethereum, BNB Chain, Algorand, Stellar, and Realio's native network. Approximately 113.7 million RIO (91.4%) of the stolen funds came from the reserves of various chains, while about 10.7 million RIO (3.27%) came from user wallets. After the attack, Realio has suspended platform access and frozen customer wallet fund transfers, and the cross-chain bridge for Algorand and Stellar will remain closed indefinitely. Due to insufficient market liquidity, the hacker only liquidated about 3.7% of the stolen assets, most of which remain in wallets controlled by the attacker.

• MAYAChain Chain Reaction Attack

Time: August 18

Loss Amount: Approximately $1.7 million

Incident Details: The cross-chain liquidity protocol MAYAChain was attacked, and the attacker exploited six interconnected software vulnerabilities to create false account balances, stealing about 20.83 BTC (about $1.34 million) and other assets from the protocol's funding pool. The incident led to the suspension of trading on the MAYAChain network, with the settlement token CACAO plummeting nearly 89%, and the total value of the liquidity pool decreasing by about $11 million. MAYAChain suspended its network operations on August 19.

Rug Pull / Phishing Scams

Typical security incidents 5

(1) On August 13, a victim with an address starting with 0xa707 signed a phishing email on Arbitrum, resulting in a loss of $549,744 USDC.

(2) On August 22, a victim with an address starting with 0x7Ba7 lost about $2 million due to copying the wrong address from contaminated transfer records.

(3) “Trump Digital Gold” GOLD Token Rug Pull

Loss Amount: Approximately $8.2 million (profits disclosed by GoPlus)

Nature of the Incident: On August 29, a fraud gang controlled the website realtrumpcoins.com and the account @realtrumpcoins1, maliciously issuing GOLD tokens and claiming support from Trump. The token's market cap once surged to about $60 million, then was quickly sold off, dropping about 99%. On-chain data showed that the related team's address once controlled about 82.45% of the token supply, with 15 affiliated wallets selling 224.5 million GOLD, receiving about $330,000, triggering suspicions of a rug pull.

(4) Tornado Cash Expired Domain Phishing Attack

Loss Amount: Approximately $2.3 million

Nature of the Incident: From August 18 to 20, the official domain of the well-known privacy mixing tool Tornado Cash, tornado.cash, was hijacked by hackers due to expiry and non-renewal, who built a highly imitative phishing page to carry out fraud. An Ethereum user, who accessed the old version of the website through an outdated browser bookmark, had 1,010 ETH stolen in batches within 12 hours, worth about $2.3 million. The domain was registered by another party after the original development team failed to renew it due to U.S. OFAC sanctions. Additionally, on-chain data confirmed that another user lost 810 ETH.

(5) Hyperliquid User Targeted by Google Ads Phishing Attack

Loss Amount: Approximately $550,000

Nature of the Incident: On August 13, a Hyperliquid user seemingly entered a counterfeit Hyperliquid website via Google search ads and subsequently encountered a phishing attack, with about $550,000 USDC being transferred to the attacker's controlled wallet. On-chain analysis showed that the attacker completed the funds transfer through three transactions. This incident also exposed the risks of the phishing attack model combining search engine ads, brand impersonation websites, and wallet authorizations.

Summary

The blockchain security landscape in August 2026 displayed three significant changes: price manipulation has become the greatest threat, governance vulnerabilities have entered a stage of large-scale exploitation, and attacks are characterized by "premeditation."

This month's attack methods have undergone a structural transformation. Price manipulation attacks replaced traditional contract vulnerabilities as the main source of losses, with attackers using illiquid tokens as a gateway for price manipulation, bypassing code audit defenses. Governance privilege abuse has evolved from an occasional event to a systemic risk, with flaws in governance mechanism design becoming new targets for attackers. Upstream component dependency vulnerabilities leading to single-patch delays triggered chain reactions across multiple chains, exposing the "single point of failure" risk in shared module ecosystems.

Phishing scams have shown a new evolutionary direction: expired domain hijacking has become a novel attack entry point, and X account intrusions promoting fake tokens continue to operate on a large scale. Attackers' methodologies are also upgrading—premeditated layouts and patch race tactics have become the new norm.

The Zero Time Technology security team advises:

• Individuals: Regularly check and revoke wallet authorizations, be wary of expired domain hijacking and phishing links; use official bookmarks to access commonly used protocols, avoiding redirects through search engines or expired domains; use separate wallets for high-value assets to isolate risk.

• Project Teams: Strictly manage governance privileges, set higher voting thresholds and execution delays for DAO governance proposals; implement multi-source verification on oracle pricing to prevent illiquid tokens from being used for price manipulation; establish a security alert and patch response mechanism for upstream dependency components; create a 7×24-hour abnormal monitoring and circuit breaker mechanism.

• Industry: Promote the establishment of security standards for governance mechanisms; strengthen industry-level research on defenses against price manipulation attacks; establish rapid warning and patch synchronization mechanisms for upstream dependency vulnerabilities; enhance APT threat intelligence sharing and blacklist database construction.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink