Crypto hacks rise 67% as August losses hit $136M

Coinmama
Changelly


Crypto hacks increased sharply in August, although the estimated value stolen fell by nearly half compared with July, according to blockchain security company PeckShield.

Summary

  • 50 major crypto hacks caused an estimated $136.3 million in losses during August, PeckShield reported.
  • August’s incident count increased 67% from July, while estimated losses declined 49.5% month over month.
  • Tectonic accounted for approximately $74 million, more than half of PeckShield’s estimated monthly losses overall.
  • Cronos validators halted production before the attacker could move most identified assets onto Ethereum successfully.
  • Cronos later resumed blocks after validators restored network state to before the Tectonic exploit occurred.

PeckShield eported on Sept. 1 that it recorded 50 major incidents during August. That was a 67% increase from the 30 incidents counted in July.

Estimated losses reached $136.3 million, down 49.5% from approximately $270 million in July. The figures represent PeckShield’s estimates and may change as affected projects investigate transactions, freeze assets or recover funds.

Binance

The Tectonic lending incident dominated the month, accounting for approximately $74 million, or more than half of PeckShield’s total.

Crypto hacks became more frequent but less costly

The August figures show a growing number of attacks with losses concentrated in one large incident. Excluding Tectonic, the remaining 49 incidents generated estimated combined losses of about $62.3 million.

PeckShield identified Moonwell as the second-largest incident at $8.7 million. Term Labs followed at $8.5 million, while Coinsbuy and TAC recorded estimated losses of $7.9 million and $7.5 million, respectively.

Other named incidents included Injective at $4.8 million, MANTRA at $3.6 million, BounceBit at $3 million and Cosmos Labs at $2.87 million. Aquifer completed PeckShield’s top ten with an estimated $2.47 million loss.

These figures should not be treated as final net losses. Security firms can classify incidents differently, particularly when funds remain traceable, frozen or recoverable. Projects may also revise their estimates after completing technical reviews.

A recent CoinGecko study found that crypto platforms lost $3.63 billion across 245 incidents between January 2025 and July 2026. The ten largest incidents accounted for more than 72.5% of that estimate, showing how a few major attacks can shape monthly totals.

Tectonic represented more than half of August losses

Tectonic disclosed an incident affecting its Cronos-based lending protocol on Aug. 30 and warned users not to interact with the platform while its team investigated.

Security researchers estimated that an attacker manipulated collateral pricing and borrowed assets worth approximately $74 million. Tectonic has not published a final loss figure or complete technical report, meaning the estimate remains subject to revision.

PeckShield classified the Tectonic incident as the fourth-largest cryptocurrency theft recorded during 2026. It ranked behind attacks involving Drift, KelpDAO and LayerZero, and hardware-wallet provider Coldcard.

Crypto.com CEO Kris Marszalek confirmed that the incident affected Tectonic rather than Crypto.com’s centralized exchange or app. He said the company’s security team was assisting the Cronos investigation.

As crypto.news previously reported, Crypto.com customer funds remained unaffected because the breach concerned a separate decentralized protocol operating on Cronos.

Cronos halted before most assets left the network

Cronos validators stopped block production after detecting the active exploit. Independent address analysis and PeckShield’s tracking indicated that the attacker moved approximately $6 million to Ethereum before the halt.

Most of the remaining identified assets stayed on Cronos. Funds remaining on the affected network were not necessarily recovered at that point, but the halt prevented additional transactions from receiving confirmation.

Cronos later resumed block production after validators restored the network to a state preceding the exploit. Blocks restarted at 23:49:01 UTC from block 90,896,189, according to the network’s update.

Node operators were directed to install Cronos version 1.7.8 and use a mainnet snapshot taken before the incident. The decision effectively removed transactions included during the discarded section of the chain.

The rollback raises questions about transactions made by unrelated users during that period. Cronos has not yet provided a complete accounting of which transfers, trades or liquidations were reversed.

PeckShield said the attacker had started moving part of the assets that reached other networks. The security company reported an initial conversion toward Bitcoin, but the amount remains small compared with the funds originally associated with the attack.

Investigations and recovery efforts remain open

Cronos and Tectonic are expected to publish a full post-incident report explaining the exploit, validator response and network restoration. Neither project has provided a publication date.

Tectonic has also not announced a repayment or compensation plan for affected depositors. Any recoverable amount will depend on the status of assets remaining on Cronos and whether exchanges or bridge operators can restrict funds moved elsewhere.

August also included network disruptions unrelated to Tectonic. MANTRA resumed block production after deploying a software update addressing a Cosmos-EVM vulnerability. The project said two team-managed wallets were affected while user balances remained unchanged.

PeckShield’s next monthly calculation could change if protocols recover assets or revise their reported exposure. For now, its dataset shows that attacks became more frequent in August even as the estimated amount lost declined sharply.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*