- Crypto hacks rose 67% in August, while estimated losses fell sharply to $136.3 million.
- Tectonic’s $75 million borrowing event drove more than half of August’s reported losses.
- Cronos reversed $68.7 million, leaving roughly $6 million beyond the rollback’s reach.
Crypto hacks caused estimated losses of $136.3 million across 50 major incidents in August, PeckShield reported. Losses fell 49.5% from July’s $270 million. Yet Tectonic accounted for about $74 million, showing how concentrated the month’s reported damage remained.
The number of major crypto hacks rose 66.7% from 30 in July to 50 in August. Meanwhile, estimated losses fell 49.5% to $136.3 million. The figures show more incidents but lower reported losses, rather than clear evidence of broader security improvement.
TRM Labs said the attacker borrowed about $75 million before Cronos halted block production. Roughly $6 million reached Ethereum, while a later rollback reversed about $68.7 million remaining on Cronos. The $75 million therefore represents the estimated gross amount borrowed, not a confirmed final net loss.
Why August’s Lower Loss Total Hides Concentrated Risk
PeckShield’s monthly estimate counted Tectonic as a $74 million loss. That represented about 54.3% of the $136.3 million total. The other 49 crypto hacks accounted for an estimated $62.3 million combined.
Moonwell ranked second at $8.7 million. Term Labs recorded $8.5 million, Coinsbuy $7.9 million and TAC $7.5 million.
PeckShield’s top ten cases produced $123.34 million, or about 90.5% of the total. Most reported losses therefore came from a small group. The monthly figure is not final. Recoveries, reversals, or updated investigations can change estimates, as Tectonic shows.
Why Tectonic’s $74 Million Estimate Needs Context
Tectonic warned users on August 30 not to interact with its Cronos-based lending protocol. The project has not published a final accounting or technical postmortem.
TRM said the attacker increased TONIC’s price about 100-fold within 20 minutes. TONIC is Tectonic’s thinly traded governance token. The attacker posted the inflated token as collateral and borrowed more valuable assets.
TONIC traded about $305,000 during the previous week. The $75 million borrowed was 245 times that volume. A temporary price therefore supported much larger loans.
The attack used collateral pricing rather than a code flaw. TRM recorded 32 price-manipulation exploits in 2026, its highest annual count. Moonwell suffered a similar $8.7 million incident three days earlier.
Cronos validators halted block production within minutes. About $6 million reached Ethereum before the shutdown, according to TRM. The remaining $68.7 million stayed on Cronos and was later reversed through the rollback.
Cronos restored the pre-attack chain state. Blocks resumed from block 90,896,189. The network warned that some connected services needed longer to recover. The $75 million describes a temporary borrowing event, not a settled loss. The rollback removed most activity, but the halt still cut access across Cronos.
How the Cronos Halt Changed the Trading Risk
The halt did not mean every Cronos service had been breached. Crypto.com CEO Kris Marszalek said its exchange and app were unaffected. He said customer funds there remained safe, but his assurance did not cover Tectonic deposits.
The distinction matters for CRO and other Cronos assets. A Tectonic exploit is not the same as a Crypto.com breach. However, the network halt made every Cronos application unavailable until validators restarted the chain.
CRO did not record an immediate sell-off. Hourly data showed it rising from $0.05718 to $0.06013 between 12:00 and 15:00 UTC, while volume increased.
That price move does not prove that the market ignored the incident. It shows that spillover is not automatic. Traders still need to separate direct losses, network disruption, and short-term speculation.
TRM said Tectonic’s TVL fell from $121.7 million to $3 million by August 31. The rollback later restored the earlier state, making the drop an incident signal rather than a final withdrawal.
What August Says About Crypto Security
The same distinction appears in broader data. TRM recorded 207 crypto hacks in the first half of 2026. That was its highest six-month count.
Losses still fell to $972 million from about $2.3 billion a year earlier. Infrastructure and operational breaches formed about 15% of incidents but caused 76% of stolen value. Smaller smart-contract attacks drove most of the increase in frequency.
CoinGecko found another concentration pattern. The industry lost an estimated $3.63 billion across 245 incidents from January 2025 through July 2026. The ten largest attacks caused more than 72.5% of that total.
Cronos also showed that rapid intervention can limit an attacker’s final proceeds. TRM said the rollback reversed about 92% of the Tectonic amount. However, the response required validators to discard blocks and every transaction inside them.
August therefore provides mixed evidence. Total estimated losses fell, but attacks became more frequent. Record price-manipulation activity makes early warnings as important as month-end totals.
Which Warning Signals Matter First?
Official security notices provide the first confirmed signal. Contract pauses, borrowing restrictions, and validator halts show when normal access has changed.
TVL changes require more context. Falling prices can lower dollar-denominated TVL without any withdrawals. A rollback can also restore balances that appeared missing in an earlier snapshot.
Wallet flows and bridge activity show whether an attacker has moved funds beyond the affected chain. In Tectonic’s case, roughly $6 million reached Ethereum. That amount remained outside the Cronos rollback.
Exchange order books provide the next signal. Wider spreads, weaker depth, and sudden volume increases can show rising stress. CRO and related DeFi tokens can then reveal whether concern is spreading beyond the exploited protocol.
August’s headline loss decline is real within PeckShield’s dataset. It is not proof that the threat from crypto hacks has disappeared. Incident concentration, live fund movements, TVL changes, and token liquidity provide a more complete risk picture.
Related: Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.





Be the first to comment