
Zero Time Tech’s Monthly Security Incident Roundup is here! According to statistics from multiple blockchain security monitoring platforms, the security landscape in the cryptocurrency sector for August 2026 was characterized by “persistently high attack frequencies, with price manipulation and governance vulnerabilities emerging as primary risks.” Total losses due to security incidents during the month amounted to approximately $215 million, with $173.5 million attributed to hacker attacks and smart contract vulnerabilities, and $41.5 million resulting from phishing attacks. Over 16 protocol-related security incidents occurred, and the total monthly losses in August significantly increased compared to $97 million in July, making August the third-highest loss month of 2026 to date.
Attack methods have undergone significant changes: price manipulation attacks have become the greatest threat this month, with a single Tectonic incident causing approximately $75 million in losses; concurrent multi-dimensional attacks include governance vulnerability exploits (Term Finance lost $8.5 million) and upstream dependency vulnerabilities (the Cosmos EVM vulnerability led to $5.7 million in losses across six chains). Attack vectors are rapidly shifting from smart contract code vulnerabilities toward non-code-based methods such as governance privilege abuse, oracle price manipulation, and upstream dependency vulnerabilities, presenting new challenges to traditional security auditing and defense systems.
Regarding hacker attacks
Seven typical security incidents
• Price manipulation attack on the Tectonic protocol on the Cronos chain
Time: August 30
Loss amount: approximately $75 million
Event details: Over approximately 20 minutes, the attacker inflated the price of TONIC, the governance token of Tectonic—the largest lending protocol on the Cronos chain—by about 100 times, then used the artificially inflated tokens as collateral to borrow other assets. The Cronos network urgently paused block production. Before the chain halt, the attacker transferred only about $6 million to Ethereum via cross-chain bridges, while approximately $68 million remained in the related addresses. Crypto.com’s CEO confirmed that its app and exchange were unaffected. Tectonic’s TVL plummeted from around $121.7 million to approximately $3 million.


• More Markets Flow EVM Liquidity Staking Attack
Time: August 31
Loss amount: approximately $9.3 million
Event details: Approximately $9.3 million was drained from the lending reserve of More Markets on Flow EVM. The attacker exploited Ankr Staked FLOW liquid staking tokens in conjunction with Aave V3’s E-mode (efficiency mode) to borrow over 15.5 million WFLOW tokens from the mFlowWFLOW lending reserve. This attack brings the total cryptocurrency hacking losses for August to $139.7 million.
• Term Finance Governance Permission Attack
Time: August 23
Loss amount: approximately $8.5 million
Event Details: The treasury of Term Finance, a DeFi fixed-rate lending protocol, suffered a governance attack. The attacker gained majority voting power over its governance tokens and stole approximately 2,843 ETH (around $6.87 million) and $1.68 million in USDC from Meta Vaults, accounting for roughly 68% of the assets held in the liquidity pools. The incident resulted from a governance authorization flaw, not a smart contract code vulnerability. The attack targeted Term Strategy Vaults built on the Yearn V3 architecture; standard Yearn vaults were unaffected. Term Labs has since shut down all Meta Vault treasuries and revoked DAO governance permissions.
• Chain of attacks exploiting vulnerabilities in the Cosmos EVM module
Time: August 20–25
Amount lost: approximately $5.7 million
Event Details: An integer underflow vulnerability in the Cosmos EVM module was exploited by attackers, resulting in attacks on six blockchain networks between August 20 and 25. The attackers caused account balances to underflow to their maximum values, then reversed the operation to withdraw the inflated balances. Specific losses included 720.9 million MANTRA tokens (approximately $3.6 million), nearly 3 billion TAC tokens, and approximately 148 million KII tokens from KiiChain. Cosmos Labs released a patch on August 19, but the first attack occurred approximately 20 hours later; KiiChain and others criticized Cosmos Labs for failing to notify affected chains in advance.
• Moonwell Protocol Price Manipulation Attack
Time: August 27
Loss amount: approximately $8.7 million
Event details: The lending protocol Moonwell on the Base chain suffered a price manipulation attack, in which the attacker exploited insufficient liquidity in the MAMO token to inflate its price and borrow funds exceeding the true value of the collateral. Multiple security firms have confirmed the scale of the loss. Several post-attack analyses indicate that the attack did not require a smart contract vulnerability—it exploited the protocol’s direct pricing of collateral based on weak spot liquidity.

• Realio Network signature key exposure attack
Time: August 25
Loss amount: approximately $6.2 million
Incident Details: The web application realio.fund of the RWA blockchain project Realio Network was compromised by hackers. The attack exploited leaked signature keys stored on the platform, not a smart contract vulnerability. The breach spanned five blockchains: Ethereum, BNB Chain, Algorand, Stellar, and the Realio native network. Approximately 113.7 million RIO tokens (91.4% of the stolen funds) were taken from reserve vaults across these chains, while about 10.7 million RIO tokens (3.27%) were stolen from user wallets. Following the attack, Realio suspended platform access and froze withdrawals from customer wallets; the cross-chain bridges on Algorand and Stellar will be permanently shut down. Due to insufficient market liquidity, the hacker has only cashed out approximately 3.7% of the stolen assets, with the majority still held in wallets under the attacker’s control.
• MayaChain cascade vulnerability attack
Time: August 18
Amount lost: approximately $1.7 million
Event Details: The cross-chain liquidity protocol MAYAChain was attacked, with the attacker exploiting six interconnected software vulnerabilities to create fake account balances and steal approximately 20.83 BTC (around $1.34 million) and other assets from the protocol’s liquidity pools. The incident caused MAYAChain’s network to suspend trading, the settlement token CACAO to plummet nearly 89%, and the total value of liquidity pools to decline by approximately $11 million. MAYAChain suspended network operations on August 19.
Rug Pull / Phishing Scam
Five typical security incidents
(1) On August 13, victims with addresses starting in 0xa707 signed a phishing email on Arbitrum, resulting in a loss of $549,744 in USDC.
(2) On August 22, victims with addresses starting in 0x7Ba7 lost approximately $2 million by copying an incorrect address from a compromised transfer record.
(3) "Trump Digital Gold" GOLD token rug pull
Amount lost: Approximately $8.2 million (profit disclosed by GoPlus)
Incident Type: On August 29, a fraud group took control of the website realtrumpcoins.com and the @realtrumpcoins1 account, maliciously issuing the GOLD token while falsely claiming endorsement from Trump's team. The token's market cap briefly surged to approximately $60 million before rapidly collapsing by about 99% due to massive sell-offs. On-chain data shows that the related team address once controlled roughly 82.45% of the token supply, with 15 associated wallets selling 224.5 million GOLD tokens, netting approximately $330,000—raising suspicions of a rug pull.
(4) Tornado Cash expired domain phishing attack
Loss amount: approximately $2.3 million
Incident Type: From August 18 to 20, the official domain tornado.cash of the well-known privacy mixer Tornado Cash expired and was hijacked by hackers who registered it and set up a high-fidelity phishing site to carry out fraud. An Ethereum user, who accessed the outdated site via an obsolete browser bookmark, lost 1,010 ETH—valued at approximately $2.3 million—stolen in batches within 12 hours. The domain was registered by another party after the original development team failed to renew it following U.S. OFAC sanctions. On-chain data also confirmed another user lost 810 ETH.
(5) Hyperliquid users targeted by Google ad phishing attack
Loss amount: approximately $550,000
Incident Type: On August 13, a Hyperliquid user allegedly accessed a counterfeit Hyperliquid website via a Google search ad and fell victim to a phishing attack, resulting in approximately $550,000 in USDC being transferred to the attacker’s wallet. On-chain analysis revealed that the attacker completed the fund transfer through three transactions. This incident again highlights the risks associated with the phishing attack pattern involving search engine ads, counterfeit brand websites, and wallet authorization.
Summary
In August 2026, the blockchain security landscape showed three significant changes: price manipulation became the greatest threat, governance vulnerabilities entered a phase of large-scale exploitation, and attacks exhibited a "premeditated" nature.
This month, attack methods underwent a structural shift. Price manipulation attacks have replaced traditional contract vulnerabilities as the primary source of losses, with attackers exploiting low-liquidity tokens as entry points to bypass code audit defenses. Governance privilege abuse has evolved from isolated incidents into a systemic risk, as design flaws in governance mechanisms have become a new target for attackers. Vulnerabilities in upstream dependency components have caused single patched delays to trigger cascading effects across multiple chains, exposing the “single point of failure” risk within shared module ecosystems.
Phishing scams are evolving in new directions: expired domain hijacking has become a new attack vector, and compromised X accounts continue to be used at scale to promote fake tokens. Attackers’ methodologies are also advancing—premeditated planning and patch-ahead tactics have become the new norm.
Zero Time Technology Security Team recommends:
• Individual: Regularly review and revoke wallet approvals; be cautious of expired domain hijacking and phishing links; use official bookmarks to access frequently used protocols, avoiding redirects via search engines or expired domains; use separate wallets to isolate risk for high-value assets.
• Project Team: Strictly control governance permissions, set higher voting thresholds and delayed execution mechanisms for DAO governance proposals; implement multi-source verification for oracle pricing to prevent tokens with insufficient liquidity from being used for price manipulation; establish security alert and patch response mechanisms for upstream dependent components; implement a 24/7 anomaly monitoring and circuit breaker system.
• Industry: Promote the establishment of security standards for governance mechanisms; enhance industry-level research on defenses against price manipulation attacks; establish rapid alert and patch synchronization mechanisms for upstream dependency vulnerabilities; strengthen APT threat intelligence sharing and blacklist database development.

