August 2026 Among Worst Months for DeFi Hacks
August 2026 emerged as a damaging month for DeFi, with repeated exploits affecting Tectonic, More Markets, Maya Protocol, Harmony & multiple Cosmos EVM networks.
August 2026 ended as another damaging month for decentralized finance, with frequent hacks and security incidents reported across the crypto industry. Lending protocols, cross-chain liquidity networks, blockchain infrastructure and hardware wallet users were all affected.
The incidents involved several different attack methods, including collateral-price manipulation, faulty protocol accounting, unauthorized token minting, shared infrastructure vulnerabilities and weak wallet seed generation.
Tectonic Dominates August’s DeFi Exploits
The largest August incident covered by EtherWorld involved Tectonic, a decentralized lending protocol operating on Cronos. An attacker reportedly manipulated the price of Tectonic’s relatively illiquid TONIC governance token by approximately 100 times within around 20 minutes.
Cronos halted block production while the exploit was investigated, while Tectonic warned users not to interact with the protocol until it could confirm that operations were safe. The incident resembled a pump-and-borrow attack. In this type of exploit, a lending protocol may continue operating according to its programmed rules while relying on an unreliable or manipulated collateral price.
A similar weakness appeared during the Rhea Finance exploit, where fake token pools and apparent oracle manipulation helped attackers extract approximately $7.6 million.
More Markets became another lending-related victim on the final day of August. Tectonic and More Markets demonstrated how quickly faulty collateral assumptions can turn into protocol-wide losses. Both incidents also showed why DeFi security audits must examine economic configurations and liquidity conditions alongside the underlying smart contract code.
Maya, Harmony & Cosmos Expand the Damage
The Maya Protocol exploit directly extracted approximately $1.7 million in hard assets from the cross-chain liquidity network. The attacker reportedly combined several weaknesses to corrupt the protocol’s internal accounting before withdrawing assets from shared liquidity pools.
Approximately 48.87 million CACAO and 98.82 LINK were involved in the exploit, while around 20 BTC was traced to an attacker-associated address. The direct theft was estimated at approximately $1.7 million, but the wider economic damage was considerably larger. CACAO fell nearly 89%, while Maya Protocol’s total pool value reportedly declined as distorted balances, falling token prices and arbitrage activity amplified the original exploit.
Cross-chain protocols can be especially difficult to secure because they must coordinate messages, liquidity and asset accounting across different networks. Earlier incidents such as the Verus-Ethereum Bridge exploit and the Hyperbridge vulnerability affecting DOT on Ethereum demonstrated how a failure in one bridge or gateway can place assets at risk without compromising the underlying blockchain.
EtherWorld’s report on the Harmony exploit described the creation of four billion ONE tokens, not a theft worth four billion US dollars. Independent security analysis valued the newly minted supply at approximately $3.2 million at the time.
Around 2.8 billion unauthorized ONE tokens were reportedly moved toward exchanges, while ONE’s price dropped sharply after the incident became public.
The case shared similarities with the fake eBTC minting attack against Echo Protocol, where a compromised administrative key allowed an attacker to create unbacked assets and extract value from connected markets.
A shared infrastructure vulnerability also affected networks using the Cosmos EVM module. The flaw reportedly enabled attackers to manipulate balance calculations involving vesting accounts. EtherWorld covered both the initial Cosmos EVM security incident and its wider implications for multichain ecosystems.
The vulnerability affected multiple independent chains using the same software module. KiiChain, TAC and MANTRA were among the networks affected or forced to halt operations while validators and developers deployed fixes.
Every August Security Incident
EtherWorld published coverage of nine hack, exploit and breach-related developments during August, representing eight distinct security cases.
- What the COLDCARD Exploit Means for Crypto?: A weak-entropy flaw affecting certain COLDCARD devices was linked to the theft of nearly 594 BTC from more than 500 addresses. The coordinated sweep occurred around July 31, despite EtherWorld publishing its analysis on August 3.
- ZachXBT Exposes Alleged $5M Crypto Scam: ZachXBT linked an alleged social-engineering network to at least $5 million in cumulative thefts. These cases occurred across multiple dates and did not represent one August DeFi protocol exploit.
- Harmony ONE Token Crashes After Unauthorized Mint: An attacker created four billion unauthorized ONE tokens through a cross-shard receipt replay vulnerability.
- Trezor ShipMonk Data Breach Exposes Customer Data: Personal information belonging to 13,689 customers was exposed through Trezor’s fulfilment partner. Trezor said its systems and hardware wallets were not compromised, and no direct cryptocurrency loss was reported.
- Maya Protocol Exploit Drains $1.7M in CACAO: A multi-stage accounting exploit extracted approximately $1.7 million while causing significantly greater damage to CACAO and protocol liquidity.
- Cosmos EVM Security Incident Forces Chains to Halt: A shared module vulnerability affected users across multiple networks and prompted emergency validator halts.
- Cosmos EVM Vulnerability Should Alarm Multichain Ecosystems: EtherWorld’s follow-up examined how independent blockchains can inherit the same security risk through shared infrastructure.
- Cronos Halts After $75M Tectonic Exploit: A reported collateral-price manipulation attack became the largest DeFi incident covered during August.
- $9.3M Drained from More Markets Lending Reserve: An attacker drained WFLOW from a lending reserve on Flow EVM using a strategy involving a bonded liquid-staking asset and E-mode.
August Exposes DeFi’s Weakest Security Links
Tectonic and More Markets highlighted risks created by collateral settings, liquidity assumptions and lending-market configurations. Maya Protocol showed how multiple accounting weaknesses can be combined into a larger exploit. Harmony demonstrated how a token’s supply can be compromised at the blockchain level, while Cosmos EVM revealed the systemic danger of shared infrastructure.
COLDCARD and the Trezor ShipMonk breach expanded the issue beyond DeFi protocols. One involved the randomness used to generate wallet recovery phrases, while the other exposed customer information through a third-party logistics provider.
The alleged scams documented by ZachXBT showed that attackers do not always need to defeat code. They can impersonate wallet companies, exchanges or support representatives and persuade users to surrender control themselves. As explored in EtherWorld’s analysis of crypto’s human security problem, irreversible transactions make social-engineering mistakes particularly damaging.
August was not the year’s largest month by reported value. April 2026 recorded more than $635 million in estimated exploit losses, driven by several major incidents. However, August’s repeated attacks showed that the security threat remains persistent even outside the industry’s largest crises.
The ecosystem has already seen how one vulnerability can spread across protocols. The KelpDAO exploit triggered a wider DeFi liquidity crisis after unbacked rsETH entered lending markets and was used to borrow other assets.
DeFi’s challenge is therefore no longer limited to identifying mistakes inside smart contracts. Protocols must also defend the price feeds, collateral parameters, administrative keys, bridges, shared modules, external service providers and human decisions on which those contracts depend.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- April 2026 Worst for DeFi: Over $635M Lost in Exploits
- Rhea Finance Exploit Drains $7.6M
- KelpDAO Exploit Triggers $290M Crisis Across DeFi
- DeFi Unites After KelpDAO $292M Hack
- How $900 Bought Control of an $8.5M DeFi Vault
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.