Crypto Hacks Rise 67% in August as Tectonic Exploit Drives $136M Losses

58 minute ago 4 sources negative

Key takeaways:

  • Audited platforms still lose 88% of hacked funds, questioning audit value as security proxy.
  • Cronos chain rollback after Tectonic exploit highlights trade-off between decentralization and investor protection.
  • Shrinking insurance coverage amplifies systemic risk as attacks shift to infrastructure, not just code.

A new wave of security data underscores how crypto attackers are outpacing industry defenses. CoinGecko’s 2026 State of Crypto Security Report found that platforms lost $3.63 billion across 245 documented incidents from January 2025 through July 2026, with the ten largest attacks accounting for more than 72.5% of the total. Infrastructure and supply-chain failures were the costliest category for both centralized and decentralized platforms, exceeding $1.8 billion, with notable breakdowns at Bybit and KelpDAO.

Decentralized applications lost roughly $546 million to smart-contract exploits, while centralized venues mainly suffered from compromised private keys. The report noted that about 60% of exploited platforms—147 of 245—had completed third-party audits before being compromised, representing 88.44% of all drained capital. Only about 11% of incidents involved in-scope smart-contract flaws, producing $396 million in losses. On-chain insurance coverage shrank 20.2% to $130.2 million, and five of nine leading insurance protocols had gone inactive by August 2026.

PeckShield’s August data showed the trend continuing. The industry recorded 50 major hacks, up 67% from July’s 30 incidents, with estimated losses of $136.3 million, down 49.5% from about $270 million in July. The Cronos-based lending protocol Tectonic dominated, with roughly $74 million in estimated losses—more than half the monthly total. Moonwell followed at $8.7 million, Term Labs at $8.5 million, Coinsbuy at $7.9 million, TAC at $7.5 million, Injective at $4.8 million, MANTRA at $3.6 million, BounceBit at $3 million, Cosmos Labs at $2.87 million and Aquifer at $2.47 million.

Tectonic disclosed the incident on Aug. 30 and warned users not to interact with its platform. Researchers believe an attacker manipulated collateral pricing and borrowed assets worth about $74 million. Cronos validators halted block production and later restored network state to before the exploit, restarting from block 90,896,189 with version 1.7.8. About $6 million was moved to Ethereum before the halt. Crypto.com CEO Kris Marszalek confirmed the incident affected Tectonic, not Crypto.com’s centralized exchange or app, and said its security team was assisting the investigation. Full post-incident reports from Cronos and Tectonic have not yet been published.

Previously on the topic:
Aug 29, 2026, 3:53 p.m.
Ajna Protocol Loses $775K in Oracleless DeFi Exploit
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.