August 2026 Among Worst Months for DeFi Hacks

August 2026 emerged as a damaging month for DeFi, with repeated exploits affecting Tectonic, More Markets, Maya Protocol, Harmony & multiple Cosmos EVM networks.

August 2026 Among Worst Months for DeFi Hacks
August 2026 Among Worst Months for DeFi Hacks

August 2026 ended as another damaging month for decentralized finance, with frequent hacks and security incidents reported across the crypto industry. Lending protocols, cross-chain liquidity networks, blockchain infrastructure and hardware wallet users were all affected.

The incidents involved several different attack methods, including collateral-price manipulation, faulty protocol accounting, unauthorized token minting, shared infrastructure vulnerabilities and weak wallet seed generation.

Tectonic Dominates August’s DeFi Exploits

The largest August incident covered by EtherWorld involved Tectonic, a decentralized lending protocol operating on Cronos. An attacker reportedly manipulated the price of Tectonic’s relatively illiquid TONIC governance token by approximately 100 times within around 20 minutes.

Cronos halted block production while the exploit was investigated, while Tectonic warned users not to interact with the protocol until it could confirm that operations were safe. The incident resembled a pump-and-borrow attack. In this type of exploit, a lending protocol may continue operating according to its programmed rules while relying on an unreliable or manipulated collateral price.

A similar weakness appeared during the Rhea Finance exploit, where fake token pools and apparent oracle manipulation helped attackers extract approximately $7.6 million.

More Markets became another lending-related victim on the final day of August. Tectonic and More Markets demonstrated how quickly faulty collateral assumptions can turn into protocol-wide losses. Both incidents also showed why DeFi security audits must examine economic configurations and liquidity conditions alongside the underlying smart contract code.

Maya, Harmony & Cosmos Expand the Damage

The Maya Protocol exploit directly extracted approximately $1.7 million in hard assets from the cross-chain liquidity network. The attacker reportedly combined several weaknesses to corrupt the protocol’s internal accounting before withdrawing assets from shared liquidity pools.

Approximately 48.87 million CACAO and 98.82 LINK were involved in the exploit, while around 20 BTC was traced to an attacker-associated address. The direct theft was estimated at approximately $1.7 million, but the wider economic damage was considerably larger. CACAO fell nearly 89%, while Maya Protocol’s total pool value reportedly declined as distorted balances, falling token prices and arbitrage activity amplified the original exploit.

Cross-chain protocols can be especially difficult to secure because they must coordinate messages, liquidity and asset accounting across different networks. Earlier incidents such as the Verus-Ethereum Bridge exploit and the Hyperbridge vulnerability affecting DOT on Ethereum demonstrated how a failure in one bridge or gateway can place assets at risk without compromising the underlying blockchain.

EtherWorld’s report on the Harmony exploit described the creation of four billion ONE tokens, not a theft worth four billion US dollars. Independent security analysis valued the newly minted supply at approximately $3.2 million at the time.

Around 2.8 billion unauthorized ONE tokens were reportedly moved toward exchanges, while ONE’s price dropped sharply after the incident became public.

The case shared similarities with the fake eBTC minting attack against Echo Protocol, where a compromised administrative key allowed an attacker to create unbacked assets and extract value from connected markets.

A shared infrastructure vulnerability also affected networks using the Cosmos EVM module. The flaw reportedly enabled attackers to manipulate balance calculations involving vesting accounts. EtherWorld covered both the initial Cosmos EVM security incident and its wider implications for multichain ecosystems.

The vulnerability affected multiple independent chains using the same software module. KiiChain, TAC and MANTRA were among the networks affected or forced to halt operations while validators and developers deployed fixes.

Every August Security Incident

EtherWorld published coverage of nine hack, exploit and breach-related developments during August, representing eight distinct security cases.

Tectonic and More Markets highlighted risks created by collateral settings, liquidity assumptions and lending-market configurations. Maya Protocol showed how multiple accounting weaknesses can be combined into a larger exploit. Harmony demonstrated how a token’s supply can be compromised at the blockchain level, while Cosmos EVM revealed the systemic danger of shared infrastructure.

COLDCARD and the Trezor ShipMonk breach expanded the issue beyond DeFi protocols. One involved the randomness used to generate wallet recovery phrases, while the other exposed customer information through a third-party logistics provider.

The alleged scams documented by ZachXBT showed that attackers do not always need to defeat code. They can impersonate wallet companies, exchanges or support representatives and persuade users to surrender control themselves. As explored in EtherWorld’s analysis of crypto’s human security problem, irreversible transactions make social-engineering mistakes particularly damaging.

August was not the year’s largest month by reported value. April 2026 recorded more than $635 million in estimated exploit losses, driven by several major incidents. However, August’s repeated attacks showed that the security threat remains persistent even outside the industry’s largest crises.

The ecosystem has already seen how one vulnerability can spread across protocols. The KelpDAO exploit triggered a wider DeFi liquidity crisis after unbacked rsETH entered lending markets and was used to borrow other assets.

DeFi’s challenge is therefore no longer limited to identifying mistakes inside smart contracts. Protocols must also defend the price feeds, collateral parameters, administrative keys, bridges, shared modules, external service providers and human decisions on which those contracts depend.


To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

  1. April 2026 Worst for DeFi: Over $635M Lost in Exploits
  2. Rhea Finance Exploit Drains $7.6M
  3. KelpDAO Exploit Triggers $290M Crisis Across DeFi
  4. DeFi Unites After KelpDAO $292M Hack
  5. How $900 Bought Control of an $8.5M DeFi Vault

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Advertisement
ETHShala Understand Ethereum. Shape the Future.

ETHShala is your gateway to Ethereum Improvement Proposals, core concepts, and ecosystem ideas.

Learn Ethereum Understand EIPs Build the Future
Explore ETHShala →
Promotional Partnerships

We’re opening a limited number of promotional partnerships for web3 ecosystem projects looking to increase their visibility across our media channels.

Partner With Us →
EIPs Insight EIPs Insight Track Ethereum Upgrades & EIPs

Track Ethereum protocol upgrades, EIPs, AllCoreDevs calls, decisions & governance - all in one place.

Explore EIPs Insight →
EtherWorld.co × Avarch Join Our Internship Program

Gain hands-on experience in Web3 media, research, core protocols & developer relations.

Apply Now →
Sponsored Announcement
ETHShala Web3 Education

Understand Ethereum. Shape the Future.

ETHShala is your gateway to the world of Ethereum Improvement Proposals, core concepts, and the ideas shaping the Ethereum ecosystem.

Learn Ethereum Understand EIPs Build the Future
Promotional Partnerships EtherWorld Media

Amplify Your Web3 Ecosystem Project

We’re opening a limited number of promotional partnerships for web3 ecosystem projects looking to increase their visibility across our media channels.

Media Sponsorship Web3 Visibility Ecosystem Reach
EIPs Insight EIPs Insight Protocol Intelligence

Ethereum Protocol & Governance Analytics

Track Ethereum protocol upgrades, EIPs, AllCoreDevs calls, decisions & governance - all in one place.

Protocol Upgrades ACD Call Trackers EIP Analytics
EtherWorld.co × Avarch
Career Opportunity

Join Our Internship Program

Gain hands-on experience in Web3 media, core protocol research, technical writing, and developer relations.

Protocol Research Web3 Media Dev Relations

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free