August 2026: The Price Feed Was Exploited

Share this article:

Crypto lost $255.4M across 46 incidents in August 2026, roughly level with July's $254.4M, with more incidents than any month this year. June and July incidents were largely due to key compromises, but August shifted to price manipulation. Eleven oracle and price-manipulation incidents accounted for $135.87M, or 53% of the month.

Two chains stopped producing blocks and rolled back state to undo the damage.

Here's the month in security 👇

August 2026 losses by category

CategoryLossIncidents
Oracle / price manipulation~$135.87M11
Token and share accounting~$61.20M6
Private key / hot-wallet compromise~$18.34M4
Access control / ownership takeover~$16.15M9
Protocol logic (withdrawal, liquidation, swap)~$10.61M7
Malicious governance proposal~$8.51M2
Bridge signature / verification bypass~$4.68M5
Input validation~$0.03M2
Total (Aug 1 to 31)~$255.4M46

Source: DefiLlama

Hacks of the month 

Tectonic, ~$120.4M (Aug 30). An attacker pumped TONIC, Tectonic's thinly traded governance token, roughly 100x in about 20 minutes. Weekly volume before the attack was around $305K. The inflated position went in as collateral on Cronos' largest lending protocol, and the attacker borrowed $120.4M across nine markets, far more than the token's real market could support. Cronos halted block production about two hours in. By then $9.19M had already left the chain, and validators rolled back 10,961 blocks to reverse the remaining $111.2M. One incident was nearly half the month. 

Source | TRM Labs · CoinDesk

Moonwell, ~$8.7M (Aug 27). Same play, but with a smaller size. An attacker moved MAMO across DEXes until the Chainlink feed read $0.4313 instead of $0.0106, a 3,970% move. That collateral supported $11.03M in borrows across 18 transactions, and $8.73M in USDC left for Ethereum. Moonwell capped Base borrows afterward. It was the protocol's third oracle-related failure in 11 months. 

Source | BlockD

Term Finance, ~$8.5M (Aug 23). Governance participation thresholds were low enough that an attacker bought voting control cheaply, then used it to change strategy parameters and install malicious contracts. 2,841.74 WETH and 1.68M USDC were withdrawn, and Term Finance shut down its meta vaults. 

Source | The wBlock · BlockSec

Cosmos EVM, six chains (Aug 20 to 25). One arithmetic bug in shared infrastructure. When the EVM synced spendable balances, it subtracted the delegated amount from the existing balance even though the delegation came out of the locked balance. Accounts underflowed to 2^256-1, then drained. Nesa lost ~$50M nominal, KiiChain ~$9.7M, TAC ~$7.5M, and MANTRA's attacker hit a burn address and a dormant multisig. Slippage cut the realized take to about $5.7M.

A researcher reported the bug through the bounty program on April 25. Cosmos Labs' testers concluded live networks weren't vulnerable, patched it silently, and shipped no advisory. The real patch went out Aug 19 at 7:01pm ET with vague release notes, and a downstream developer posted the exact exploit path on GitHub eight hours later. The first attack landed 20 hours after the patch. MANTRA's response: 38 independent validators cannot assess, build, test, and coordinate a state-breaking upgrade in that window without a vulnerability-specific advisory. 

Source | The Block · BlockSec

Offchain: Web2 lost its keys again.

August’s traditional-security incidents ran on credentials that were stolen, phished, or simply left in public.

ChainDrop, a self-propagating Shai-Hulud variant, published 2,212 malicious versions across 444 npm packages in under four hours on Aug 4 and took over the keyv and cacheable namespaces, 450M+ weekly downloads between them. Initial access was a compromised GitHub account rather than a stolen npm token: poisoned commits went into the maintainer’s repos, and the projects’ own release workflows published them through OIDC trusted publishing with valid provenance attached, so provenance checks passed. The payload harvested more: npm and GitHub tokens, AWS, GCP and Azure keys, Vault secrets, and 300+ patterns including Anthropic, OpenAI and Gemini API keys.

Manchester Airports Group disclosed a breach affecting 8.7M customers, most of whom had only an email address exposed. Extortion group FulcrumSec says it pulled the data using live Iterable API keys that MAG shipped in its own client-side JavaScript, and independent analysis found those keys in the public bundles going back to 2022. MAG has not confirmed the root cause.

McKesson disclosed a breach on Aug 28 after vishing calls got attackers into employee Okta accounts, and from there into Salesforce and Snowflake. ShinyHunters claims 284M records, though it says that figure counts raw rows rather than people.

Source | The Register · SecurityWeek · BleepingComputer

The pattern across the month.

June and July were largely focused on key compromises, while August focused on inputs. At Tectonic and Moonwell, every contract did exactly what it was written to do, but the price it was told to trust was wrong.

Three things belong on the review list this month:

Price feeds are code. A lending market that accepts a governance token with $305K in weekly volume as collateral is making a solvency bet on that token's liquidity. Check what a feed costs to move, not just where it comes from. DefiLlama has recorded 37 oracle and price-manipulation incidents in 2026. All of 2025 had 17.

Governance is an execution path. Term Finance's attacker never broke a contract. They bought the right to change one. Quorum thresholds, timelocks and proposal scope belong in the audit at the same depth as the vault logic.

Shared dependencies inherit each other's disclosure failures. A researcher found the Cosmos EVM bug in April and it got cleared. Six chains paid for that call in August. If you ship on shared infrastructure, you also ship its patch process, and you need to know how fast you can coordinate a state-breaking upgrade before you need to.

One last note on the rollbacks. Cronos reversed $111.2M, and Harmony reverted to a checkpoint just before an attacker used a cross-shard bug to forge roughly 3 trillion ONE on Aug 11. Both worked. Both were also a validator set choosing which state to keep, which is a different security model than the one most users think they have. Say that out loud rather than filing it under incident response.

Disclaimer

This report aggregates publicly reported information as of the publication date and may be revised as investigations evolve and post-mortems are released. Recommendations are general guidance. Verify against primary sources before acting on any specific claim.

About This Series

Quantstamp publishes the Security Beat monthly. We've conducted 1,300+ audits and secured $500B+ in digital assets across 250+ clients, including Ethereum Foundation, Aave, Polymarket, Ethena, Visa, OpenSea, Maker, Curve, Compound, and Lido. If you'd like to chat about anything security or request an audit, reach out.

Back
Quantstamp Announcements

July Security Beat: Keys Over Code (Again?)

Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email. Here's the month in security 👇

Read more
Quantstamp Announcements

June Security Beat: Keys Over Code

$75.32M was lost across 32 crypto incidents in June, up from May's $59.52M. No coordinated campaign carried the month, but one targeted operation did. A targeted social-engineering attack against Humanity Protocol reached the keys behind the $H token and drained $32M, roughly 42% of every dollar lost in June. Quantstamp led the independent investigation and traced the tooling to a phishing campaign previously seen targeting macOS users. Offchain, a fresh npm supply chain wave hit Red Hat's packages on the first day of the month, and a PeopleSoft zero-day was exploited for two weeks before Oracle said a word. Here's the month in security 👇

Read more
Quantstamp Announcements

May 2026 Security Beat

$59.52M was lost across 29 crypto incidents, down sharply from April's ~$635M. No single hack carried the month. The bigger story happened off-chain, where a self-propagating npm worm called Mini Shai-Hulud kept resurfacing in new waves through the month, ultimately spanning more than 1,000 malicious package versions across the npm ecosystem.

Read more