Crypto hacks jumped 67 percent in August, with security firm PeckShield counting 50 major incidents — up from 30 in July — although estimated losses fell by nearly half to 136.3 million USD, because a single incident, the Tectonic lending exploit on Cronos, absorbed more than half of the month’s damage on its own.
By Priya Sharma | September 1, 2026
The Hook: More Attacks, Less Stolen
PeckShield reported on September 1 that it recorded 50 major incidents during August, a 67 percent increase from the 30 incidents counted in July. Yet estimated losses reached 136.3 million USD, down 49.5 percent from approximately 270 million USD the month before, according to crypto.news. The figures are estimates and may shift as affected projects investigate transactions, freeze assets, or recover funds.
The takeaway is two-sided: attackers are probing more targets more often, but fewer mega-thefts are getting through — with one glaring exception.
The Evidence: Tectonic Dominated the Month
The Tectonic lending incident accounted for approximately 74 million USD, or more than half of PeckShield’s total. Security researchers estimate that an attacker manipulated collateral pricing and borrowed assets against it — a classic oracle-style attack, where the machine that reports an asset’s value is tricked into overvaluing collateral so the attacker can drain loans. Excluding Tectonic, the remaining 49 incidents combined for roughly 62.3 million USD in estimated losses.
PeckShield’s top ten for August, by estimated loss:
- Tectonic — approximately 74 million USD (Cronos lending protocol)
- Moonwell — 8.7 million USD
- Term Labs — 8.5 million USD
- Coinsbuy — 7.9 million USD
- TAC — 7.5 million USD
- Injective — 4.8 million USD
- MANTRA — 3.6 million USD
- BounceBit — 3 million USD
- Cosmos Labs — 2.87 million USD
- Aquifer — 2.47 million USD (Solana AMM)
These should not be read as final net losses. Security firms classify incidents differently, particularly when funds remain traceable, frozen, or recoverable, and projects routinely revise their numbers after technical reviews.
The Core Conflict: One Big Breach Versus a Thousand Cuts
Tectonic disclosed the incident on August 30 and warned users not to interact with the platform while its team investigated. Cronos validators stopped block production after detecting the active exploit — a dramatic but effective emergency brake. PeckShield ranked Tectonic as the fourth-largest cryptocurrency theft of 2026 so far, behind attacks involving Drift, KelpDAO and LayerZero, and hardware-wallet provider Coldcard.
Crypto.com CEO Kris Marszalek moved quickly to contain the fallout, confirming that the incident affected Tectonic — a separate decentralized protocol operating on Cronos — rather than Crypto.com’s centralized exchange or app, and saying his company’s security team was assisting the investigation. The distinction matters for anyone who conflates a chain’s DeFi ecosystem with the companies built around it.
Zooming out, the problem is structural. A recent CoinGecko study found that crypto platforms lost 3.63 billion USD across 245 incidents between January 2025 and July 2026, with the ten largest incidents accounting for more than 72.5 percent of the total. In plain terms: the industry’s losses are not death by a thousand cuts — they are a handful of catastrophic failures that better risk controls could have prevented.
Market Implications: What This Means for DeFi Users
For anyone lending, staking, or parking savings in DeFi protocols, August is a reminder of three practical rules. First, size matters — the biggest single loss came from a lending market where one manipulated price cascade drained tens of millions, so diversifying across protocols limits your exposure to any one failure. Second, check whether a protocol’s collateral pricing relies on a single oracle or a hardened, multi-source feed. Third, speed of response counts: Cronos halting blocks and Tectonic’s rapid warning likely capped the damage compared with slower incidents elsewhere.
The falling dollar total even as incident counts rise also suggests monitoring and recovery are improving — more attacks are being caught early enough to keep losses contained.
The Verdict: Safer Trend, Real Tail Risk
August’s numbers are directionally encouraging — total losses nearly halved month over month — but the Tectonic exploit shows the tail risk in DeFi remains brutal. Until oracle manipulation and collateral-pricing attacks become structurally harder, treat any yield above mainstream rates as compensation for exactly this kind of event. One incident can still eat half a month’s losses in a single afternoon.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
50 incidents vs 30 in july and somehow losses dropped by half. attackers are spraying more and landing smaller, that tracks with all the copy-paste contracts out there
The Tectonic exploit alone absorbed more than half of the 136 million. One lending protocol on Cronos doing that much damage puts the rest of the month into perspective.
^ as a tectonic user this one stings. been saying their oracle setup looked shaky for weeks lol
Fewer dollars stolen is good news until you remember 136 million is still gone. hard to celebrate a down month for crime
these numbers always get revised upward later once projects actually count what they lost. check back in a month, that 136.3M will be closer to 180
july started near 270m and crept up too. the first peckshield snapshot is always the floor, never the ceiling
july sat near 270m and kept crawling upward for weeks after the first snapshot. 136.3 is just the opening draft of august
50 incidents in one month and somehow losses dropped to 136m. tectonic really ate half the bill alone lol
tectonic was like 60%+ of the entire figure, the rest is pocket change attacks
one cronos lending protocol eating 60% of the whole month and people still aped into the next copy paste fork the same week lol
one cronos lending protocol out of 50 incidents doing 60% of the damage tells you the long tail is mostly noise and copy-paste contracts
one cronos protocol being 60 percent of losses also means the other 49 averaged under 1.2m each. noise tier for insurers but carnage for the teams hit
Fifty incidents in one month is grim reading. The Tectonic exploit on Cronos doing more than half the damage says most of the other hacks were small, sloppy jobs.
Or teams are simply getting faster at freezing funds. PeckShield itself warns the estimates shift as recoveries happen.
30 to 50 incidents in a single month is the real headline. small teams shipping unaudited forks faster than auditors can read them