TLDR
August 2026 saw 50 significant crypto security incidents, a record monthly count, even as estimated losses fell to around $136 million.
- Blockchain firm PeckShield logged 50 major hacks in August, up 67% from Julys 30, while estimated losses dropped from about $270 million to $136.3 million.
- One exploit at Tectonic on Cronos accounted for roughly $74 million, with smaller attacks on Moonwell, Term Labs, Coinsbuy, TAC and others making up the remaining losses.
- The data shows more frequent but smaller hacks, while separate wallet and data breaches highlight a widening attack surface that users and protocols need to treat as an ongoing structural risk.
Deep Dive
1. August Hack Numbers
PeckShield reported that August 2026 recorded a record 50 major crypto hacks, up from 30 in July and 40 in each of April, May and June. That is a 67 percent jump in incident count month on month.
Despite the surge in attacks, estimated losses fell 49.5 percent, from roughly $270 million in July to about $136.3 million across 50 incidents. Average loss per hack dropped to around $2.7 million in August compared with about $9 million in July.
A separate summary based on PeckShieldAlert data reached similar figures, noting that crypto security losses totaled $136 million across 50 incidents, covering both protocol exploits and phishing.
Attackers are hitting the ecosystem more often, but many incidents are mid size rather than megascale; the risk is structural, not limited to one chain or protocol.
2. Key August Exploits
The months largest loss came from the Tectonic lending protocol on Cronos (CRO), which PeckShield estimated at about $74 million, more than half of Augusts stolen funds. Validators halted Cronos and later rolled back the chain, leaving most assets trapped.
Other notable protocol level incidents included Moonwell on Base at $8.7 million, Term Labs at $8.5 million, Coinsbuy at $7.9 million and TAC at $7.5 million, plus smaller exploits affecting Injective, mantra/">MANTRA, BounceBit, Cosmos Labs and Aquifer. Together, the top ten hacks accounted for over $120 million, with roughly $12 to $13 million spread across dozens of smaller incidents.
This concentration means many projects suffered relatively small but still material hits, while a single lending exploit dominated the dollar impact.
For users and protocols, big lending and DeFi platforms remain key systemic risk points, but small caps and niche apps are also frequent targets.
3. Risks And What Next
August also saw serious infrastructure and data incidents, including a Coinkite hardware wallet firmware flaw that enabled remote seed guessing and multi million Bitcoin thefts, plus data breaches at Trezor, SafePal and Bits of Gold that exposed hundreds of thousands of customer records. These events attack wallets, logistics providers and analytics tools rather than smart contracts.
Security firms like Immunefi and TRM Labs note a broader trend in 2026 of rising hack counts but lower total losses than in prior years, as more value is spread across many protocols and preventive measures occasionally cap damage. At the same time, physical and identity risks are increasing as breaches expose verified crypto holders and addresses.
For the rest of 2026, the key signals to watch are governance and oracle designs in DeFi, bridge security, hardware wallet and vendor disclosures, and whether incident response continues to limit net losses when exploits occur.
Conclusion
Augusts 50 incidents show that crypto security risk is intensifying in frequency even as average losses per attack fall. One large DeFi exploit, many smaller hacks and several infrastructure breaches together underline that both protocol design and the wider service stack around crypto remain vulnerable. For crypto users and builders, the takeaway is to treat security as a continuous process across contracts, wallets, vendors and user behavior rather than a one off audit or checklist.
