The week of August 17 to August 23, 2026 delivered another punishing stretch for crypto security, with at least five confirmed on-chain exploits combining to drain more than $13 million in verified direct losses.
The damage was spread across a cross-chain liquidity protocol, a stablecoin bridge, a Bitcoin restaking Layer 1, a metaverse token’s omnichain infrastructure, and a fixed-rate lending protocol’s governance layer. The stretch pushed August’s publicly logged hack count into double digits and extended 2026’s running loss total past $1.26 billion across more than 219 incidents.
What made the week distinctive was not the aggregate dollar figure, which sat well below several individual incidents from earlier in the year, but the diversity of attack surfaces that broke. Every core layer of the modern crypto stack got hit, and no two attacks used the same playbook.
One attacker chained six bugs inside a single transaction to mint tokens out of thin air. Another spent 24 days seeding a forged cross-chain message before firing a flash loan. A third bootstrapped $8.5 million out of a two-ETH deposit routed through Tornado Cash by simply voting on a proposal.
Maya Protocol Loses $1.7M as Six Chained Bugs Collapse CACAO 88%
The first major exploit of the week landed on Tuesday, August 18. At approximately 17:30 UTC, an attacker submitted a single MsgDeposit transaction carrying 23 messages at block 17977941 to MAYAChain mainnet, a THORChain fork that routes native swaps between Bitcoin, Ethereum, Arbitrum, and its own MAYAChain.
That one transaction was enough to trigger a cascade that the Maya team later described in its own post-mortem as a six-bug chain running through the protocol’s trade account and outbound transaction handling logic.
Protocol pseudonymous co-founder Aaluxx Myth confirmed the losses publicly on X within hours. The mechanics were brutal in their elegance. The system first incorrectly classified a legitimate outgoing transfer as missing, which triggered a theft-detection routine, which fired an uncapped slash-subsidy compensation payout. That subsidy credited a low-liquidity pool with roughly 49 million CACAO even though the underlying reserve held only about 168,000 CACAO.
The attacker then claimed the phantom balance with a 100 CACAO deposit, took 99.93% ownership of the pool, and withdrew 48.87 million tokens, nearly half of the total supply.
Confirmed extraction across external chains totalled roughly $1.36 million, with total attacker value approaching $1.7 million. The confirmed haul was largely 20.83 BTC, worth approximately $1.34 million, sent to a single Bitcoin address across roughly 10 blocks. The knock-on damage was worse.
CACAO fell from $0.115 to $0.013 in less than 240 blocks, a nearly 89% drop, and total pool value across the protocol fell by an estimated $10.9 million once liquidity flight was priced in, effectively wiping out Maya’s entire TVL in a matter of hours.
The network remained halted through August 21, and the team opened a bounty offer to the attacker for return of funds. As previously reported by The Crypto Times, cross-chain infrastructure has now driven more than $328 million in losses this year, and Maya is now the second THORChain-family exploit of 2026.
Allbridge’s CCTP Router Bleeds $191,000 in a One-Month Slow Play
Twenty-four hours later, on August 19, a different kind of attack came to fruition on Allbridge, and the setup for it had been in place for nearly a month. According to a detailed post-mortem published by SlowMist, the attacker began laying the groundwork on July 26 by directly calling Circle’s MessageTransmitterV2.sendMessage function on Polygon, constructing a forged CCTP message falsely claiming a 1 million USDC transfer while no actual USDC burn occurred. Circle then generated a valid attestation for the complete message following its standard flow.
That attestation was held in reserve for 24 days. On August 19, the attacker waited until the Base Router received a legitimate CCTP deposit that pushed its balance to approximately 191,000 USDC, and launched the exploit just six seconds later.
Using the previously forged message and its valid attestation to call Allbridge’s receiveCctpMessage function, the attacker was credited with a phantom $1 million receipt due to missing verification on sender identity, message origin, and actual mint amount.
An Aave flash loan then covered the shortfall, and the entire 191,156 USDC balance was drained. The lesson from SlowMist’s writeup was that a valid Circle attestation alone is not authorization, and receiving protocols must independently verify the source-side TokenMessenger and actual mint settlement.
BounceBit Shutters Its Entire Layer 1 After a $3M Authorization Flaw
Almost concurrently with the Allbridge incident, Bitcoin restaking platform BounceBit was quietly bleeding out. Between 21:02 UTC on August 19 and 01:54 UTC on August 20, an attacker executed 14 unauthorized transactions and moved 286,543,148 BB tokens, worth approximately $3 million to $3.3 million, from nine mainnet accounts. Block production was halted at height 20,702,857 at 02:36:37 UTC on August 20.
The root cause was not a compromised key. As BounceBit stated in its official post-mortem, the vulnerability sat inside the Evmos stack the chain was built on. The flaw allowed a smart contract caller to specify a different account as the source of funds without any verification that the account had authorized the transaction. No private key was compromised, no signature was forged, and no wallet, hardware device, or exchange account was breached. The failure was inside the chain’s native authorization module.
The response was unusually drastic. Rather than patch and continue, BounceBit announced it would permanently retire its Layer 1 blockchain and migrate the entire ecosystem to BNB Chain, reissuing BB as a BEP-20 token based on a snapshot taken at block 20,697,260, immediately prior to the first anomalous transfer.
The stated reason was that the underlying Evmos project itself was discontinued in May 2026, making the environment unmaintainable. The 286.5 million BB tokens held by the attacker will be excluded from the new issuance.
The Sandbox Bridge Exploit: 14.9B Unbacked SAND, $675K Real Drain
On Saturday, August 22, metaverse platform The Sandbox got caught by another LayerZero delegate abuse. The vector, first flagged publicly by security firm Blockaid, targeted the SAND cross-chain OFT contract on Base, with a mirrored surface on BNB Smart Chain.
The attacker commandeered LayerZero delegate authorization through an approveAndCall mechanism, enabling unauthorized token creation on Base without corresponding collateral from legitimate SAND reserves locked on Ethereum.
Blockaid’s initial alert flagged approximately $49 billion in face-value SAND minted across more than 400 transactions. PeckShield tagged two attacker addresses that received 14.9 billion SAND in the first visible wave. The genuine drain was several orders of magnitude smaller.
Roughly 14.75 million SAND was extracted from the Ethereum OFT Adapter within 60 seconds, generating approximately 80 ETH in proceeds, equivalent to about $675,000. The unbacked minted supply was effectively unsellable at scale.
The Sandbox confirmed containment on X, disabling bridging to and from Base and BSC, isolating the affected supply, and noting the impact represented under 0.01% of the total SAND supply. Ethereum and Polygon SAND was unaffected.
Bithumb suspended SAND deposits and withdrawals at 11:11 KST on August 22, with Upbit following one minute later under South Korea’s Virtual Asset User Protection Act. As The Crypto Times detailed in its full breakdown of the five-hour rampage, LayerZero OFT peer and delegate abuse has now been the direct or proximate cause of nominal token issuance measured in trillions across at least three separate incidents in 2026.
Term Labs Governance Exploit Drains $8.5M on August 23
The week’s largest single loss landed on its final day. On Sunday, August 23, DeFi fixed-rate lending protocol Term Finance confirmed that an attacker had seized voting control of several strategy vaults and drained roughly $8.5 million.
Term Labs acknowledged the incident on X, describing it as a governance exploit impacting Term Vaults. CertiK’s alert confirmed the attacker wallet held roughly 2,843 ETH (about $6.87 million) and 1.68 million USDC, later swapped for approximately 1.6 million DAI.
The exploit did not touch the code. The attacker gained 100% voting control over four out of five USDC strategy vaults and roughly 91% control of the Ethereum Meta Vault. With that supermajority, the attacker voted to drain the funds. The seed capital was almost comically small: just 2 ETH sourced through Tornado Cash was enough to bootstrap voting power over vaults holding millions in user deposits.
Yearn Finance clarified that while Term Vaults are built on Yearn v3, the exploit occurred through a custom governance wrapper and is not applicable to standard Yearn vault setups. As The Crypto Times covered when BonkDAO lost $20 million in July, this class of exploit does not require any technical wizardry.
Also This Week: Address Poisoning, Coldcard Firmware, and Data Breach Fallout
Alongside the five protocol-level exploits, the week also produced a string of parallel incidents worth documenting:
- Bofur Capital drained of $2 million in address poisoning attack: As The Crypto Times reported, the affected wallet withdrew 2 million USDC from the Compound III market at 16:01:23 UTC on August 21, and roughly 30 minutes later at 16:31:11 UTC transferred the full amount to a lookalike address. PeckShield flagged the incident on August 22, noting the attacker had pre-seeded a dust transaction a full day earlier from an address that mimicked a known counterparty. The stolen USDC was instantly swapped to DAI to break the on-chain paper trail.
- Coldcard ships firmware 5.6.1 as the $130 million drain continues: Coinkite released firmware versions 5.6.1 for the Mk4 and 1.5.1Q for the Q on August 20, adding required user-sourced entropy during seed generation, transaction-integrity checks, and stronger randomness handling. The release does not retroactively fix wallets that generated seeds under the vulnerable firmware. As The Crypto Times covered when Coinkite CTO Peter Gray was linked to the flawed libngu code, affected users must migrate seeds to unaffected hardware. Most of the stolen 1,816 BTC continued to sit at attacker-controlled addresses with minimal laundering activity through the week.
- SafePal data breach fallout continues: The hardware wallet maker’s disclosure of an authorization flaw in an order-tracking plug-in that exposed personal information from 39,798 customers, covering orders placed between March 2, 2025 and April 11, 2026, continued to drive phishing risk through the week. Private keys, seed phrases, and payment information were not affected, but names, addresses, phone numbers, and shipping details were.
- CACAO price crash spillover: Beyond Maya Protocol’s direct $1.7 million loss, the CACAO price collapse imposed roughly $9.2 million of additional pool-value destruction on liquidity providers and arbitrageurs who absorbed the sell-off, taking effective damage past $10.9 million.
- BounceBit L1 permanent shutdown announced: Beyond the $3 million direct loss, the wider consequence was the retirement of an entire Layer 1 chain, one of the most consequential cascading failures traced to the discontinuation of an EVM stack in 2026 to date.
Conclusion
Aggregating everything between August 17 and August 23, direct on-chain losses tally to roughly $15.4 million across confirmed incidents, made up of $1.7 million at Maya Protocol, $191,000 at Allbridge, $3 million at BounceBit, $2 million at Bofur Capital, $675,000 at The Sandbox, and $8.5 million at Term Labs.
That figure does not price in Maya’s second-order $9.2 million pool-value collapse, nor the structural cost of an entire Layer 1 announcing its own retirement mid-week, nor the ongoing bleed from the Coldcard firmware flaw that has now crossed $130 million in cumulative losses. The week’s real signal is not the dollar total but the vector variety.
Bridges failed on message verification, chains failed on native authorization, metaverse tokens failed on delegate configuration, governance systems failed on voter concentration, and institutional wallets failed on the last seven characters of an Ethereum address. With more than four months of 2026 still to go, the year is already running significantly ahead of 2025’s incident count, and no single hardening effort will stem this variety of failure modes.
Also Read: Phantom to Drop Sui Network on Sept 24: Migration Window Opens for Holders
