Blockchain security firm CertiK said on August 31 that confirmed incidents in August 2026 produced approximately $215 million in losses, of which roughly $41.5 million was attributed to phishing.
The smart contract auditor and security firm noted on X that DeFi accounted for $144.6 million of the month’s total. About $110.7 million in funds were later classified as returned or frozen, leaving a large share of the headline figure still in dispute or locked on-chain.
The August tally arrives after CertiK’s Hack3D H1 2026 report recorded $1.32 billion lost across 344 incidents in the first half of the year. That half-year figure was lower than H1 2025 on a raw basis because 2025 included the $1.45 billion Bybit theft; adjusted for that outlier, CertiK said comparable losses were higher in 2026.
The firm also said 2026 has already seen more losses from code vulnerabilities than some prior full-year totals, though August itself was dominated by a different category.
Price Manipulation Drove Most August Losses
CertiK’s August breakdown put price manipulation at $131.6 million, phishing at $41.5 million, code vulnerabilities at $20.6 million, wallet compromise at $11.8 million and governance incidents at $8.5 million. The single largest line item was Tectonic, listed at $120.4 million, which happened on August 30.
Tectonic is the largest lending protocol on Cronos, a Crypto.com-linked chain. On August 30, Cronos halted the network after an attacker inflated the thinly traded TONIC token by about 100 times in roughly 20 minutes and borrowed against the higher collateral value. Independent reporting put attacker proceeds near $74–75 million, with only about $6 million bridged to Ethereum before validators paused the chain. Tectonic’s total value locked fell from about $121.7 million to near $3 million, which helps explain why CertiK’s impact figure is higher than the amount that left the network. Crypto.com said its exchange and app were unaffected.
Moonwell on Base lost an estimated $8.7 million on August 27 after similar collateral-price inflation of the illiquid MAMO token. CertiK, PeckShield and Blockaid converged on that range. Several post-mortems said no smart-contract bug was required; the protocol priced collateral from thin spot liquidity.
On August 23, Term Finance suffered a separate governance exploit of about $8.5 million. Smaller August names on CertiK’s graphic included Coinsbuy ($7.9 million) and Fogo ($3.9 million).
The classification matters. A reply to CertiK’s alert argued that large lending losses such as Tectonic and Moonwell executed as written: illiquid collateral, a moving price, and a borrow that cleared. That view matches contemporaneous coverage describing “Mango Markets-style” pump-and-borrow attacks rather than broken code. CertiK still grouped most of August’s dollar damage under price manipulation, not code vulnerability.
Recovery Rates and the Broader 2026 Pattern
CertiK listed $110.7 million as returned or frozen in August. The Cronos halt is the clearest example: most Tectonic proceeds never left the chain. That does not automatically mean depositors will be made whole. Neither Cronos nor Tectonic had published a restart plan or compensation policy when the monthly alert was issued.
Incident counts have climbed through 2026 on CertiK’s monthly charts, with August the highest bar so far. H1 data already showed a split: code bugs produced the most incidents (204), but far less money drained ($152 million) than wallet compromises ($445 million) or phishing ($366 million). August inverted the H1 money ranking. Manipulation of low-liquidity tokens used as collateral, not novel contract flaws, produced the month’s biggest check.
But not every trackers agrees on the exact figure. TRM Labs counted fewer H1 incidents and a lower loss total than CertiK. Tectonic’s $75 million “escaped or frozen proceeds” figure and CertiK’s $120 million “incident impact” figure can both be true depending on whether TVL collapse and bad debt are included. Readers comparing headlines should treat those definitions as distinct.
The practical pattern is consistent. Protocols that accept thinly traded tokens as collateral with spot or weakly lagged oracles remain exposed even when audits find no classic vulnerability. Phishing remains a large, separate drain.
Chain-level emergency pauses can trap funds, but they also underline how much “decentralized” lending still depends on a small validator set willing to halt production. August’s $215 million is therefore less a story of new bug classes than of known market-structure risk repeating at larger scale.
Also read: Justin Sun Says HTX Hit by DDoS Attack, User Funds Unaffected
