August became the "hottest" month of 2026 in terms of the number of crypto project hacks: 50 major incidents were recorded. However, despite the record number of attacks, the total damage fell to $136.3 million — 49.5% lower than July's figures.

My observations of the market show that we are witnessing an important structural shift. Hackers are attacking more often, but their "effectiveness" is declining. This suggests that the industry is gradually learning from its mistakes, and defense mechanisms are becoming more efficient.

The largest hack of the month

The main event of August was the incident involving the Cronos network. Tectonic, the largest lending protocol on this blockchain, was attacked. The attackers managed to withdraw about $74 million, making this hack the fourth largest by volume for the entire year of 2026.

Notably, the hacker managed to convert only about $6 million into Ethereum (ETH) before validators urgently halted the network. According to my data, the attacker has already begun laundering funds, transferring them through a bridge to the BTC network — at that point, it was approximately $200,000.

Cronos developers promptly rolled the network back to its state before the attack and resumed block production. This is an example of competent crisis management, which, unfortunately, is still rare in the industry.

The number of attacks is rising, the average damage is falling

August's 50 incidents surpassed the figures for April, May, and June, when 40 attacks were recorded monthly. January, February, and March were significantly calmer — 16, 15, and 20 hacks, respectively.

Number of hacks in the cryptocurrency industry by month in 2026.
Number of hacks in the cryptocurrency industry by month in 2026.

The average damage per attack dropped to $2.7 million, compared to about $9 million in July. The top 10 incidents accounted for $123.34 million, while the remaining 40 attacks brought hackers only about $12.9 million. This confirms that major targets are becoming less accessible.

April remains the "costliest" month of the year with damage of $646.89 million — mainly due to the Drift and KelpDAO hacks, which together cost approximately $577 million.

Among other notable victims in August are Moonwell, which lost $8.7 million, Term Labs with $8.5 million, as well as Coinsbuy ($7.9 million) and TAC ($7.5 million). The top ten also included attacks on Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.

My conclusion: the decline in average damage amid a rise in the number of attacks is a positive signal, but not a reason for complacency. Projects need to strengthen smart contract audits and implement emergency stop mechanisms, as Cronos did. Otherwise, we risk seeing a new "black April" at any moment.