August became a record month for the number of hacker attacks on cryptocurrency projects: 50 incidents were recorded. However, despite the increase in the number of breaches, the total damage fell to $136.3 million — 49.5% less than in July. A paradoxical trend that requires close analysis.

My data, based on blockchain security monitoring, shows that attackers are acting more actively, but their "catch" is becoming more modest. While April, May, and June each saw 40 attacks per month, this figure rose to 50 in August. For comparison, January, February, and March saw only 16, 15, and 20 incidents, respectively.

The largest hack of the month

The main event of August was the incident involving the Cronos network. The victim was Tectonic, the largest lending protocol on that blockchain. The attacker managed to withdraw about $74 million, making this attack the fourth-largest in terms of losses for the entire 2026 year. Notably, the hacker was only able to convert about $6 million into Ethereum (ETH) before validators urgently halted the network.

According to my observations, the hacker began laundering the stolen funds by transferring them through a bridge to the BTC network — at that time, it was approximately 200,000 BTC. Cronos developers promptly rolled the network back to its state before the attack and resumed block production.

The number of attacks is rising, the average damage is falling

The average damage per attack in August was $2.7 million, compared to about $9 million in July. The top 10 incidents accounted for $123.34 million, while the remaining 40 attacks brought hackers only about $12.9 million. This suggests that most breaches are becoming less "lucrative," but their frequency is steadily increasing.

April remains the "blackest" month of the year: total damage then reached $646.89 million, mainly due to massive attacks on Drift and KelpDAO, which brought attackers approximately $577 million.

Among other notable losses in August, Moonwell lost $8.7 million, Term Labs — $8.5 million, Coinsbuy — $7.9 million, and TAC — $7.5 million. The top ten largest hacks also included incidents involving Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.

My expert view: The decline in average damage is a positive signal, but it should not be reassuring. The rise in the number of attacks indicates that hackers are adapting and seeking weaker targets, especially in DeFi protocols. The industry needs to strengthen smart contract audits and implement more robust real-time monitoring mechanisms, otherwise August's record could be broken as early as September.