August was an anomalous month for crypto industry security: 50 major hacks were recorded — an absolute record for the entire year of 2026. However, the paradox is that the total damage plummeted to $136.3 million, which is 49.5% lower than July's figures.
Largest incident of the month: the attack on Tectonic
The main event of August was the attack on the Tectonic protocol, operating within the Cronos ecosystem. It is the largest lending protocol on this blockchain, and the attackers managed to withdraw about $74 million. This theft became the fourth largest in volume for the entire year of 2026.
Notably, the hacker managed to convert only about $6 million into Ethereum (ETH) — the network was promptly halted by validators. During the investigation, it was revealed that the attacker began laundering funds by moving them through a bridge to the BTC network (approximately 200,000 at the time of the incident). Cronos developers rolled the network back to its pre-attack state and resumed block production.
Frequency rises, profitability falls
August's 50 incidents significantly exceeded the figures for April, May, and June, when 40 attacks per month were recorded. At the beginning of the year, the dynamics were more modest: January — 16 hacks, February — 15, March — 20.
The average damage per attack dropped to $2.7 million, compared to about $9 million in July. At the same time, the top 10 incidents brought hackers $123.34 million, while the remaining 40 attacks accounted for only about $12.9 million. This indicates that large targets are becoming less accessible, and attackers are forced to spread their efforts across smaller projects.
April remains the most "lucrative" month for hackers: the damage amounted to $646.89 million, mainly due to attacks on Drift and KelpDAO, which brought attackers about $577 million.
Other notable losses
In August, Moonwell ($8.7 million), Term Labs ($8.5 million), Coinsbuy ($7.9 million), and TAC ($7.5 million) also suffered. The top 10 largest hacks included incidents involving Injective, MANTRA, BounceBit, Cosmos Labs, and aquifer.
My analysis: The trend toward an increasing number of attacks with a declining average damage is a positive signal for market maturity. Projects have become faster at responding to incidents, and validators more effective at blocking fund withdrawals. However, the record number of hacks serves as a reminder: the attack surface is expanding, and smaller protocols remain the weak link. Investors should prioritize security audits and risk insurance when choosing DeFi platforms.