Web3 August Security Report: 29 Major Security Incidents Resulting in Over $68.29 Million in Losses
In August 2026, the major cause of significant security incidents was contract vulnerabilities, with 18 incidents due to contract/network vulnerabilities and 2 incidents due to private key leaks. Smart contract security and private key management remain weak points in Web3 security.
Written by: Beosin
According to monitoring data from the Beosin Alert platform, in August 2026, the total loss from various security incidents amounted to approximately $76.15 million, with a total of 29 major security incidents occurring, primarily due to contract vulnerabilities. Among these, there were 18 incidents due to contract/network vulnerabilities and 2 incidents due to private key leaks. Smart contract security and private key management continue to be weak points in Web3 security.
Top 10 Losses in August
On August 13, a personal user address 0x13e3....179e lost WBTC, cbBTC, LDO, USDS, CRV, and other crypto assets due to a private key leak, with a total loss of approximately $25.6 million, making it the incident with the highest actual loss. On August 30, the lending protocol Tectonic on the Cronos network suffered a hacker attack due to a contract vulnerability, with an estimated loss of about $74 million. This attack led the Cronos network to take emergency measures, pausing the network and rolling back transactions. The hacker ultimately transferred approximately $6 million to the Ethereum network through cross-chain transactions.
Additionally, the Harmony public chain had approximately 4 billion ONE tokens minted due to a vulnerability, with a nominal loss exceeding $4 million, but the status of the forged tokens was cleared through transaction rollback, so it is not counted as a loss.
Types of Attacked Projects and Losses by Chain
This month, the attacked targets included various types such as public chains, lending protocols, wallet applications, token contracts, cross-chain bridges, and individual users. Among them, DeFi projects suffered the most significant losses, totaling up to $33.09 million; while personal addresses lost approximately $28.4 million due to private key leaks or phishing. Token contracts were attacked the most frequently, with a total of 10 attacks; DeFi contracts were attacked 9 times, ranking second.
The chain with the highest loss in May was Ethereum, with losses exceeding $48.58 million and a total of 15 security incidents. Currently, most DeFi protocols and phishing attacks targeting whales are still primarily on Ethereum. The second most frequent chain for security incidents is BNB Chain, but the attack targets are mainly token contracts, resulting in smaller losses. Additionally, security incidents occurred on public chains such as Cronos, Base, Harmony, Bitcoin, and Solana, showing a multi-chain attack trend.
Analysis of Major Security Incidents
1. Tectonic and Moonwell: Price Manipulation
Tectonic and Moonwell are on-chain lending protocols, and the reason for the attacks was the manipulation of the prices of certain illiquid token collateral, allowing attackers to borrow excessive assets at inflated asset values for profit. In the Tectonic attack, the attacker inflated the price of Tectonic's governance token $TONIC by 100 times, obtaining a borrowing limit of approximately $74 million, and then borrowed assets such as USDT. After the incident, the Cronos network urgently paused the entire chain from block production, and the attacker transferred approximately $6 million to Ethereum before the network was paused. Subsequently, the Cronos network rolled back to recover losses.
The hacker's Ethereum profit address: 0xc404160B79BD8905061a1cAecBeCa2EEab3f72DD and the flow of stolen funds:
Currently, approximately 2659 ETH remains in 0xc4041, and 140.1 ETH was transferred to 0x6df89c42f0abdfaa2b5b77edcdafbc945ed6ee6c and then further dispersed to multiple newly created addresses.
Moonwell was attacked because the attacker manipulated the price of the illiquid MAMO token to borrow cbBTC, resulting in a loss of approximately $8.7 million:
These two attacks were not based on smart contract vulnerabilities but were due to the protocol itself mispricing collateral from weak spot liquidity, incorrectly calculating the value of the collateral. To prevent such attacks, protocols can obtain data from multiple oracles to get data from different sources and make additional judgments in the case of drastic price fluctuations.
2. Harmony: Replay Attack
Harmony is a Layer 1 that supports sharding, running four shards and transferring assets between them through a receipt-based asynchronous cross-shard mechanism. The source shard generates a cryptographic receipt for outbound transactions, while the target shard is responsible for verifying whether the receipt and its Merkle proof match the signed source block header before recording the transaction, and each receipt can only be used once.
The vulnerability in this attack existed in the legacy part of the Harmony sharding system. Previously, Harmony checked whether the shard receipt had been used by looking at two fields, CXMerkleProof.ShardID and BlockNum,
Since these two fields are outside the signed block header, attackers could modify them without breaking any existing functionality. In this attack, the attacker obtained a cross-shard receipt and modified its ShardID and BlockNum, causing the verifier to recognize it as a brand new receipt. The target shard accepted the modified receipt and recorded it again, while the original shard did not deduct the corresponding assets.
This is a very typical replay attack. For any fields used for "one-time use tokens," they must be part of the signed header certification. When verifying receipts, shard ID and block number should be read directly from the signed block header, rather than trusting unverified fields in the proof structure.
3. Term Finance: Governance Attack
Term Finance is a DeFi fixed-rate lending protocol, with each vault being an ERC-4626 Vault based on Yearn V3 code. The governance of Term Finance's vaults is not based on approval voting but on veto voting. When curators propose parameter change proposals, the governors open a window for LP token holders to raise objections. However, there are serious vulnerabilities in the governance voting threshold settings:
● Lack of absolute vote count or capital minimum: The conditions for proposal approval, isSupportThresholdReached() and isMinParticipationReached(), only check relative proportions rather than absolute vote counts. This means that as long as a relative majority is met, the proposal can pass, regardless of the total number of voters or total capital.
● Extremely low participation: Almost no depositors wrapped their vault shares (tmvETH) into governance tokens (gtmvETH) to participate in voting. This resulted in an extremely low total supply of governance tokens for the relevant vaults.
Attackers exploited the above design flaws to achieve governance attacks on the vaults at a very low cost:
(1) Obtaining voting rights: The attacker exchanged approximately 0.5 ETH for about 0.485 tmvETH vault shares and wrapped them 1:1 into 0.485 gtmvETH governance tokens, obtaining voting rights.
(2) Initiating malicious proposals: When the attacker created the proposal, the contract recorded that the total supply of governance tokens at that time was only 0.535 gtmvETH. This meant that the 0.485 gtmvETH held by the attacker accounted for 90.66% of the total.
(3) Voting and execution: The attacker cast a vote in favor as the only voter. Since there were no opposing votes, the support rate far exceeded the 50% threshold; at the same time, their personal voting power also exceeded the minimum participation threshold (minVotingPower) calculated based on the extremely low total supply.
(4) Withdrawing assets: After the proposal passed, malicious operations were executed to withdraw assets (WETH) from the vault.
The attacker used the same method to breach 6 vaults of Term Finance, causing a loss of approximately $8.5 million.
This attack is also a very typical on-chain protocol governance attack. For on-chain governance, project parties should set the following checkpoints for prevention:
● Set absolute vote count or capital minimum: Governance proposals should not rely solely on relative proportions for approval. A hard threshold based on absolute numbers must be set, such as requiring that the amount of supporting votes must reach a certain amount (e.g., $1 million) or a number of independent addresses.
● Equip time locks with guardians or cancellation paths: Although governance execution usually has delays, this only retains a certain reaction time. Project parties must equip effective guardian mechanisms or proposal cancellation paths for the execution delay period. If malicious proposals are discovered during the delay period, guardians can immediately intervene and cancel them.
● Monitor governance participation: Protocols should establish real-time monitoring of governance participation in each vault. When a vault's total supply of governance tokens or voting participation rate is found to be abnormally low, timely alerts should be issued, and even automatic protective measures should be triggered.
-- Price
Web3 Security Threat Trends
The deepest trend in Web3 security in 2026 is the systemic expansion of attack surfaces. Vulnerabilities are emerging simultaneously at the code level, daily operations, and interactive operations, and relying solely on several security audits or tools cannot cover operational security, on-chain governance, business operation logic vulnerabilities, and other aspects. This poses new challenges for Web3 project parties in building security defense systems.
Additionally, attacks targeting DeFi contracts and individual users are frequent. Contract vulnerabilities or authorizations are easily exploited by attackers, and contract developers or operators should review the security of contracts. For contracts handling core business, multiple and multi-party security audits should be conducted. For individual users, it is advisable to regularly use blockchain explorers or revocation authorization tools to check and cancel unused contract authorizations, and to stay informed about common and new phishing techniques to enhance security awareness.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

BlackRock Executive: Bitcoin Volatility Halved, Shifting from 'Get-Rich Narrative' to 'Collateral Narrative'

Lemon exits Brazil over crypto licensing costs

Banks Monitor Crypto Transfers, No Fixed Limit for Blocking

Ethereum's Next Upgrade May Become the Most Significant Catalyst in History

Web3 Newsletter: Industry Highlights and Must-See Trends This Week

Bitcoin Community Acknowledges Quantum Computing Risk, Says VanEck

South Korea to Build a Chain That Only Recognizes Korean Won, Maroo Incorporates Compliance into Infrastructure

Accelerated Crypto Tax Reform in the U.S.! Who Benefits and Who is Limited?

Dialogue with OneKey's Wang Yishi: In the AI Era, Is the Hardware Wallet's Offensive and Defensive Battle Only 'Two Weeks' Left?

Genius.fun launches BNB Chain platform for corporate ownership

Ned Davis Research Predicts Bitcoin Will Reach $230,000 by 2035

Ethereum EIP-8198 Proposal Reduces Block Time to 10 Seconds

Is the crypto bear market finally coming to an end?

Beware of Scams and Malicious Pools in On-Chain Dog Projects

Ethereum’s client diversity picture fractures under incompatible estimates

龙虾 Airdrop 2026: Trade and Share 50,000 USDT on WEEX

In-depth Analysis of the 630 Companies YC Invested in This Year: The Top 10 Directions It Is Most Optimistic About

Fed Rate Hike 2026: Can Bitcoin Hold $75K as Gold Stays Strong?

The Quantum Issue: To Freeze Coins Or Not

BlackRock Suggests Fed Keep Rates Steady, Focus on Warsh's Speech

Insight WEEX: CLARITY Act Explained as Bitcoin Tests the $75K Level

Trade Daily, Win Daily: How to Share 5,000 USDT and Compete for iPhone Duo on WEEX

Design Flaw in Uniswap v4 Hook? 0x Reveals Over Half of Hooks Exhibit Malicious Behavior

CLARITY Vote Fails; Bitcoin Breaks Below $76,000 | WEEX TradFi Daily Brief (September 16, 2026)
Global markets on September 16 are focused on the Fed rate decision. On September 15, the S&P 500 fell 0.45% to 7,585.73, the Nasdaq fell 0.78%, and the Dow fell 0.63% as the 10-year yield broke above 5% and Brent crude rose to about $109. The CLARITY procedural vote failed to clear the 60-vote threshold, sending bitcoin down to about $75,600 and Ethereum toward $2,400. Energy led with a gain of about 2.3%. Investors are waiting for the 14:00 ET policy statement and Walsh press conference on September 16.

WEEX Exclusive:CLARITY Vote Fails; Bitcoin Breaks Below $76,000 | WEEX TradFi Daily Brief (September 16, 2026)

Whistleblower on Capitol Hill|Rewire News Briefing

Moose Begins Public Testing on Monad

CLARITY Act Fails Its September 15 Senate Vote: What Happens Now
The CLARITY Act failed its cloture vote 46-43, falling well short of the 60 votes needed and lead sponsor Cynthia Lummis says that's effectively the end for 2026.

Ampleforth Proposal 54 Canceled, 98% of USDC Balance Requested










