Security News
Recent exploits and disclosures across EVM/DeFi. For deep breakdowns, see Security Research.
KiiChain loses 148M+ KII tokens across 18 wallets in unexplained exploit
KiiChain, an EVM-compatible Layer 1, suffered an exploit draining 148,326,583.15 KII tokens spread across 18 separate wallets. Root cause has not been publicly disclosed. Rekt.news published coverage on September 2, 2026.
Notional Finance escrow contract drained for ~$1.73M via integer overflow in collateral check
On September 3–4, 2026, an attacker exploited an unsafe `int256 → uint128` downcast in Notional Finance's free-collateral calculation: calling `mintfCashPair()` twice created a -2^128 liability that the cast silently truncated to zero, letting the attacker borrow against a fabricated collateral-free position. The attacker exfiltrated 69,242 DAI + 1,658,423 USDC (≈689 ETH) via Tornado Cash.
Cozy Finance hit by two separate exploits on Optimism, losing ~$330K total
On September 7, 2026 two independent attackers struck Cozy Finance on Optimism: the first submitted a fraudulent UMA Optimistic Oracle price proposal that passed unchallenged, triggering ~$160K in fake insurance payouts; a separate attacker then drained an additional ~$170K in a 13-minute bridge-and-exit sequence. This is the protocol's second significant Optimism incident, following a ~$427K exploit in August 2025.
Cronos Post-Mortem: $9.19M Permanently Lost After Tectonic Oracle Attack and Chain Rollback
Cronos validators published their final post-mortem on September 8, 2026 for the August 30 Tectonic Finance exploit, confirming that $9.19M remains unrecovered after the chain rolled back 10,961 blocks to recoup $111.2M. The attacker pumped TONIC's governance token 100× to borrow against inflated collateral in a textbook thin-liquidity oracle manipulation.
Liquid Network Loses ~$320M in BTC to Range-Proof Cache Bug; ~$47M Net After Partial Return
On September 6, attackers exploited two chained bugs in Elements' CachingRangeProofChecker to prime Liquid federation nodes into accepting an invalid block that fabricated L-BTC and triggered a 3,998.67 BTC peg-out from the federation wallet. Blockstream halted transactions, patched nodes, and recovered ~3,400 BTC; the attackers kept ~598.5 BTC (~$47M) as a self-declared bounty. The deployed patch fixes Bug A but leaves Bug B unresolved.
Liquid Network Hit for $320M via Range-Proof Cache Bug; Attacker Returns 85%
On September 6–7, 2026, ~4,000 BTC (~$320M) were drained from Liquid Network's federation wallet through a cache-key collision in Elements' range-proof verification code that omitted asset context, allowing the attacker to mint unbacked L-BTC. Blockstream patched affected bridge nodes on September 7; the attacker returned ~3,401 BTC and retained ~598.5 BTC (~$47M), claiming white-hat status.
September Week-1 Crypto Hacks Total ~$322M; Liquid Network's $320M Dominates
Publicly reported exploits between September 1–7, 2026 reached ~$322M across four confirmed on-chain drains on Ethereum, BNB Chain, XRP Ledger, and the Liquid Network/Bitcoin sidechain. The Liquid Network incident alone accounts for 99% of the week's losses; the three remaining EVM/smart-contract drains (including the Notional Finance V1 exploit) collectively totalled ~$2.3M.
Liquid Network Loses ~$320M in BTC After Elements Software Bug; Hackers Claim White-Hat Status
On September 6–7, 2026, roughly 4,000 BTC (~$320M) — about 95% of the Liquid Network's holdings — were drained through a software bug in Blockstream's Elements framework, moving funds via the SideSwap trading platform. The perpetrators publicly offered to return most funds through Bitcoin transaction messages, conditional on the vulnerability being patched first; Liquid halted new transactions while investigating. Note: Liquid is a Bitcoin sidechain, not an EVM contract, but the incident highlights federation/multisig trust model risks relevant to cross-chain bridge design.
Tectonic/Cronos Price Manipulation: ~$75M Attempted, ~$69M Recovered via Chain Rollback
An attacker pumped the TONIC token ~100× in 20 minutes on thin markets, deposited inflated collateral on the Tectonic lending protocol on Cronos, and borrowed liquid assets. Cronos validators halted the chain and rolled back state, recovering ~$69M before bridging; the incident triggered a September 6 report on surging DeFi price-manipulation exploits and highlighted risks of permissive collateral parameters for low-liquidity tokens.
Royal.io Legacy Contract Loses $263K to Flash Loan + ERC1155 Zero-Value Transfer Exploit on Polygon
Attackers exploited Royal.io's abandoned Royal1155LD contract on Polygon by combining a flash loan with 100 zero-value ERC1155 self-transfers to inflate reward balances in the `beforeLdaTransfer` hook, draining ~$263K USDC from the legacy reward pool. Active Royal.io V2 contracts were unaffected.
Liquid Network Loses ~$320M in Largest Bitcoin Sidechain Exploit on Record
A software bug in Elements (the open-source code powering the Liquid sidechain) allowed attackers to drain ~4,000 of the federation's ~4,200 BTC (~$320M) via SideSwap. Perpetrators sent an on-chain message claiming white-hat status and offering conditional return of funds; Blockstream has not confirmed any return as of September 7. The network halted new transactions while federation members patched the vulnerability.
FloorDAO (Olympus Fork): ~$16K Drained via stake() Wrong-Destination Logic Bug on Ethereum
On September 5, 2026, a logic bug in FloorDAO's stake() function routed funds to msg.sender instead of the intended warmup contract; an attacker cycled stake/unstake to drain ~$16K. The incident is a recurring pattern in OHM-fork codebases where fund-routing targets are misconfigured post-fork.
Liquid Network Drained of ~$320M via Elements Rangeproof Cache Bug (September 6, 2026)
On September 6, 2026 at 14:06 UTC, a rangeproof cache bug in the Elements protocol — where the cache key omitted asset type and output script context — let attackers mint ~3,996 unbacked L-BTC and peg them out for real Bitcoin. Self-described white hats claimed responsibility; Liquid halted all bridge nodes and exchanges suspended L-BTC trading. A patch had been merged to the Elements repo but was not yet in a tagged release.
Tectonic $75M Price Manipulation Prompts Cronos Chain Halt and Rollback
An attacker manipulated TONIC's spot price ~100x via a $1.34M liquidity pool and borrowed ~$75M in real assets from Tectonic lending protocol on Cronos (Aug 30). Validators halted the entire blockchain and rolled back 11,000+ blocks; ~$6.65M crossed to Ethereum before the halt, with 2,659 ETH laundered via Tornado Cash on September 3.
Notional Finance V1 Drained $1.73M via unsafe uint128 Downcast in Legacy fCash Escrow
On September 4, 2026, an attacker exploited an integer overflow in Notional Finance's legacy V1 escrow contract: calling `mintfCashPair()` twice created a combined fCash liability of exactly 2^128, which an unsafe `uint128()` cast truncated to zero — making the attacker appear debt-free and allowing a full borrow of 69,257 DAI + 1,658,524 USDC (~$1.73M). Stolen funds were swapped to ~689 ETH and deposited into Tornado Cash within 80 minutes.
DeFi Lending Records 32 Price-Manipulation Attacks in 2026, a Sector Record — Tectonic the Most Recent
A September 6, 2026 analysis found that DeFi lending protocols have absorbed 32 price-manipulation exploits so far in 2026, roughly one in eight of all crypto hacks this year, with Tectonic's $75M Cronos attack the most recent and dramatic. The article flags that low-liquidity collateral tokens without TWAP-based pricing remain the common thread across the attack wave.
Term Finance Loses $8.5M as Attacker Buys Cheap Governance Majority to Drain Yearn v3 Strategy Vaults
On August 23, 2026, an attacker funded with just 2 ETH via Tornado Cash accumulated majority voting power in Term Finance's sparsely held governance token and passed proposals to drain 2,843 ETH and 1.68M USDC from strategy vaults built on Yearn v3 infrastructure — all without touching any audited contract code. Term Labs permanently shut down Meta Vault deposits, revoked all DAO governance roles, and pledged a full post-mortem.
Term Labs Governance Capture: Attacker Buys 90.66% Vote Share for $951, Drains $8.5M
On August 23, an attacker acquired 0.4852 tmvETH for ~$951, staking it to seize 90.66% governance control of Term Finance vaults on Ethereum. They exploited a permission loop (DELAY.owner()==ROLES, with Role 1 granted to DAO) to reset the 7-day timelock to zero, then immediately executed vault-draining transactions for 2,843 ETH and 1.68M USDC — a total of ~$8.5M. Funding was seeded through Tornado Cash.
More Markets Loses 15.5M WFLOW ($9.3M) on Flow EVM via Unbacked ankrFLOW Minting + E-Mode
An attacker exploited Ankr's ankrFLOW liquid-staking contract to mint ~8.6M unbacked tokens, then used Aave V3 e-mode's high 95% LTV to borrow More Markets' entire WFLOW reserve. Thin on-chain liquidity meant the attacker realized only ~$246K after slippage, but the protocol's reserve was fully drained.
Cosmos EVM GHSA-7g4w-cg88-2cq2: Vesting Underflow Drains $5.7M Across Six Chains (Post-mortem Aug 28)
Cosmos Labs' August 28 post-mortem details how three chained bugs in the shared Cosmos EVM module — a vesting balance underflow to ~2^256, a compensating overflow that zeroes victim balances, and precomputed malicious contract deployment — were exploited August 20–25 across MANTRA, TAC, KiiChain and three other chains for ~$5.72M. The bug was first reported April 25 and the public patch release on August 19 inadvertently tipped attackers.
Term Labs Publishes Full Incident Report After $8.5M Governance Attack (August 23)
Term Finance published its final post-mortem on September 3, 2026 covering the August 23 governance exploit in which an attacker spent ~$951 in repo tokens to seize control of Yearn v3 strategy vaults, removed timelocks, and drained 2,843 ETH + 1.68M USDC (~$8.5M). All fixed-rate positions have been recovered; Meta Vaults remain shut down.
August 2026 Sets Monthly Hack Record: 50 Incidents, $136M Stolen — PeckShield
PeckShield's August 2026 recap recorded 50 confirmed crypto-hack incidents totaling $136M in losses — the highest monthly incident count of 2026, though down 49% by dollar value from July's $270M. Top losses included Tectonic (~$6.3M escaped), Term Finance ($8.5M), Injective ($4.9M), Cosmos EVM ($5.7M), and BounceBit ($3M). The pattern reinforces 2026's dominant trend: key-compromise and cross-chain oracle/bridge vectors drive the largest dollar losses, while smart-contract code bugs remain frequent but smaller.
Injective Loses $4.9M to Binary Options Settlement Oracle Exploit; Chain Halts 3.7 Hours (Aug 31, 2026)
An attacker on Injective created 299 self-administered binary options markets pointing to a deliberately broken oracle feed, then exploited the protocol's refund-on-missing-price fallback to drain $4.9M. A market ID collision amplified the damage. Injective halted for 3 hours 42 minutes, deploying emergency patch v1.20.3-safeharbor.1 which disables binary-options settlement on mainnet pending a redesign.
Tectonic on Cronos Hit by $75M Flash-Loan Oracle Manipulation; Chain Rolls Back (Aug 30–31, 2026)
An attacker pumped Tectonic's governance token TONIC ~100x in 20 minutes via flash-loan amplification on August 30–31, borrowing approximately $75M in blue-chip assets against the inflated collateral. Cronos validators halted block production and rolled back ~11,000 blocks, recovering ~$68.7M on-chain; ~$6.3M in USDC had already bridged to Ethereum. TRM Labs noted this is the latest in an all-time high for price-manipulation attacks in 2026.
Notional Finance V1 Escrow Loses $1.73M to Integer Overflow on Ethereum (Sep 4, 2026)
An attacker exploited an unsafe `uint128()` downcast in Notional Finance's legacy V1 escrow contract on September 4, 2026, using two `mintfCashPair()` calls that summed to exactly -2^128 — a value the free-collateral check read as zero. Approximately $1.73M in DAI and USDC was drained, swapped for 689 ETH, and routed through Tornado Cash. Notional had wound down V3 after a November 2025 Balancer cascade but left V1 contracts live and funded with no guardian or sweep mechanism.
The Sandbox Halts Base and BNB Bridges After approveAndCall Exploit Mints 329T SAND
On August 21–22, 2026, an attacker exploited an approveAndCall vulnerability in The Sandbox's SAND OFT contract on Base to hijack LayerZero delegate permissions, minting 329.24T unbacked SAND (face value ~$49B) across 703 events. Only ~14.75M real SAND (~$675K) was actually drained from the Ethereum OFT Adapter; The Sandbox disabled bridging and removed LayerZero peer settings within hours.
RedStone: Tectonic's $75M Loss Was Collateral Risk, Not Oracle Failure
RedStone's co-founder clarified that the oracle reported the correct TONIC market price throughout the Tectonic exploit; the failure was the protocol accepting a manipulable thin-liquidity token as collateral with no liquidity-depth cap. A borrow cap tied to executable liquidity would have prevented the loss.
August 2026: Record 50 Crypto Hacks, $136M Lost — Oracle Manipulation Dominant Vector
CertiK and PeckShield tallied 50 separate crypto security incidents in August 2026 — the highest monthly incident count in 2026 — with $136.3M in total losses. Price manipulation accounted for $131.6M of August's DeFi-specific losses. Year-to-date total reached $1.3B across 200+ incidents.
Cronos Halts Entire Blockchain and Rolls Back 11,000 Blocks After $75M Tectonic Oracle Exploit
An attacker on August 31 pumped the TONIC token ~100× in 20 minutes and borrowed ~$75M in real assets against inflated collateral on Tectonic (Cronos lending protocol). Cronos validators halted block production and rolled back chain state to before the attack — a controversial emergency measure that prevented most losses but raised decentralization concerns; only ~$6M escaped to Ethereum before the halt.
Cosmos EVM Integer Underflow Drains $5.7M Across Six Chains — Bug Was Previously Marked Fixed
A shared integer underflow vulnerability in the Cosmos EVM module's vesting account and staking balance handling was exploited across MANTRA, TAC Chain, KiiChain, and three undisclosed chains between August 20–25, 2026, for ~$5.7M total. Cosmos Labs confirmed the bug had previously been reported and incorrectly marked as resolved. All affected chains were urged to halt, and several rolled back.
Balancer V1 Pool Drained $234K via Rounding Bug in Legacy Fixed-Point Math
A nested flash loan from Aave, Spark, Morpho, and Uniswap V3 drove a Balancer V1 WBTC pool's reserve to near-zero on August 31, enabling the attacker to mint 4,408.8 BPT for a single satoshi by exploiting an integer-rounding flaw in joinswapPoolAmountOut. Balancer Labs dissolved in March 2026 after the same bug family caused a $116M V2 drain — leaving immutable V1 contracts permanently unpatched and all live forks of V1 code exposed.
Moonwell (Base) Loses $8.7M as MAMO Spot Price Is Pumped 8× Over 3 Hours
On August 27, 2026, attackers manipulated the MAMO token from $0.0105 to $0.088 on Base, deposited the inflated collateral on Moonwell, and borrowed cbBTC, WETH, USDC, and wstETH — extracting ~$8.7M in assets ($11M gross borrowed). Moonwell, which has now suffered three exploits in nine months, imposed emergency borrow caps; no smart-contract code was directly breached — the attack succeeded entirely through spot-oracle manipulation.
Term Labs Post-Mortem: Attacker Zeroed Governance Delays Before $8.5M Vault Drain
Term Labs published its post-mortem on September 3, 2026, revealing that an attacker spent just ~$951 to pass a disguised 'LP veto' governance proposal that zeroed the protocol's execution timelock. With zero delay in effect, four subsequent proposals recalled ETH strategy vaults to an attacker-controlled exit contract and swept USDC vaults via a counterfeit token priced at each vault's full liquid balance — draining 2,843 ETH + 1.68M USDC in total.
PeckShield: August 2026 Saw 50 DeFi Hacks Totaling $136M — Highest Monthly Count on Record
PeckShield's September 1 monthly wrap-up counted 50 distinct hacks in August 2026 totaling approximately $136M in losses, marking the highest monthly incident count the firm has recorded. The pace underscores an accelerating exploit environment across EVM and non-EVM chains heading into September.
Aquifer Solana AMM Loses $2.5M in Suspected Key Compromise; 20% Whitehat Bounty Deadline Passes
Solana-based AMM Aquifer suffered a ~$2.5M exploit attributed to a suspected privileged key compromise, with funds split across Solana and Ethereum attacker wallets. Aquifer offered a 20% bounty for the return of 80% of funds by September 3, 2026 — no confirmed recovery was reported before the deadline.
Rain Card Legacy Contract Exploit Drains $1.1M from Avici and Tria Neobank Users
An unpatched legacy Rain card contract allowed an attacker to seize admin control over individual card-collateral accounts, draining ~$500,800 from Avici (1,685 users) and ~$430,000 from Tria (636 users). Stolen funds were bridged to Ethereum and routed through Tornado Cash. Rain has upgraded all legacy contract instances; both neobanks pledged user compensation.
Term Finance Loses $8.5M to Governance Exploit: Attacker Buys 90.66% Voting Power for $951
On August 23–24, 2026, an attacker spent roughly $951 to acquire 0.4852 tmvETH, capturing 90.66% of voting power in Term Finance's near-empty governance pool. Using that supermajority, the attacker voted to redirect vault assets — extracting 2,843 ETH (~$6.9M) and 1.68M USDC from Term's Yearn V3-based Meta Vaults. The exploit highlights governance-apathy risk: low on-chain participation makes any DAO cheaply capturable.
Oraichain ICS-20 EVM Precompile Bug Enables Unauthorized Minting of 1.51 Billion ORAI
On August 8–9, 2026, a vulnerable ICS-20 EVM precompile on Oraichain credited ORAI to IBC transfer recipients without debiting senders, enabling unlimited token minting (~1.51B ORAI minted, ~98× total supply). The network was halted at 04:00 UTC August 9; exchanges froze deposits; on-chain restoration was later confirmed complete.
Rain Infrastructure Stale Contract Exploit Drains $1.1M from Solana Neobank Avici
On August 29, 2026, an attacker exploited an outdated Rain card contract on Solana by repeatedly replaying signed authorization messages to self-appoint as administrator and drain ~$1.1M from 1,685 Avici and Tria user accounts. Funds were swapped to SOL, bridged to Ethereum, and routed through Tornado Cash. AVICI token fell 49%.
Term Finance Governance Exploit: $951 Vote Purchase Drains $8.5M via Timelock Bypass
On August 23–24, 2026, an attacker purchased ~0.485 tmvETH for ~$951 to seize majority governance control of four USDC vaults and the Ethereum Meta Vault on Term Finance, self-approved a proposal resetting the 7-day timelock to zero, and immediately transferred ~2,843 ETH + 1.68M USDC (~$8.5M). Term Labs permanently shut down Meta Vault deposits.
Balancer V1 Pool Loses $234K to Rounding-Error Exploit; V1 Forks Still Exposed
On August 31, an attacker used nested flash loans (Aave, Spark, Morpho, Uniswap V3) to compress a Balancer V1 WBTC pool reserve to near-zero, then exploited a fixed-point rounding bug in `joinswapPoolAmountOut` to mint 4,408.8 BPT for a single satoshi. Draining ~$234K, the attacker exposed that this unmaintained V1 code shares the same bug family as the $116M Balancer V2 November 2025 exploit. Balancer urged all V1 LPs to withdraw immediately.
The Sandbox SAND Bridge Exploited via LayerZero Delegate Hijack; 339 Trillion Unbacked SAND Minted
On August 21–22, 2026, an attacker exploited a configuration flaw in The Sandbox's Base and BNB Chain bridge contracts by hijacking LayerZero delegate permissions through the `approveAndCall` function, granting themselves sole verifier rights and minting over 339 trillion unbacked SAND. Actual reserves drained were ~$675K (14.74M real SAND from the Ethereum vault) before the bridge was closed; most unbacked SAND could not be cashed out. The Sandbox committed to reimbursing affected holders.
More Markets Loses $9.3M as E-Mode LST Attack Drains Flow EVM Lending Reserve
On August 31, 2026 at ~07:58 UTC, an attacker used ankrFLOW inside More Markets' Aave V3 E-mode category to borrow 15.5M WFLOW (~$9.3M), leaving the protocol technically insolvent with TVL below outstanding loans. Blockaid detected and disclosed the attack; More Markets issued no initial pause. This is the third DeFi lending exploit in five days.
CertiK: August 2026 Crypto Losses Total $215M — Price Manipulation Tops Attack Vectors at $131.6M
CertiK's August 2026 monthly security report tallied ~$215M in total crypto losses, with DeFi-specific losses at ~$144.6M. Price manipulation was the leading attack vector at $131.6M (dominated by the Tectonic incident), followed by phishing ($41.5M), code vulnerabilities ($20.6M), wallet compromise ($11.8M), and governance attacks ($8.5M).
Cronos Chain Rolled Back After Tectonic Exploit; ~$68.7M Reversed But $6M on Ethereum Remains with Attacker
Cronos validators rolled the chain back to block 90,896,189, reversing ~$68.7M in stolen funds still on-chain. The rollback erased all user transactions in the discarded ~90,000-block window. Roughly $6.29M in USDC that crossed the bridge to Ethereum before the halt remains in attacker hands — beyond the reach of the Cronos rollback.
Balancer V1 BPool Exploited for $234K via Rounding Bug and Flash Loan Dust Attack
A legacy, unmaintained Balancer V1 BPool was drained of ~$234K after an attacker used a flash loan to compress pool reserves to near-zero, then exploited a fixed-point rounding error in `joinswapPoolAmountOut` to mint 4,408.8 BPT tokens for a single satoshi of input. The vulnerability belongs to the same bug family as the November 2025 exploit that drained $116M from Balancer V2 and led to Balancer Labs' shutdown. Remaining V1 LPs and Balancer V1 fork operators are urged to exit or patch immediately.
Tectonic Lending Exploit Drains ~$75M, Cronos Validators Halt Entire Blockchain
An attacker pumped Tectonic's TONIC governance token ~100× over ~20 minutes using thin AMM liquidity (~$1.34M pool depth), then deposited the inflated tokens as collateral and borrowed approximately $75M in real assets. Cronos validators responded with an emergency full chain halt, trapping ~$68M of the attacker's proceeds on-chain while ~$6M was bridged to Ethereum. The attack wiped ~46% of Cronos's total DeFi TVL and is the largest DeFi exploit of August 2026.
More Markets Loses $9.3M in WFLOW via E Mode + Ankr Bonded LST Exploit on Flow EVM
An attacker exploited the interaction between More Markets' E Mode configuration and an Ankr bonded liquid staking token on Flow EVM, draining 15.5M WFLOW (~$9.3M) from the mFlowWFLOW lending reserve. Neither Ankr nor the Flow L1 chain was compromised; Blockaid is investigating on-chain fund movements.
Tectonic Lending Protocol Loses ~$75M to Governance Token Oracle Manipulation on Cronos
An attacker pumped Tectonic's TONIC governance token ~100× in under 20 minutes and drained ~$75M in real assets by borrowing against inflated TONIC collateral. Cronos validators halted the entire blockchain, freezing ~$60M of the stolen funds on-chain; only ~$6M escaped before the halt.
Moonwell MAMO Oracle Exploit Drains $8.7M from Base Lending Markets
On August 27, 2026, an attacker manipulated the price of the thinly-traded MAMO token from ~$0.01 to ~$0.47 via low-liquidity markets, then used the inflated MAMO collateral to borrow ~$11M (net $8.7M) from four Moonwell Core Markets on Base. Moonwell responded by capping borrow caps at 1 wei across all Base Core Markets. This is Moonwell's third security incident in 2026.
Cronos Blockchain Halted After Tectonic TONIC Oracle Manipulation Drains ~$75M
On August 30, 2026, an attacker inflated the price of Cronos' TONIC governance token ~100× in under 20 minutes via thin-liquidity markets, then borrowed $75M from Tectonic, the chain's largest lending protocol. Cronos validators halted the blockchain to contain the damage, stranding ~$60M on-chain; only ~$6M was bridged to Ethereum before the halt. The attack mirrors the 2022 Mango Markets exploit.
Moonwell Hit by $8.7M Oracle Manipulation on Base — Third Exploit in 11 Months
Attacker inflated the illiquid MAMO token from $0.01 to ~$0.43 using spot-market pressure and used the manipulated spot price in Moonwell's oracle to borrow $8.7M in cbBTC, USDC, wstETH, and ETH. The protocol froze new borrowing across all Base Core Markets. Cumulative 2026 losses for Moonwell now exceed the protocol's full annual revenue.
Cosmos EVM Bug (GHSA-7g4w-cg88-2cq2) Drains $5.72M Across Six Chains After Bounty Assessment Error
A critical integer-underflow in the Cosmos EVM state-sync layer was exploited Aug 20–25, draining ~$5.72M from MANTRA, TAC, KiiChain, and three other chains. Cosmos Labs had incorrectly cleared the bounty-reported bug as non-exploitable on live networks; a silent public patch on Aug 19 gave attackers a 20-hour window before downstream chains could upgrade. Post-mortem published Aug 28–29.
Sandbox SAND Bridge Exploit: Attacker Hijacks LayerZero Delegate via approveAndCall, Drains $675K from Ethereum OFT Adapter
On August 21–22, an attacker exploited an approveAndCall function on The Sandbox's SAND OFT contract on Base, hijacking LayerZero delegate permissions to mint 329 trillion unbacked SAND across 703 events; real losses totalled approximately $675K (14.75M SAND drained from the Ethereum OFT Adapter). The Sandbox has disabled bridges on Base and BNB Smart Chain and announced a 1:1 compensation plan for affected holders.
Cosmos EVM Advisory GHSA-7g4w-cg88-2cq2: Staking Precompile Underflow Drained $5.7M Across Six Chains
Cosmos Labs confirmed on August 28 that a critical integer underflow in the cosmos/evm staking precompile, exploited via vesting account manipulation, allowed attackers to manufacture massive token balances and drain approximately $5.72M from MANTRA, TAC, KiiChain, and three other Cosmos EVM chains between August 20–25. The bug was reported on April 25 but dismissed; fixes shipped in v0.6.2/v0.7.2 on August 19 — the day before exploitation began. All unpatched chain operators are urged to halt validators immediately.
'Free Pavel' Token Rug-Pull Drains ~$94K (35 ETH) on Ethereum
A token named 'Free Pavel' deployed on Ethereum was rug-pulled, with approximately 35 ETH (~$94,000) drained from holders. The incident was flagged in Fairyproof's weekly blockchain security watch for August 27, 2026.
Term Labs Governance Exploit: $8.5M Drained From Meta Vaults Without Any Code Bug
On August 23, 2026, an attacker accumulated sufficient voting power to take majority control of Term Labs' USDC strategy vaults and Ethereum Meta Vault, self-approving proposals to drain 2,843 ETH and 1.68M USDC (~$8.5M total). Term Labs permanently closed Meta Vault deposits and revoked DAO governance roles in response. No smart contract code was exploited — governance design was the sole vulnerability.
Moonwell Base Protocol Loses $8.7M in MAMO Spot Oracle Manipulation Attack
On August 27, 2026, an attacker pumped the illiquid MAMO governance token ~8× on Aerodrome SlipStream and Uniswap v3 Base pools, exploiting Moonwell's spot-price oracle to borrow over $8.7M in cbBTC, wstETH, USDC, and ETH. Moonwell set all Base Core Market borrow caps to 1 wei as an emergency pause. This is the protocol's third security failure in 11 months.
Moonwell's AI-Generated Oracle Code Caused $1.78M cbETH Exploit in February 2026
Moonwell suffered $1.78M in bad debt in February 2026 after Solidity oracle code partially authored by Claude Opus 4.6 priced cbETH at $1.12 instead of ~$2,200 by using only the cbETH/ETH exchange rate without multiplying by the ETH/USD feed. Liquidation bots drained 1,096 cbETH before the error was detected, making it the first widely documented exploit of AI-assisted 'vibe-coded' smart contracts.
Moonwell Loses ~$8.7M on Base After MAMO Oracle Price Pumped 43×
On August 27, 2026, an attacker manipulated the price of the illiquid MAMO token from ~$0.01 to ~$0.43 on Base, used the inflated collateral to borrow cbBTC, USDC, wstETH, and ETH from Moonwell's lending market, and consolidated proceeds into approximately $8.7M DAI. Moonwell has set borrow and supply caps to 1 wei across affected markets as an emergency measure.