BLOCKCHAIN AI.NEWS

Security · The month in review

The Contracts Held. The Prices Didn't

CertiK put August's confirmed losses at about $215 million. Code vulnerabilities — the thing the entire audit industry exists to find — account for $20.6 million of it. Almost everything else came from lying to an oracle, or asking a vault nicely.

Editorial illustration: a chrome balance scale tipped hard, one pan overflowing with golden light, the other holding a single small steel bolt
✓ August tally first reported by The Crypto Times (Aug 31), from CertiK data · Incident-by-incident detail: Metaverse Post · H1 2026 context: Forbes on CertiK's Hack3D report, and TRM Labs

CertiK closed the books on August today and put the month's confirmed losses at roughly $215 million, reported first by The Crypto Times. That is the headline, and it is the least interesting number in the release.

The interesting number is $20.6 million. That is what August cost in the category marked code vulnerabilities — bad smart contract logic, the flaw a security audit is designed to catch. It is under a tenth of the month. Set against it: $131.6 million under price manipulation, which is not a bug in anybody's code. It is a market being told something false about what an asset is worth, by a protocol that agreed in advance to believe it.

Phishing took $41.5 million. Wallet compromise took $11.8 million. Governance — an attacker legitimately voting funds out of a treasury — took $8.5 million. Add those to the two above and you have $214 million of a $215 million month, which is a way of saying CertiK's categories leave almost nothing unexplained. The industry now knows exactly how it is being robbed.

August 2026, by how the money left

Price manipulation$131.6M
Phishing$41.5M
Code vulnerability$20.6M
Wallet compromise$11.8M
Governance$8.5M
CertiK's August 2026 category breakdown, via The Crypto Times, Aug 31. The five categories total about $214M against a headline figure of about $215M; the gap is rounding. Bar widths are proportional to the largest category, not to the month.

One incident is most of the month

Before anyone builds a thesis on that chart, here is the caveat that should travel with it. CertiK lists Tectonic — the Cronos lending market drained on Aug 30 — at $120.4 million. That single incident is 56% of the entire month and roughly 91% of the price-manipulation category. Add Moonwell's $8.7 million MAMO manipulation on Base, and two events account for about $129 million of the $131.6 million in that bar.

So the honest version of the finding is narrower than the chart implies: August was not a month in which a thousand attackers discovered oracle manipulation. It was a month in which two of them did it at scale, and one of those two was very large. A category dominated by a single outlier is a description of that outlier, not a trend.

What makes it worth reporting anyway is that the outlier is not an outlier in kind. We have now covered three of these inside a week, each following the same recipe: a lending market accepts a thinly traded token as collateral, an attacker buys the price up in a shallow pool, and borrows real assets against the number. Pendle and Morpho on Aug 25. Moonwell on Aug 27. Tectonic on Aug 30. The technique is four years old — Mango Markets was taken apart with it in 2022 — and it does not require a vulnerability, because nothing is broken. The collateral list is doing what it was configured to do.

The recovered column deserves more scrutiny than it gets

CertiK also reports about $110.7 million as returned or frozen — more than half the month's headline loss. That figure will get repeated as good news, and it is worth being careful about what it can and cannot mean.

"Returned" and "frozen" are not the same event. Returned money is back with users. Frozen money is stuck somewhere, unavailable to the attacker and, in most cases, equally unavailable to the people it belonged to. Our own reporting on the Cronos halt found roughly $60 million of the Tectonic proceeds stranded on a chain that had stopped producing blocks, against about $6 million that reached Ethereum before the validators pulled the lever. Whether that $60 million is ever moved back is a governance decision nobody has yet made in public.

CertiK has not published a split between the two, and we are not going to assume one. What can be said flatly: a large recovered figure in a month like August is substantially a story about intervention — halts, freezes, exchange cooperation — rather than about attacks failing. The attacks did not fail. They were interrupted afterwards, by parties with the power to interrupt them, which is a different and more uncomfortable fact.

Two firms, one half-year, a third of a billion apart

A note on counting, because we have now published figures from both sources and readers deserve to know they do not agree.

CertiK's Hack3D report put H1 2026 at $1,315,676,432 across 344 incidents, as Forbes reported in July. TRM Labs, whose H1 dataset we covered on Aug 27, put the same six months at about $972 million across 207 incidents. Same period, same industry, a gap of roughly $344 million and 137 incidents.

Neither firm is wrong. They are counting different things — what qualifies as an incident, whether phishing of individuals is in scope, whether a loss later recovered still counts, how a manipulated-price loss is valued when the manipulated price was never real. These are defensible methodological choices and they compound. The practical consequence is that "crypto lost $X this year" is a sentence with no fixed referent, and anyone quoting one number without naming the counter is selling a precision that does not exist.

CertiK's own year-over-year figure demonstrates the trap neatly. H1 2026 looks 46.8% below H1 2025 — until you notice that 2025's total included the single $1.45 billion Bybit theft. Strip that one event out and, per Forbes's read, comparable losses were about 28% higher this year. Q2 alone ran 194 incidents against 145 in Q2 2025. The headline said improvement; the underlying count said the opposite.

What the ledger is actually saying

Read across all of it and the month describes a shift in where the soft tissue is. Smart contract code, after a decade of audits, competitions and formal verification, is now the smallest line on the list. The things around the code are not: the price feed, the collateral parameters, the governance token float, the human who clicks a signature request.

Those are configuration and process, not engineering. None of them are caught by auditing a contract, because none of them are defects in a contract. Tectonic's collateral factor for TONIC was published. Term Finance's governance token was cheap and sparsely held in public. Neither fact was hidden; both were simply nobody's job to escalate.

August also set 2026's highest incident count. That is the number to carry into September, and it sits oddly against a loss figure inflated by one very large event. More attempts, mostly smaller, against a widening surface — with the occasional one that lands on a protocol big enough to make the month.

The Take

The audit industry solved the problem it was built for, and the money moved to the problems nobody owns. There is no equivalent of a smart contract audit for the question "should this asset be collateral at all," or "how much would it cost to buy control of our own governance token" — those are risk decisions made by teams that often have no risk function, reviewed by a DAO vote that nobody reads. The August ledger is a bill for that gap, and the $20.6 million code-vulnerability line is the proof: engineering is no longer the weak link, so pointing at more audits is pointing at the part that is working. The uncomfortable corollary is in the recovered column. More than half of what was stolen in August was clawed back by somebody halting a chain or freezing an address — which means the industry's most effective security control right now is a small number of people with the power to switch things off. That is a real control. It is not decentralisation, and the two are increasingly hard to hold at the same time.

More on the subject