Key Takeaways
Most of these losses were not caused by broken code. Four of the five incidents came from manipulated prices, shared software that was patched quietly, stolen organizational access, and an old contract version nobody retired.
Your risk in a lending market is set by the weakest collateral it accepts, not by the asset you personally deposited. A stablecoin depositor can lose money because of a thinly traded governance token in the same pool.
"Self-custodial" describes a wallet, not always the whole product. In the crypto card incident, user wallets were untouched. The money that was stolen had already been moved into a third party contract for spending.
What Happened in One Week
Between 20 August and 30 August 2026, five separate security incidents hit decentralized finance and crypto payments. Reported losses ranged from roughly one million dollars to roughly seventy five million. Two blockchains stopped producing blocks. Several protocols froze borrowing.
Taken individually, each looks like bad luck. Taken together, they map out four repeatable classes of failure that beginners and intermediate users can learn to check for. Some figures below come from on-chain researchers and security firms rather than from the affected teams, and are described as estimates where a project has not confirmed them. Several investigations were still open at the time of writing.
Date (2026) | Incident | Reported scale | Failure class | Status at time of writing |
|---|---|---|---|---|
20 to 25 August | Cosmos EVM shared module bug | About 5.72 million dollars converted across six chains | Cleared but not fixed bug in shared code | Post-mortem published 28 August, three chains halted, exchange accounts frozen |
27 August | Moonwell on Base | About 8.7 million dollars | Illiquid collateral and oracle manipulation | Borrow caps cut to 1 wei, post-mortem published |
28 to 29 August | Rain card contract, affecting Avici and Tria | About 1.1 million dollars traced on-chain | Third party contract in a self-custodial product | Contract versions upgraded, refunds promised |
29 August | Fogo Foundation compromise | 400 million FOGO, about 3 million dollars | Organizational and key compromise | Mainnet halted, addresses restricted, incident not fully explained |
30 August | Tectonic on Cronos | Estimated 66 to 75 million dollars | Illiquid collateral and oracle manipulation | Cronos network halted, no restart timeline or post-mortem |
The cluster arrived during a year with an unusually high incident count. CoinGecko counted 164 separate hacks and exploits in 2026 through early August, more than any full previous year, with 2025 next highest at 97. Immunefi placed DeFi specific losses for the first half of 2026 at roughly 680 million dollars, down about 74 percent from the 2022 peak. Together those figures describe more attacks, each generally smaller.
More reading CoinMarketCap vs CoinGecko Portfolio Tracker: Which Is Better for Beginners?
Failure Class One: Illiquid Collateral and Oracle Manipulation
Two of the week's largest losses used the same playbook. No contract was broken. The attacker changed the price.
How the attack works
A lending protocol needs to know what your collateral is worth, so it asks a price source called an oracle. If that price comes from a market with very little real liquidity, an attacker with modest capital can move it a long way in a short time. The sequence is usually:
Buy a large amount of a thinly traded token that the protocol accepts as collateral.
Push its market price sharply higher with a small amount of real money, because the order book or pool is shallow.
Deposit the now overvalued tokens into the lending protocol.
Borrow liquid, genuinely valuable assets such as wrapped bitcoin, ether or stablecoins against that inflated position.
Walk away without repaying. The bad debt stays with the protocol and its depositors.
Moonwell, 27 August 2026
Moonwell is a lending protocol on Base, the Ethereum layer 2 operated by Coinbase. According to the protocol's own post-mortem, the attack ran from 06:09:45 to 09:30:13 UTC and the attacker borrowed assets with a gross value of 11,028,762 dollars from four markets. CertiK, PeckShield and Blockaid each independently put the net loss at about 8.7 million dollars.
The collateral was MAMO, a small Base token. Reported price movement varies by source and measurement window, from roughly eight times to roughly forty times, with CoinGecko data cited showing a move from around 0.01 dollars to as high as 0.43 dollars. The borrowed assets included cbBTC, USDC, wstETH and ETH. Moonwell responded by setting borrow caps across all Base core markets to 1 wei, which in practice stops new borrowing, and cutting MAMO and WELL supply caps to the same level.
Two details make this instructive. First, MAMO sat in a shared core market, so the emergency brake had to cover every core market on the chain. A depositor supplying USDC and assuming they held only stablecoin risk was exposed to a token they may never have heard of. Second, this was Moonwell's third oracle related incident in under twelve months, following a cbETH pricing failure in February 2026.
Tectonic and the Cronos halt, 30 August 2026
Tectonic is the largest lending protocol on Cronos, the chain originally developed by the Crypto.com group. Before the incident, DefiLlama showed roughly 121.7 million dollars in total value locked and about 82.7 million dollars in outstanding borrows.
On-chain researcher Weilin Li reported that the attacker pushed the price of TONIC, Tectonic's own governance token, roughly one hundred times higher within about twenty minutes, then borrowed against it. TONIC carried a 20 percent collateral factor, meaning the protocol allowed borrowing against one fifth of the stated value. Reporting described an attacker position of roughly 364.6 trillion TONIC being treated as around 375 million dollars of eligible collateral.
Li first estimated about 66 million dollars, then identified a second attacker-controlled address holding roughly 8 million dollars, bringing his estimate to about 75 million. At least one separate on-chain analysis circulated a much larger figure of about 119.5 million dollars drained from the pools. Neither Tectonic nor Cronos had confirmed a final number or published a post-mortem at the time of writing.
Cronos validators then halted the chain. Because the network runs a Tendermint style consensus with a validator set capped at 100, coordinating that halt was practical. Only about 6 million dollars had been bridged to Ethereum beforehand, leaving most of the proceeds stranded. Crypto.com's chief executive said the company's app and exchange were unaffected.
Li publicly compared the pattern to the Mango Markets attack of October 2022, in which over 100 million dollars was drained using the same inflate and borrow method. Four years later, the method still works.
What good design looks like
Design choice | Weak version | Stronger version |
|---|---|---|
Price source | Live spot price from one shallow venue | Time weighted average price, or an aggregated feed across deep venues |
Market structure | One shared pool with many collateral types | Isolated markets, so a bad asset cannot drain unrelated deposits |
Collateral list | Governance and micro cap tokens accepted freely | Strict listing criteria tied to real liquidity depth |
Caps | High or absent supply and borrow caps | Caps sized to what the market could actually absorb in a sell off |
Circuit breakers | Manual, discovered after the fact | Automated deviation checks that pause borrowing on abnormal price moves |
A time weighted average price, usually shortened to TWAP, averages a price over a period instead of taking the latest tick. It makes brief manipulation far more expensive, because the attacker has to hold the fake price for longer.
Failure Class Two: The Bug That Was Cleared but Not Fixed
The Cosmos EVM incident is the most uncomfortable of the five, because the flaw was known months in advance.
Cosmos EVM is shared software that lets independent Cosmos based networks run Ethereum compatible applications. Dozens of chains use it, which means they inherit the same bugs.
Date (2026) | Event |
|---|---|
25 April | A researcher reports the vulnerability through the Cosmos Labs bug bounty program |
Testing phase | Testers cannot reproduce the exploit on the configurations used by live networks, so it is judged not to affect production |
May | A fix is merged through the silent patch process, which ships fixes without telling operators what they address |
19 August | Releases v0.6.2 and v0.7.2 ship, with no vulnerability specific advisory |
20 to 25 August | Attackers exploit six chains |
28 August | Cosmos Labs publishes a post-mortem acknowledging the misjudgment |
The bug was an integer underflow. In simple terms, a balance was subtracted below zero and, instead of erroring, wrapped around to the maximum possible value, a 78 digit number. The attacker then ran the same arithmetic in reverse against a target account, overflowing it back down and ending up with that account's tokens. No new tokens were created and total supply was effectively unchanged. Targets were arbitrary accounts holding large balances, such as burn addresses and multi signature wallets created at chain launch.
Cosmos Labs estimated roughly 5.72 million dollars was converted, split as about 2.87 million through decentralized exchanges and about 2.85 million through centralized ones, with the centralized accounts later frozen. MANTRA, TAC and KiiChain were named in the timeline. The other three affected chains were not publicly identified. Cosmos Labs said it contacted about 40 networks and that it had patched 37 vulnerabilities through the silent process over the previous 13 months.
Two lessons matter here. The first is scope: this was not a hack of the Cosmos Hub or of every Cosmos chain, and calling it a "Cosmos hack" would be misleading. The second is coordination. Shared modules concentrate risk, there is no single button to update dozens of sovereign chains at once, and a quiet patch gives attackers who read commit history a head start over operators who do not.
Failure Class Three: Organizational Compromise
On 29 August, the Fogo Foundation said an unknown actor had compromised the organization and that 400 million FOGO tokens had been sent to an attacker. Fogo is a Solana Virtual Machine layer 1 built for low latency trading and was only weeks into live trading.
The tokens represented about 4 percent of the 10 billion token genesis supply but more than 10 percent of circulating supply, worth roughly 3 million dollars at the time. That gap between genesis supply and circulating supply is why a small percentage of the total became a large percentage of the tradeable float.
The Foundation initially said the blockchain itself was operating normally. About fifteen hours later the mainnet was halted so validators could upgrade the network to restrict addresses linked to the unauthorized activity, with no restart time or technical detail given at that point. Bitget and KuCoin suspended FOGO deposits and withdrawals, and the token fell roughly 18 percent in 24 hours.
This was not a protocol bug. It was a failure of access control around foundation held wallets, and it belongs to the largest loss category of 2026. Industry analyses have attributed roughly 70 percent of this year's losses to compromised private keys, devices and infrastructure rather than to smart contract flaws.
Failure Class Four: The Custody Handoff Inside "Self-Custodial" Products
Rain supplies stablecoin card infrastructure and is a Visa principal member. Its technology sits behind a number of consumer crypto card products.
On 28 and 29 August, an attacker exploited a vulnerability in an outdated version of Rain's Solana card contract. Roughly 1.1 million dollars was traced on-chain across several programs. Avici, which markets itself as a self-custodial neobank with a Visa linked card, reported 1,685 affected users and 500,859.22 dollars in impacted card balances, and said every affected balance would be refunded in full. Tria reported 636 affected users and losses above 430,000 dollars, also promising full repayment. Stolen stablecoins were reportedly converted to SOL, moved across networks and routed through a mixing service. Avici said it filed a report with the FBI Internet Crime Complaint Center. Rain said the affected version was upgraded everywhere it was still running, with no further unauthorized activity detected.
The important structural point is this. Avici's self-custodial wallets on Solana and Ethereum compatible networks were not touched. What was drained was the separate contract holding balances that users had already loaded onto their cards. Under this card model, a customer deposits crypto into a collateral account and receives a matching spending limit, and settlement later draws on that collateral.
So the product is self-custodial right up to the moment you fund the card. After that, your money depends on someone else's contract, someone else's deployment discipline, and their willingness to retire old versions.
This is not a niche concern. Tracked crypto card spending more than tripled to about 1.04 billion dollars in July 2026, with stablecoins funding roughly 70 percent of more than 10 million transactions. Every one of those top ups is a handoff.
The Chain Halt Question
Two chains in this cluster, Cronos and Fogo, stopped producing blocks. Halting worked. It kept most of the Tectonic proceeds from leaving Cronos and stopped further movement of the Fogo tokens.
It also demonstrates a trade off with no clean answer. A chain that a small group can pause is a chain that can protect users in an emergency. It is also a chain that can freeze addresses, possibly yours. Precedent cuts both ways: in October 2022, validators paused BNB Chain after a bridge exploit and preserved most of the funds involved.
For a user, the practical question is simpler than the philosophical one. If your assets sit on a chain that can be halted, they stop moving during a halt whether or not you ever touched the exploited protocol.
A Protocol Due Diligence Checklist
The right response to a bad week is not to avoid decentralized finance. It is to look at a protocol the way an auditor would before depositing.
Question to ask | What a good answer looks like | Warning sign | |
|---|---|---|---|
1 | Who prices my collateral? | Documented oracle with time weighting or aggregation across deep venues | Live spot price from a single shallow pool |
2 | Are markets isolated or shared? | Isolated markets, or a clearly published risk framework for the shared pool | One pool, many collateral types, no segmentation |
3 | What is the thinnest asset accepted? | Every listed collateral has real, verifiable daily volume | A governance or micro cap token with a generous collateral factor |
4 | Are there caps, and are they sized sensibly? | Supply and borrow caps below what the market could absorb | High or unset caps on volatile assets |
5 | Whose code is this really? | Named framework, current version, active maintainer | Forked code, unclear version, dormant repository |
6 | How are vulnerabilities disclosed? | Public advisories with severity, plus published post-mortems | Silent patches and no incident history |
7 | Who holds admin keys? | Multi signature with a timelock and published signers | Single key upgrade authority, or unexplained admin powers |
8 | Can the chain be halted, and by whom? | Documented validator set and halt policy | No stated policy, or a very small operator group |
9 | Where does custody actually end? | A clear diagram of which contract holds funds at each step | Marketing that says self-custodial without defining scope |
10 | What happened last time? | Prior incidents disclosed and fully remediated | Repeat failures of the same class, or unresolved shortfalls |
11 | Who covers bad debt? | A published reserve, insurance fund or compensation policy | Nothing written down before the incident |
12 | How much am I comfortable losing? | Position sized to the weakest component in the system | Position sized to the marketing |
A practical sequence for a beginner: start with question 1, then 3, then 9. Those three catch the majority of what went wrong in this cluster.
What This Week Does Not Mean
It does not mean decentralized finance is uniquely broken. Every one of these failures has a direct parallel in traditional finance: mispriced collateral, unpatched shared software, insider access compromise, and a payments processor running an outdated system. What is different is speed and visibility. Every incident here was observable on-chain before any official statement, which gives attackers less friction and defenders faster evidence.
The realistic conclusion is narrower and more useful than "avoid DeFi". Understand which component of a product actually holds your money, understand who decides what that money is worth, and size your position accordingly.
Frequently Asked Questions
Was the whole Cosmos ecosystem hacked?
No. The flaw was in Cosmos EVM, a shared module that some Cosmos based chains use to run Ethereum compatible applications. Six chains were exploited. The Cosmos Hub was not among the affected networks described in the post-mortem.
If a blockchain can be halted, is it really decentralized?
Decentralization is a spectrum, not a yes or no. A chain with a small, coordinated validator set can stop an attack in progress, which protects most of the funds on Cronos. The same capability means transactions can be paused or addresses restricted. Neither property is purely good or bad. It is a trade off you should know about before you choose where to hold assets.
My wallet says self-custodial. Does that protect me?
It protects the assets that are actually in that wallet. It does not automatically cover funds you have moved into a linked product, such as a card balance, a staking contract or a bridge. In the Rain related incident, the self-custodial wallets were untouched while the separate card contract was drained. Read the documentation to find out where custody changes hands.
Why do oracle manipulation attacks still work?
Because the underlying problem is economic rather than technical. Code can be audited, but a token's real liquidity cannot be audited into existence. As long as a protocol accepts a thinly traded asset as collateral and prices it from a shallow market, someone can move that price faster than the protocol can react.
Do audits prevent these attacks?
Audits catch code defects, and they are valuable. Four of the five incidents here did not involve a code defect in the protocol that lost money. Audits do not price liquidity, do not manage foundation keys, and do not force teams to retire old contract deployments.
Related Terms
Oracle: the service a protocol uses to learn an asset's price. If the oracle can be manipulated, the protocol can be manipulated.
Collateral factor: the share of a deposited asset's stated value that can be borrowed against. A 20 percent collateral factor allows borrowing up to one fifth of the stated value.
TWAP (time weighted average price): a price averaged over a period rather than taken at a single moment, which makes short lived manipulation more expensive.
Integer underflow: an arithmetic error where a number is reduced below its minimum and wraps around to a very large value, producing balances that were never intended.
Isolated market: a lending market where each collateral type is ring fenced, so a failure in one asset does not spread to unrelated depositors.
Sources
The Block, "Crypto.com-linked Cronos network halts after Tectonic exploit estimated at $75 million", 30 August 2026: https://www.theblock.co/news/defi/2026-08-30-crypto-com-linked-cronos-network-halts-after-tectonic-exploit-estimated-at-413069
Cointelegraph, "Cronos halts network after Tectonic exploit involving estimated $75M", 31 August 2026: https://cointelegraph.com/news/cronos-network-halt-tectonic-exploit-75-million
The Block, "Cosmos Labs says it wrongly cleared the bug behind a $5.7 million six-chain hack", 29 August 2026: https://www.theblock.co/news/defi/2026-08-29-cosmos-labs-says-it-wrongly-cleared-the-bug-behind-a-5-7-million-six-chain-hack-413061
The Hacker News, "Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable", August 2026: https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
The Block, "Layer 1 blockchain Fogo halts mainnet after attacker receives 400 million FOGO tokens", 29 August 2026: https://www.theblock.co/news/defi/2026-08-29-layer-1-blockchain-fogo-halts-mainnet-after-attacker-receives-400-million-fogo-tokens-413064
CoinDesk, "A $1.1 million crypto card hack crashed a neobank's token 49%", 29 August 2026: https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49
CoinGecko Research, "Crypto Hacks and Exploits Through The Years 2016 to 2026": https://www.coingecko.com/learn/crypto-hacks-and-exploits-2016-to-2026
This article is for educational purposes only. It is not investment, legal or financial advice. Figures marked as estimates were unconfirmed at the time of writing and several investigations remained open.
More Reading
What Are Oracles in Crypto and Why Do They Keep Getting Hacked?
The Complete Beginner's Guide to Self-Custody: How to Hold Your Own Crypto Safely
Self-Custody Best Practices in 2026: Hardware Wallets, Multi-Sig, and AI-Agent Compatible Setups
DeFiLlama for Beginners: Free Tool to Understand DeFi TVL and Protocols Safely
Beginners Guide to Hardware Wallets Ledger vs Trezor vs Coldcard




