More Markets exploited for $9.3 million

Defi lending project More Markets lost $9.3 million after an attacker was able to trick the lending protocol logic and empty the project's reserve. The attack was noticed by blockchain security researchers at Blockaid; More Labs later announced they were investigating. Oddly, while acknowledging that funds had been stolen, they wrote, "Our initial investigation reveals that MORE was not exploited. MORE's contracts are secure. MORE is solvent. The protocol is paused." They claimed that only 5% of the assets were bridged out of the Flow blockchain, though did not explain how they planned to prevent the attacker from moving more tokens or collapsing the token price entirely.

Crypto.com-affiliated Cronos blockchain halted after Tectonic theft

The ostensibly decentralized Cronos blockchain was halted after a price manipulation attack allowed an attacker to borrow more than $75 million against nearly worthless collateral from the Tectonic lending platform. The attacker pumped the price of the thinly traded TONIC token, the native token of Tectonic, then borrowed against it. The attacker cashed out approximately $6 million by bridging it to Ethereum before the Cronos chain was halted, limiting their profits. The blockchain was offline for almost 24 hours, during which time it was rolled back to a block prior to the hack — essentially undoing all the transactions that occurred after that block.

Cronos was launched by the exchange Crypto.com in 2021, and although the two entities are technically separate, they remain very closely linked. Because the Cronos chain is maintained by a relatively small number of validators, many controlled by Crypto.com, it was relatively easy to halt the chain — though the move was criticized by some who felt that it only illustrated Cronos' lack of decentralization and immutability. Some criticized the decision to halt the chain for nearly 24 hours over an exploit of a third-party protocol.

Exploit on Rain crypto payments infrastructure provider causes losses for "self-custodial" neobanks

A vulnerability in a smart contract belonging to Rain, a crypto payments infrastructure provider, resulted in $1.1 million in losses to various firms. Customers of the Avici cryptocurrency neobank, which offers a Visa credit card through which customers can spend crypto, suffered roughly $500,000 in losses. Customers of another neobank, Tria, lost more than $430,000.

The losses are somewhat unusual because the neobanks describe themselves as self-custodial, which normally means that customers have total control over their crypto assets rather than storing them on a third-party platform. Normally, self-custody is more resilient to exploits like this, given that assets remain in user wallets. However, because these neobanks require customers to load funds they want to be able to spend into a third-party contract, they were vulnerable to the theft.

Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

Term Finance loses $8.5 million to governance attack

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure

Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."

KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.

BounceBit exploited for $3 million, announces shutdown and migration

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

$1.76 million stolen from MAYAChain in attack exploiting six bugs

The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.

Ravencoin rolls back blockchain after exploit

Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.

Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.

Harmony token plunges 40% after unauthorized mint

An attacker was able to exploit the Harmony blockchain to mint 4 billion of the network's $ONE token. The massive increase in token supply caused the token price to plunge 40%.

Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback — that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.

This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North Korean hacking groups.