Web3 August Security Monthly Report | 29 Major Security Incidents Resulting in Total Losses Exceeding $68.29 Million
Web3 Security Report for August: 29 Major Incidents Caused Over $68.29 Million in Losses
In August 2026, Web3 space experienced 29 major security incidents, resulting in total losses of over $68.29 million. Contract vulnerabilities remained the primary cause, accounting for 18 cases, while 2 incidents stemmed from private key leaks, highlighting persistent weaknesses in smart contract security and key management.
The most significant incident involved a private key leak on August 13, leading to a $25.6 million theft from a user's address. On August 30, the lending protocol Tectonic on Cronos suffered a ~$74 million attack due to a contract flaw; the network was paused and transactions rolled back, but the attacker successfully bridged around $6 million to Ethereum. Another notable event was Harmony's exploitation via a replay attack, creating 40 billion ONE tokens (nominal loss ~$4M), though the state was later reverted.
DeFi protocols were the hardest hit in terms of value lost (~$33.09M), while individual users lost approximately $28.4M. Token contracts were the most frequently targeted (10 incidents), followed by DeFi contracts (9 incidents). Ethereum saw the highest loss value (~$48.58M across 15 events), followed by BNB Chain in incident frequency, though with smaller losses. Attacks occurred across multiple chains including Cronos, Base, Harmony, Bitcoin, and Solana.
Key attack vectors analyzed include:
1. **Price Manipulation (Tectonic & Moonwell):** Attackers artificially inflated the value of low-liquidity collateral tokens to borrow excess assets. This underscores the need for protocols to use multiple oracle sources and implement checks for extreme price volatility.
2. **Replay Attack (Harmony):** Exploiting a legacy system flaw, an attacker modified fields in a cross-shard receipt to replay it, leading to double-spending. The fix requires all fields used for "single-use" markers to be part of the signed block header.
3. **Governance Attack (Term Finance):** Attackers exploited low governance participation and the lack of absolute quorum thresholds to pass malicious proposals with minimal capital, draining approximately $8.5 million from six vaults. Recommendations include setting absolute voting power minimums and implementing effective guardian mechanisms during timelocks.
The overarching trend is a systematic expansion of the attack surface beyond code to include operational, governance, and business logic vulnerabilities. This demands a more holistic security approach from projects. Users are advised to regularly review and revoke unnecessary contract approvals and stay informed about evolving phishing tactics.
marsbitAyer 10:36