Sixteen Hacks in Nineteen Days, and August Was Not Even the Worst Month
2026 has produced more separate crypto hacks than any year on record and less stolen money than 2025. Sixteen of them landed in the first nineteen days of August. The attacks got smaller, more frequent, and almost entirely stopped bothering with smart contract bugs.

By August 18, 2026, DefiLlama had logged 219 separate crypto hacks for the year, worth $1.26 billion. All of 2025 produced 146 incidents, and those took $2.71 billion. More attacks, less money, and the year still had four months to run.
Sixteen of those incidents landed in the first nineteen days of August.
The largest was not a smart contract exploit at all. The Coldcard entropy failure, which began on July 30 and kept producing waves into August, eventually accounted for 1,816 BTC from more than 5,200 hardware wallets. TRM Labs put it at $116 million and ranked it the third-largest crypto theft of the year. Nothing in the month came close.
Harmony was next by scale if not by dollar value. On August 12 an attacker exploited a cross-shard receipt flaw to forge roughly 3.01 trillion ONE tokens, moving 2.385 trillion of them in a hundred seconds. The chain rolled back to August 11, discarding more than 109,000 legitimate transactions to undo six attacker ones.
Ravencoin lost no coins at all and still had a worse week than most projects that do. A flaw in KAWPOW block header validation let blocks lie about their own height and skip proof of work entirely, and two mining pools controlling the majority of hashrate rebuilt the chain from August 7, overruling Ravencoin's own developers on how much history to delete.
Then the ordinary attrition. An unidentified whale lost roughly $25.6 million on August 12 to a phishing compromise, on the same wallet that had lost $24.2 million to an attack in 2023. That time some funds came back. This time none did. Coinsbuy lost $7.9 million across Ethereum and TRON, with the proceeds laundered through Monero. Coreum and Oraichain both suffered protocol-level failures. Maya Protocol closed the month's roster on August 18, drained for about $1.7 million after six chained bugs left a liquidity pool holding 50 million tokens that had never been funded.
Web3 losses passed $1.31 billion for the first half of 2026 by one count, with wallet compromises and infrastructure breaches now the costliest attack surface. That is the real story hiding in the arithmetic. Audits are built to find bugs in smart contracts. Most of this money did not leave through a smart contract.
Coldcard was a firmware build configuration. The whale was phishing. Coinsbuy was infrastructure. Harmony and Ravencoin were consensus-layer failures in code that had run for years without complaint. Maya was an error handler that logged a failure and did nothing about it. A conventional audit, scoped to contracts, would have found approximately none of it.
The pattern holds outside August too. Drift Protocol lost up to $285 million in April to compromised administrative credentials after six months of quiet infiltration, not to a contract bug. Kelp DAO, Ostium, AFX Trade, Allbridge, Verus: keys, oracles, validator quorums, bridge logic, the same vulnerability class recycled.
CoinGecko's count of 164 incidents through early August already exceeded any full prior year, with 2025's 97 the next highest. Some of that is better detection rather than more crime. Some of it is not.
What the falling dollar figure conceals is that the victims changed. 2022 produced $2.77 billion in losses and remains the costliest year on record, but those losses concentrated in a handful of enormous bridge and protocol failures. 2026's money is coming out of thousands of individual wallets, a few hundred thousand dollars at a time, from people whose names never appear in a headline and whose losses do not add up to anything a research firm writes a report about.
The median Coldcard victim lost 0.41 BTC. There were more than five thousand of them.
The Aftermath
None of August's major incidents has produced an arrest. Harmony and Ravencoin both resolved by rewriting chain history at the cost of legitimate user transactions. Maya is pursuing its attacker through a bug bounty. The Coldcard proceeds are partly laundered and partly sitting unspent in watched addresses. Coinsbuy's funds went through Monero and are effectively gone. The 2023 whale who lost $25.6 million a second time received nothing back, unlike the first occasion. With four months remaining, 2026 is certain to set a record for incident count and, on current pace, will finish well below 2022 and 2025 on dollars lost.
COMMENTS