Back to Blog

Newsletter - August 2026

Code Auditing
September 1, 2026
4 min read
Key Insights
  • Cosmos EVM exploit lost ~$14.8M via balance sync underflow/overflow across six chains.

  • Moonwell lost ~$9.1M after low-liquidity MAMO price manipulation inflated borrowing power.

  • Term Finance lost ~$8.47M when weak governance thresholds enabled a cheap takeover.

Top 3 DeFi Incidents in August 2026

Cosmos EVM Multi-Chain Exploit: ~$14.8M

Between August 20 and 25, 2026, a balance-synchronization vulnerability in the Cosmos EVM module was exploited across six chains. The affected chains confirmed by Cosmos Labs are MANTRA, TAC Chain, and KiiChain, the other three have not been disclosed. Based on the value of the transferred assets from the three disclosed chains, losses are estimated at approximately $14.8 million. TAC Chain's staking pool alone lost about 2.986 billion TAC, worth roughly $7.5 million at the time.

The TAC Chain case illustrates how the vulnerability worked. TAC Chain runs both Cosmos SDK and the EVM, and the same 20-byte address can serve as a Cosmos vesting account and also an EVM contract. Cosmos tracks an account's total, locked, and spendable balances. Locked balances cannot be transferred, but they can be delegated. The EVM tracks only the spendable balance and keeps it synchronized with the Cosmos side.

The root cause was that when the EVM synchronized the spendable balance, it subtracted the delegated amount from the existing balance, even though the delegation came out of the locked balance. When an account delegated 1 locked wei, its Cosmos total balance fell from 1 to 0, while its spendable balance was 0 both before and after the delegation. The EVM synchronization logic nevertheless computed 0 - 1, and the EVM-side balance underflowed to MAX_UINT256.

The attacker abused this vulnerability to underflow their own attack contract's EVM balance to MAX_UINT256. However, this anomalous amount could not be transferred out normally. The attack contract then sent a precisely calculated, enormous value to the staking module account holding a large amount of real TAC, causing that account's balance to overflow to zero during addition. Once the same value was deducted from the attack contract, it was left with approximately the module account's original TAC balance. Through this transfer operation, about 2.986 billion TAC was re-credited to the attack contract, then transferred out and bridged to BNB Chain.

Moonwell: ~$9.1M

On August 27, 2026, Moonwell on Base suffered an attack, resulting in a loss of approximately $9.1 million.

The attack manipulated the oracle price Moonwell used to value MAMO collateral. MAMO had extremely limited market liquidity, meaning concentrated purchases could move its price substantially. Moonwell also assigned it a 50% collateral factor, allowing a price increase to translate directly into significant borrowing capacity.

The attacker bought approximately 94.31 million MAMO across multiple DEXes, pushing up market execution prices and driving the Chainlink MAMO/USD feed from about $0.0106 to a peak of $0.4313, a 3,970% increase. The highest price Moonwell used for collateral valuation was approximately $0.4025, about 3,698% above the pre-attack level. The attacker then formally supplied about 15.09 million MAMO and transferred another 53.39 million directly to the mMAMO contract to circumvent the supply cap. The attacker's mMAMO ultimately represented approximately 55.51 million MAMO. At Moonwell's peak accepted price of $0.4025, the collateral was valued at about $22.34 million, providing approximately $11.17 million of borrowing capacity. The attacker completed 18 borrows totaling $11.03 million and subsequently moved about $8.73 million in USDC to Ethereum.

The incident demonstrates the vulnerability of oracle-based lending markets to low-liquidity collateral. When an asset can be moved with limited capital, relying on its market price while assigning a high collateral factor can convert a temporary price distortion directly into protocol bad debt. Lending protocols should set collateral factors, supply caps, and borrow caps according to market depth, while applying additional controls for rapid price increases and realistic liquidation capacity.

Term Finance: ~$8.47M

On August 23, 2026, Term Finance Meta Vaults on Ethereum were drained in a governance takeover, losing roughly $8.47 million.

The root cause was a governance threshold that no longer matched the actual value it was supposed to protect. A Meta Vault spreads deposits across a set of strategy vaults, each governed by its own Aragon DAO. To vote, users had to opt in by wrapping their vault shares into a governance token, and a proposal's minimum participation threshold was measured against that wrapped supply rather than total shares outstanding. Because almost no one wrapped their shares, the seven-day timelock and veto mechanism were still technically active, but the pool of eligible voters they depended on had shrunk to almost nothing.

With this gap open, about 0.5 ETH was enough to buy and wrap sufficient tmvETH to hand the attacker roughly 90.66% of the ETH Meta Vault's voting power. A second address captured the entire active electorate of five USDC strategy vaults with deposits of about $5 each. The attacker then filed twelve proposals disguised as vetoes of parameter changes.

At execution, the proposals reduced the 604,800-second (seven-day) delay to zero, recalled funds from four ETH strategies, and installed a strategy hardcoded to forward assets to the attacker, extracting about 2,841.74 WETH. The attacker then swapped out the controllers and pricing components of the five USDC strategies, zeroed out the reserve ratio, and forced the vaults to buy a worthless repo token at an attacker-set price, extracting a further 1.68 million USDC.

Best Security Auditor for Web3

Validate design, code, and business logic before launch

References

Cosmos EVM multi-chain incident

Moonwell

Term Finance

The information above is based on data available as of 00:00 UTC on September 1, 2026.

This concludes the August security incidents brief.

You can learn more in our Security Incidents Library.

Stay informed and stay secure!

Sign up for the latest updates
~$10.26M Lost: Term Finance, MAYAChain | BlockSec Weekly
Security Insights

~$10.26M Lost: Term Finance, MAYAChain | BlockSec Weekly

During the week of August 17-23, 2026, two notable security incidents resulted in approximately $10.26M in total losses across Ethereum and MAYAChain. The highlighted Term Finance incident (~$8.5M) was a flawed governance design rather than a coding bug: each vault ships its own on-chain DAO whose support-threshold and participation checks are purely relative, with no absolute floor; with almost no one taking part in governance, there was no electorate to vote a proposal down and no guardian to cancel one, so an attacker acquired a supermajority of a vault's voting power for roughly 0.5 ETH and, after the execution delay elapsed, drained six of Term's vaults for approximately $8.5M in total. MAYAChain (~$1.76M) lost funds to a chain of accounting and state-validation defects, where a single crafted deposit made valid withdrawals appear to have failed, triggered a recovery path that inflated a low-liquidity pool's recorded native-token balance with no real backing, and let the attacker drain the inflated value by adding and withdrawing liquidity.

Harmony Cross-Shard ONE Mint + ~$47M Key Losses | BlockSec Weekly
Security Insights

Harmony Cross-Shard ONE Mint + ~$47M Key Losses | BlockSec Weekly

During the week of August 10-16, 2026, 5 notable security incidents are featured, involving approximately $47M in quantified losses, with the detailed analysis focused on a chain-implementation flaw in the Harmony Layer-1. Harmony suffered unauthorized minting of native ONE through a cross-shard receipt replay: destination shards derived the receipt spent-marker from unauthenticated MerkleProof.ShardID and BlockNum fields instead of the signed source header, so an already-credited receipt could be replayed with no matching source-shard debit. Approximately 3.01T ONE was forged, but its nominal value far exceeds the token's market capitalization and is neither realizable nor confirmed realized loss, so Harmony is excluded from the total; the ~$47M came from private-key compromises (Unknown Whale Wallet ~$25M, Kite ~$14M, and Coinsbuy ~$7.9M) plus a Fox business-logic flaw (~$117K).

~$1.6M Lost: Moke Token, LpdFi Exploits | BlockSec Weekly
Security Insights

~$1.6M Lost: Moke Token, LpdFi Exploits | BlockSec Weekly

During the week of August 3-9, 2026, 2 notable security incidents on BNB Chain resulted in approximately $1.6M in total losses, both from price manipulation. The highlighted LpdFi incident (~$697K) reused the same manipulable PancakeSwap pair reserves for both order valuation and interest redemption, letting the attacker inflate a position's principal and reshape the pool to redeem an oversized interest claim. Moke Token (~$906K) combined a manipulable spot price with duplicated LP dividend accounting to claim inflated MOKE and collect the resulting BNB dividends multiple times.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit