Back to Blog

Newsletter - August 2026

Code Auditing
September 1, 2026
4 min read
Key Insights
  • Cosmos EVM exploit lost ~$14.8M via balance sync underflow/overflow across six chains.

  • Moonwell lost ~$9.1M after low-liquidity MAMO price manipulation inflated borrowing power.

  • Term Finance lost ~$8.47M when weak governance thresholds enabled a cheap takeover.

Top 3 DeFi Incidents in August 2026

Cosmos EVM Multi-Chain Exploit: ~$14.8M

Between August 20 and 25, 2026, a balance-synchronization vulnerability in the Cosmos EVM module was exploited across six chains. The affected chains confirmed by Cosmos Labs are MANTRA, TAC Chain, and KiiChain, the other three have not been disclosed. Based on the value of the transferred assets from the three disclosed chains, losses are estimated at approximately $14.8 million. TAC Chain's staking pool alone lost about 2.986 billion TAC, worth roughly $7.5 million at the time.

The TAC Chain case illustrates how the vulnerability worked. TAC Chain runs both Cosmos SDK and the EVM, and the same 20-byte address can serve as a Cosmos vesting account and also an EVM contract. Cosmos tracks an account's total, locked, and spendable balances. Locked balances cannot be transferred, but they can be delegated. The EVM tracks only the spendable balance and keeps it synchronized with the Cosmos side.

The root cause was that when the EVM synchronized the spendable balance, it subtracted the delegated amount from the existing balance, even though the delegation came out of the locked balance. When an account delegated 1 locked wei, its Cosmos total balance fell from 1 to 0, while its spendable balance was 0 both before and after the delegation. The EVM synchronization logic nevertheless computed 0 - 1, and the EVM-side balance underflowed to MAX_UINT256.

The attacker abused this vulnerability to underflow their own attack contract's EVM balance to MAX_UINT256. However, this anomalous amount could not be transferred out normally. The attack contract then sent a precisely calculated, enormous value to the staking module account holding a large amount of real TAC, causing that account's balance to overflow to zero during addition. Once the same value was deducted from the attack contract, it was left with approximately the module account's original TAC balance. Through this transfer operation, about 2.986 billion TAC was re-credited to the attack contract, then transferred out and bridged to BNB Chain.

Moonwell: ~$9.1M

On August 27, 2026, Moonwell on Base suffered an attack, resulting in a loss of approximately $9.1 million.

The attack manipulated the oracle price Moonwell used to value MAMO collateral. MAMO had extremely limited market liquidity, meaning concentrated purchases could move its price substantially. Moonwell also assigned it a 50% collateral factor, allowing a price increase to translate directly into significant borrowing capacity.

The attacker bought approximately 94.31 million MAMO across multiple DEXes, pushing up market execution prices and driving the Chainlink MAMO/USD feed from about $0.0106 to a peak of $0.4313, a 3,970% increase. The highest price Moonwell used for collateral valuation was approximately $0.4025, about 3,698% above the pre-attack level. The attacker then formally supplied about 15.09 million MAMO and transferred another 53.39 million directly to the mMAMO contract to circumvent the supply cap. The attacker's mMAMO ultimately represented approximately 55.51 million MAMO. At Moonwell's peak accepted price of $0.4025, the collateral was valued at about $22.34 million, providing approximately $11.17 million of borrowing capacity. The attacker completed 18 borrows totaling $11.03 million and subsequently moved about $8.73 million in USDC to Ethereum.

The incident demonstrates the vulnerability of oracle-based lending markets to low-liquidity collateral. When an asset can be moved with limited capital, relying on its market price while assigning a high collateral factor can convert a temporary price distortion directly into protocol bad debt. Lending protocols should set collateral factors, supply caps, and borrow caps according to market depth, while applying additional controls for rapid price increases and realistic liquidation capacity.

Term Finance: ~$8.47M

On August 23, 2026, Term Finance Meta Vaults on Ethereum were drained in a governance takeover, losing roughly $8.47 million.

The root cause was a governance threshold that no longer matched the actual value it was supposed to protect. A Meta Vault spreads deposits across a set of strategy vaults, each governed by its own Aragon DAO. To vote, users had to opt in by wrapping their vault shares into a governance token, and a proposal's minimum participation threshold was measured against that wrapped supply rather than total shares outstanding. Because almost no one wrapped their shares, the seven-day timelock and veto mechanism were still technically active, but the pool of eligible voters they depended on had shrunk to almost nothing.

With this gap open, about 0.5 ETH was enough to buy and wrap sufficient tmvETH to hand the attacker roughly 90.66% of the ETH Meta Vault's voting power. A second address captured the entire active electorate of five USDC strategy vaults with deposits of about $5 each. The attacker then filed twelve proposals disguised as vetoes of parameter changes.

At execution, the proposals reduced the 604,800-second (seven-day) delay to zero, recalled funds from four ETH strategies, and installed a strategy hardcoded to forward assets to the attacker, extracting about 2,841.74 WETH. The attacker then swapped out the controllers and pricing components of the five USDC strategies, zeroed out the reserve ratio, and forced the vaults to buy a worthless repo token at an attacker-set price, extracting a further 1.68 million USDC.

Best Security Auditor for Web3

Validate design, code, and business logic before launch

References

Cosmos EVM multi-chain incident

Moonwell

Term Finance

The information above is based on data available as of 00:00 UTC on September 1, 2026.

This concludes the August security incidents brief.

You can learn more in our Security Incidents Library.

Stay informed and stay secure!

Sign up for the latest updates
~$320M Lost: Liquid Network, Symbiosis Exploits | BlockSec
Security Insights

~$320M Lost: Liquid Network, Symbiosis Exploits | BlockSec

This report, covering 2026/09/07 - 2026/09/13, examines two security incidents that caused approximately $320M in losses, including the Liquid Network exploit of 2026/09/06 that the previous report did not cover. The larger was that Liquid Network exploit, where the rangeproof validation cache in Elements derived its key by hashing four fields — two of them variable in length — concatenated with nothing marking the boundaries between them, so a verdict recorded for one output was returned for another whose proof was never examined, letting the attacker create 4,000 unbacked L-BTC and peg out nearly all of them as bitcoin. On the Bitcoin route of the Symbiosis cross-chain bridge, spanning BNB Smart Chain, Ethereum and Rootstock, off-chain code that reads Bitcoin deposits took the depositor's identity from a field the depositor controls and then subtracted its fee from the deposit without checking whether the fee itself was negative, letting a 330-satoshi deposit mint `46,116,860,184.27388234 syBTC`; the pools it had to be sold through held only 11.26 syBTC, so the loss to liquidity providers and users came to an estimated 9.97 BTC (~$770K).

~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly
Security Insights

~$9.4M Lost: Injective, Aquifer Exploits | BlockSec Weekly

During the past week (2026/08/31 - 2026/09/06), four security incidents caused approximately $9.4M in losses across Injective, Solana, Ethereum, and Flow EVM. The largest was the Injective exploit, where an insurance fund identifier collided with a binary options market identifier and the settlement path never compared their denominations, draining about $4.8M; Aquifer on Solana lost about $2.47M because its swap path invoked an unvalidated caller-supplied Token Program, and Notional Finance V1 on Ethereum lost about $1.73M to an unchecked `uint128` cast that valued a debt at zero. Ankr FLOW on Flow EVM closed out the week with about $410K drained through a staking entry point that skipped its pause guard and minted against a stale ratio.

From Incidents to Regulation: Why Crypto Institutions Need Blockchain Penetration Testing
Security Services

From Incidents to Regulation: Why Crypto Institutions Need Blockchain Penetration Testing

Exchanges, payment firms, custodians, and wallet providers now lose the most money beyond the smart contract—in signing, custody, keys, people, and supply chains. Code-level audit and transaction-level monitoring each leave a gap, and traditional penetration tests may miss crypto's signing and fund semantics. This article opens our blockchain penetration testing series with the two legs of the case for institutions in scope: where the risk actually comes from, and how NYDFS, DORA, VARA, SFC, and MAS treat adversarial testing across five jurisdictions.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit