Top 3 DeFi Incidents in August 2026
Cosmos EVM Multi-Chain Exploit: ~$14.8M
Between August 20 and 25, 2026, a balance-synchronization vulnerability in the Cosmos EVM module was exploited across six chains. The affected chains confirmed by Cosmos Labs are MANTRA, TAC Chain, and KiiChain, the other three have not been disclosed. Based on the value of the transferred assets from the three disclosed chains, losses are estimated at approximately $14.8 million. TAC Chain's staking pool alone lost about 2.986 billion TAC, worth roughly $7.5 million at the time.
The TAC Chain case illustrates how the vulnerability worked. TAC Chain runs both Cosmos SDK and the EVM, and the same 20-byte address can serve as a Cosmos vesting account and also an EVM contract. Cosmos tracks an account's total, locked, and spendable balances. Locked balances cannot be transferred, but they can be delegated. The EVM tracks only the spendable balance and keeps it synchronized with the Cosmos side.
The root cause was that when the EVM synchronized the spendable balance, it subtracted the delegated amount from the existing balance, even though the delegation came out of the locked balance. When an account delegated 1 locked wei, its Cosmos total balance fell from 1 to 0, while its spendable balance was 0 both before and after the delegation. The EVM synchronization logic nevertheless computed 0 - 1, and the EVM-side balance underflowed to MAX_UINT256.
The attacker abused this vulnerability to underflow their own attack contract's EVM balance to MAX_UINT256. However, this anomalous amount could not be transferred out normally. The attack contract then sent a precisely calculated, enormous value to the staking module account holding a large amount of real TAC, causing that account's balance to overflow to zero during addition. Once the same value was deducted from the attack contract, it was left with approximately the module account's original TAC balance. Through this transfer operation, about 2.986 billion TAC was re-credited to the attack contract, then transferred out and bridged to BNB Chain.
Moonwell: ~$9.1M
On August 27, 2026, Moonwell on Base suffered an attack, resulting in a loss of approximately $9.1 million.
The attack manipulated the oracle price Moonwell used to value MAMO collateral. MAMO had extremely limited market liquidity, meaning concentrated purchases could move its price substantially. Moonwell also assigned it a 50% collateral factor, allowing a price increase to translate directly into significant borrowing capacity.
The attacker bought approximately 94.31 million MAMO across multiple DEXes, pushing up market execution prices and driving the Chainlink MAMO/USD feed from about $0.0106 to a peak of $0.4313, a 3,970% increase. The highest price Moonwell used for collateral valuation was approximately $0.4025, about 3,698% above the pre-attack level. The attacker then formally supplied about 15.09 million MAMO and transferred another 53.39 million directly to the mMAMO contract to circumvent the supply cap. The attacker's mMAMO ultimately represented approximately 55.51 million MAMO. At Moonwell's peak accepted price of $0.4025, the collateral was valued at about $22.34 million, providing approximately $11.17 million of borrowing capacity. The attacker completed 18 borrows totaling $11.03 million and subsequently moved about $8.73 million in USDC to Ethereum.
The incident demonstrates the vulnerability of oracle-based lending markets to low-liquidity collateral. When an asset can be moved with limited capital, relying on its market price while assigning a high collateral factor can convert a temporary price distortion directly into protocol bad debt. Lending protocols should set collateral factors, supply caps, and borrow caps according to market depth, while applying additional controls for rapid price increases and realistic liquidation capacity.
Term Finance: ~$8.47M
On August 23, 2026, Term Finance Meta Vaults on Ethereum were drained in a governance takeover, losing roughly $8.47 million.
The root cause was a governance threshold that no longer matched the actual value it was supposed to protect. A Meta Vault spreads deposits across a set of strategy vaults, each governed by its own Aragon DAO. To vote, users had to opt in by wrapping their vault shares into a governance token, and a proposal's minimum participation threshold was measured against that wrapped supply rather than total shares outstanding. Because almost no one wrapped their shares, the seven-day timelock and veto mechanism were still technically active, but the pool of eligible voters they depended on had shrunk to almost nothing.
With this gap open, about 0.5 ETH was enough to buy and wrap sufficient tmvETH to hand the attacker roughly 90.66% of the ETH Meta Vault's voting power. A second address captured the entire active electorate of five USDC strategy vaults with deposits of about $5 each. The attacker then filed twelve proposals disguised as vetoes of parameter changes.
At execution, the proposals reduced the 604,800-second (seven-day) delay to zero, recalled funds from four ETH strategies, and installed a strategy hardcoded to forward assets to the attacker, extracting about 2,841.74 WETH. The attacker then swapped out the controllers and pricing components of the five USDC strategies, zeroed out the reserve ratio, and forced the vaults to buy a worthless repo token at an attacker-set price, extracting a further 1.68 million USDC.
Best Security Auditor for Web3
Validate design, code, and business logic before launch
References
Cosmos EVM multi-chain incident
Moonwell
Term Finance
The information above is based on data available as of 00:00 UTC on September 1, 2026.
This concludes the August security incidents brief.
You can learn more in our Security Incidents Library.
Stay informed and stay secure!



