Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

Term Finance loses $8.5 million to governance attack

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure

Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."

KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.

BounceBit exploited for $3 million, announces shutdown and migration

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

$1.76 million stolen from MAYAChain in attack exploiting six bugs

The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.

Ravencoin rolls back blockchain after exploit

Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.

Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.

Harmony token plunges 40% after unauthorized mint

An attacker was able to exploit the Harmony blockchain to mint 4 billion of the network's $ONE token. The massive increase in token supply caused the token price to plunge 40%.

Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback — that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.

This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North Korean hacking groups.

Coinsbuy exploited for $8 milllion

The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.

Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.

Step App "move-to-earn" project shuts down

Step App, one of the last surviving "move-to-earn" projects from the 2022 crypto fitness fad, announced it will shut down all services on August 21. The project advertised itself as a "fitness app that pays you", and was essentially a step counter that paid crypto rewards. Users had to first buy the Step App's FITFI token to purchase an NFT representing sneakers, then were rewarded with the project's KCAL tokens for each minute they spent moving — although the number of minutes that would generate rewards were capped, often at just a few minutes, and required more NFTs to increase.

Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.

Proof of Attendance Protocol (POAP) shuts down

Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.

The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.

Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."

Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets

"Coldcard" in boxy red typeColdcard logo (attribution)
Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.

An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research.

Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built".

Two arrested after Flare Network staking site scammed users out of 3.4 million XRP (~$8.5 million)

South Korean police say scammers running a fake staking website under the name of the real Flare Network took 3.4 million XRP (~$8.5 million) from 71 investors. It's possible the scammers stole closer to $19 million. Victims were promised guaranteed returns of 1.5% to 1.8% a month; the site was only live for about a week in October 2025 before the operators disappeared with the deposits.

Two men were arrested on fraud charges, and Korean police are seeking a third. They reportedly advertised the scam project via YouTube and online articles.