Moonwell loses $8.7 million to fourth exploit in less than a year

An attacker stole around $8.7 million from the Moonwell defi lending protocol after manipulating the price of an illiquid token called MAMO. After pumping the MAMO token price, they "borrowed" various assets and abandoned the overinflated collateral.

This theft is the fourth Moonwell exploit in less than a year, following a $3.7 million oracle manipulation attack in November 2025, another oracle attack in February 2026 amounting to $1.78 million, and a $1 million governance attack in March.

Term Finance loses $8.5 million to governance attack

Ethereum lending protocol Term Finance lost around $8.5 million when an attacker purchased the majority of the project's governance token — which was not widely held — and then voted themselves to be the controller of the project's vaults. Although the project has governance safeguard, including a timelock and veto procedure, neither went into effect for reasons the project has yet to explain.

The attacker withdrew around 2,843 ETH (~$6.9 millon) and $1.68 million in the USDC stablecoin, amounting to about 68% of assets on the platform.

Term Finance previously lost $1.65 million to an oracle misconfiguration error in April 2025, but recovered $1 million of the funds.

KiiChain, TAC, and other Cosmos-based blockchains exploited after "negligent" vulnerability disclosure

Multiple blockchains based on the Cosmos chain suffered exploits after Cosmos Labs publicly disclosed a vulnerability in the Cosmos EVM. Some have criticized Cosmos for "negligence" in their vulnerability management. KiiChain, one of the affected chains, wrote in their postmortem, "This loss was avoidable. ... Publishing a security fix in the open, before the chains running that code have been told privately and given time to patch, hands the vulnerability to anyone reading the commit. Standard responsible disclosure exists precisely to prevent this. Cosmos Labs gave no advance notice to downstream chains, did not flag the release as security critical, and did not tell affected chains that a public release had happened until Friday 21 August, two days later."

KiiChain was exploited for around 148 million KII, which the attacker was able to cash out for around $1.6 million. TAC, a Telegram-focused blockchain, was exploited for about 3 billion TAC (~$7.5 million). Nesa Chain was exploited, and though an attacker was able to steal tokens nominally worth $50 million, lack of liquidity limited their profits to around $60,000. A blockchain called MANTRA also halted due to an exploit, but the network said that no user funds were impacted.

BounceBit exploited for $3 million, announces shutdown and migration

An attacker took advantage of a bug in the authorization logic for the BounceBit layer-1 blockchain, allowing them to transfer around 286.5 million BB (~$3 million) from nine wallets. BounceBit halted the blockchain shortly after, then later announced they would be permanently shutting down the chain and reissuing tokens on Binance's BNB Chain. "Maintaining a standalone Layer 1 is no longer the most effective way to serve our users," they said. They explained that it would be challenging to patch the underlying flaw because the chain was based on Evmos, an Ethereum blockchain implementation that was shut down in May.

BounceBit, a bitcoin restaking protocol, raised $6 million in seed funding in 2024 from Blockchain Capital, Breyer Capital, Bankless Ventures, OKX Ventures, HTX Ventures, and others.

$1.76 million stolen from MAYAChain in attack exploiting six bugs

The Maya Protocol announced that an attacker had stolen 20 BTC (~$1.4 million) and various other assets totaling $1.76 million. A postmortem disclosed that the "sophisticated attacker exploited six chained bugs" to steal the assets. "The bugs exploited were not caught by Halborn audit, nor Fable 5 audit", wrote Maya founder on Twitter. Halborn is a blockchain security firm; Fable 5 is an AI model developed by Anthropic.

Ravencoin rolls back blockchain after exploit

Attackers exploited a vulnerability in Ravencoin, a blockchain based on the bitcoin codebase, to mine invalid blocks. Although Ravencoin subsequently patched the bug, the blockchain contains roughly four days of invalid history.

Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior to the invalid blocks. This is a controversial move in the crypto world, where immutability is considered sacrosanct. It's also disruptive, because legitimate transactions during that time period will be undone, with coins returned to the origin wallets. Several exchanges have halted RVN withdrawals and deposits, anticipating potential issues.

Harmony token plunges 40% after unauthorized mint

An attacker was able to exploit the Harmony blockchain to mint 4 billion of the network's $ONE token. The massive increase in token supply caused the token price to plunge 40%.

Harmony paused its token bridge and asked exchanges to freeze tokens coming from four addresses connected to the attacker. They also said they were considering a possible rollback — that is, reverting the blockchain to a pre-attack state, undoing all transactions since that point. This is a very controversial choice in the crypto world, where blockchains are prized for their immutability. It also becomes less effective if attackers are able to move tokens off the network before the rollback happens.

This is the second time Harmony has had mint-related issues. In January 2024, a bug caused around 150 million $ONE to erroneously be minted and distributed to 79 wallets. And in June 2022, Harmony suffered a $100 million theft, later attributed by the US FBI to North Korean hacking groups.

Coinsbuy exploited for $8 milllion

The Coinsbuy crypto platform was exploited for around $8 million across both the Ethereum and Tron blockchains. The attacker was able to steal the funds from eight wallets belonging to the exchange. The wallets were later replenished by Coinsbuy, suggesting that the attack vector did not involve compromising the wallets themselves.

Coinsbuy has said that the vulnerability has been addressed, and offered a $100,000 "bounty" for the returned funds.

Step App "move-to-earn" project shuts down

Step App, one of the last surviving "move-to-earn" projects from the 2022 crypto fitness fad, announced it will shut down all services on August 21. The project advertised itself as a "fitness app that pays you", and was essentially a step counter that paid crypto rewards. Users had to first buy the Step App's FITFI token to purchase an NFT representing sneakers, then were rewarded with the project's KCAL tokens for each minute they spent moving — although the number of minutes that would generate rewards were capped, often at just a few minutes, and required more NFTs to increase.

Holders of the project's FITFI and KCAL tokens have two weeks to cash out, although they're not likely to recoup much. FITFI trades at fractions of a cent, and KCAL trades at $0.01 — far below its $1–$4 prices from the project's peak in 2022 and 2023. Holders of Step NFTs are likely similarly out of luck.

Proof of Attendance Protocol (POAP) shuts down

Proof of Attendance Protocol, or POAP, was a darling of the web3 hype cycle and supposed proof of the utility of NFTs. "Using blockchain technology, POAP tokenizes your memories, so they can last forever and be truly yours," the website gushes, presenting a solution to a problem I previously did not realize I had.

The tokens were typically issued as souvenirs from crypto conferences or other events, and were supposed to function as cryptographically verifiable proof that the owner attended an event. The fact that the POAPs were tradable of course undermined this somewhat, but nevertheless the crypto world had come up a number of reasons why POAPs would be the future of event planning and digital identity and all kinds of things.

Now, the project's co-founder has announced that "Unfortunately, crypto's funding cycles and distribution dynamics made it hard to build a sustainable company without cannibalizing the ethos that made POAP mean something. Building on a fragile and quickly evolving stack, in the middle of an incredible hype cycle, only added to the challenges."