Wave of DeFi Hacks: More Markets and Tectonic Lose $168 Million in One Week

August 2026 became a black month for the DeFi industry: two major protocols lost a combined $168 million in coordinated attacks. More Markets lost $93 million through a vulnerability in its lending reserve, while Tectonic on the Cronos network lost $75 million, leading to a complete network shutdown.

Total damage: $168 million in a single week. More Markets: $93M through exploitation of its lending protocol. Tectonic: $75M, with the Cronos network halted to prevent further losses.

🏦 More Markets: $93 Million From Lending Reserves

DeFi lending protocol More Markets became the victim of a sophisticated attack in which attackers drained $93 million from protocol reserves. The attack took place on August 24, 2026 and exploited a vulnerability in the liquidity management mechanism.

⚙️ Exploit Mechanism

The attackers discovered a flaw in the logic used to calculate collateral ratios and liquidation thresholds. Through a series of manipulative transactions, they created artificial conditions that allowed them to withdraw funds from lending pools without sufficient collateral.

The attack involved several stages:

  • Price manipulation: Using flash loans to temporarily manipulate price oracles
  • Position creation: Opening leveraged positions with artificially inflated collateral
  • Liquidation cascade: Triggering a cascade of liquidations to extract funds
  • Asset withdrawal: Rapidly moving stolen funds through cross-chain bridges

💸 Distribution of Stolen Funds

Analysis of on-chain data showed the following breakdown of losses:

  • USDC: $42 million (45% of the total)
  • USDT: $28 million (30%)
  • ETH: $15 million (16%)
  • Other tokens: $8 million (9%)

The attackers quickly converted the stolen assets into ETH and began laundering them through Tornado Cash and other mixers. Some of the funds were transferred to centralized exchanges, which led to temporary freezes.

Team response: More Markets immediately suspended all protocol operations and launched an investigation. The team contacted exchanges and asked them to freeze suspicious accounts, while also offering a 10% reward for information leading to the recovery of the funds.

🌐 Tectonic and Cronos: $75 Million and a Network Shutdown

Almost simultaneously with the More Markets attack, Tectonic on the Cronos network suffered an even more serious incident. Attackers drained $75 million, prompting an unprecedented decision — a complete shutdown of the Cronos network.

⚡ Incident Timeline

The Tectonic attack occurred on August 25, 2026 and developed rapidly:

  1. 03:42 UTC: Security monitors detected the first suspicious transactions
  2. 03:58 UTC: The Tectonic team confirmed the exploit and began emergency response measures
  3. 04:15 UTC: A decision was made to halt the Cronos network
  4. 04:30 UTC: The network was fully stopped and all transactions were suspended

🔍 Technical Analysis of the Vulnerability

The Tectonic exploit used a more complex attack vector than the More Markets incident. The attackers discovered a vulnerability in smart contract logic related to the cross-chain bridging mechanism.

Key elements of the attack included:

  • Reentrancy vulnerability: Exploiting a reentrancy flaw to withdraw funds multiple times
  • Oracle manipulation: Manipulating price feeds to create favorable conditions
  • Logic flaw: Exploiting an error in the business logic used to calculate interest
  • Bridge exploitation: Using a vulnerability in the cross-chain bridge to move assets out

🛑 Cronos Network Shutdown: An Unprecedented Measure

The decision to halt the entire Cronos network was an extraordinary measure rarely seen in the blockchain industry. It was necessary to:

  • Prevent further losses: Stop all transactions to protect remaining funds
  • Preserve evidence: Freeze the network state for subsequent analysis
  • Coordinate the response: Buy time to develop a response strategy
  • Prevent panic: Avoid mass withdrawals by users

Scale of the decision: Halting an entire L1 network is an extremely rare measure. The last comparable case was the Ethereum DAO hack in 2016. This demonstrates the seriousness of the situation and the team's determination to protect users.

🔗 Common Attack Patterns

Analysis of both incidents revealed several common patterns that may indicate coordination or the use of similar techniques.

🎯 Similar Attack Vectors

Both attacks involved:

  • Oracle manipulation: Manipulating price oracles to create favorable conditions
  • Flash loans: Using flash loans to obtain temporary liquidity
  • Cross-chain bridges: Rapidly moving funds through bridges for laundering
  • Mixers and tumblers: Using Tornado Cash and similar services

⏰ Timing of the Attacks

Notably, both attacks occurred within a 24-hour period:

  • More Markets: August 24, 14:23 UTC
  • Tectonic: August 25, 03:42 UTC
  • Difference: Less than 14 hours between the attacks

This close timing may indicate a coordinated effort or suggest that the same group used similar exploit kits against different protocols.

🎭 Choice of Targets

Both protocols had characteristics that made them attractive targets:

  • High TVL: More Markets ($450M TVL) and Tectonic ($380M TVL) held significant reserves
  • Complex logic: Both relied on complicated business logic with many moving parts
  • Cross-chain functionality: Bridges created additional attack vectors
  • Relative novelty: Both protocols were launched in 2024-2025

📊 DeFi Hack Statistics in 2026

These incidents occurred against the backdrop of a broader increase in DeFi hacks throughout 2026.

📈 Overall Statistics

According to various security firms:

  • Total in 2026: $1.2 billion lost in DeFi hacks
  • August 2026: $280 million lost, including these two incidents
  • Average hack size: $8.5 million
  • Number of incidents: 142 during the year

🎯 Most Vulnerable Sectors

Losses by protocol type were distributed as follows:

  • Lending protocols: 34% of all losses ($408M)
  • DEXes: 28% ($336M)
  • Bridges: 22% ($264M)
  • Yield aggregators: 16% ($192M)

2026 trend: Lending protocols remain the most vulnerable sector because of their complex logic and large pools of locked capital. Attackers increasingly focus on protocols with more than $100M in TVL.

🛡️ Response From the Teams and the Ecosystem

Both teams responded quickly, taking a series of measures to minimize losses and protect users.

🚨 Immediate Actions by More Markets

The More Markets team took the following steps:

  1. Protocol suspension: All protocol functions were immediately halted
  2. Public statement: Transparent communication with users
  3. Exchange outreach: Requests to freeze suspicious accounts
  4. Bug bounty: A 10% reward ($9.3M) offered for the return of funds
  5. Forensic analysis: External security firms brought in to investigate

🛑 Emergency Measures by Tectonic and Cronos

The Tectonic team and the Cronos network took more radical measures:

  1. Network shutdown: Complete halt of the Cronos network
  2. Emergency governance: Emergency validator vote
  3. Communication: Regular updates for the community
  4. Recovery plan: Development of a network restart strategy
  5. Compensation: A promise to compensate affected users

🤝 Response From the Broader Ecosystem

The wider crypto community actively responded to the incidents:

  • Security firms: PeckShield, CertiK and others published attack analyses
  • Exchanges: Binance, Coinbase and others froze suspicious addresses
  • Other protocols: Many DeFi projects conducted emergency audits
  • Regulators: Increased scrutiny of DeFi security

🔮 Implications for the Industry

These hacks have significant implications for the broader DeFi ecosystem and its approach to security.

📉 User Confidence

The incidents may affect user confidence in several ways:

  • Liquidity outflows: Users withdrawing funds from DeFi protocols
  • Lower TVL: Overall DeFi TVL potentially declining by 5-10%
  • Growing skepticism: Increased concern about DeFi security
  • Migration to traditional finance: Some users returning to TradFi

🛡️ Stronger Security Practices

The industry is responding by strengthening security measures:

  • More audits: Increased frequency and depth of security audits
  • Bug bounty programs: Expansion of vulnerability reward programs
  • Insurance protocols: Growing popularity of DeFi insurance
  • Real-time monitoring: Deployment of advanced monitoring systems

⚖️ Regulatory Attention

The hacks are attracting regulatory attention:

  • Increased scrutiny: Closer oversight of DeFi protocols
  • New requirements: Possible introduction of mandatory security standards
  • Consumer protection: Stronger protections for users
  • International coordination: Greater cooperation between regulators

Regulatory trend: Following a series of major hacks in 2026, regulators in the United States and European Union are considering mandatory security audits for DeFi protocols with more than $50M in TVL.

🎓 Lessons for DeFi Projects

These incidents contain important lessons for DeFi projects and developers.

🔒 Technical Lessons

  1. Multiple audits: One audit is not enough — two or three independent audits may be necessary
  2. Formal verification: Use formal methods for critical components
  3. Bug bounty: Active bug bounty programs can identify issues that audits miss
  4. Gradual rollout: Increase TVL limits gradually after launch
  5. Emergency plans: Maintain predefined incident response procedures

🏗️ Architectural Lessons

  1. Minimize complexity: Simpler logic is generally easier to secure
  2. Defense in depth: Multiple layers of protection are critical
  3. Circuit breakers: Automatic shutdown mechanisms when anomalies are detected
  4. Rate limiting: Limits on the speed and volume of operations
  5. Oracle diversity: Using multiple independent oracle sources

👥 Operational Lessons

  1. 24/7 monitoring: Continuous monitoring of all critical protocol components
  2. Rapid response: Ability to react quickly to security incidents
  3. Transparent communication: Open communication with users
  4. Community engagement: Active collaboration with the community
  5. Continuous improvement: Ongoing improvement of security practices

📊 Economic Impact

These hacks have significant economic consequences for different stakeholders.

💰 Direct Financial Losses

Immediate financial consequences include:

  • Protocols: $168M in stolen funds
  • Users: Lost investments and yield
  • Investors: Declining protocol token values
  • Insurance providers: Payouts on covered losses

📉 Indirect Economic Effects

Broader economic consequences include:

  • Lower TVL: Overall capital outflows from DeFi
  • Slower innovation: More cautious launches of new protocols
  • Higher costs: Increased security spending across the industry
  • Market sentiment: Negative effects on broader market confidence

🏦 Institutional Consequences

Potential effects on institutional adoption include:

  • Slower adoption: Institutions may delay entering DeFi
  • Greater due diligence: Stricter pre-investment assessments
  • Insurance requirements: Mandatory insurance coverage in some institutional frameworks
  • Regulatory compliance: Stronger compliance requirements

🔍 Comparison With Previous Major Hacks

For context, these incidents can be compared with other major DeFi hacks.

📊 Historical Perspective

Comparison with notable DeFi hacks:

  • Ronin Bridge (2022): $625M — the largest hack in history
  • Wormhole (2022): $320M — bridge exploit
  • Nomad (2022): $190M — bridge vulnerability
  • Mango Markets (2022): $114M — oracle manipulation
  • More Markets (2026): $93M — lending protocol exploit
  • Tectonic (2026): $75M — cross-chain vulnerability

🎯 Evolution of Attack Vectors

Attack techniques have evolved over time:

  • 2020-2021: Simple smart contract bugs
  • 2022: Bridge exploits and oracle manipulation
  • 2023-2024: Economic attacks and governance exploits
  • 2025-2026: Sophisticated multi-vector attacks

Trend: Attacks are becoming increasingly sophisticated and complex. Attackers combine multiple techniques and exploit several vulnerabilities at once.

💎 Conclusion: Challenges and Opportunities

The More Markets and Tectonic hacks, totaling $168 million, are a sobering reminder of the persistent security challenges facing the DeFi industry. Despite years of development and billions of dollars in TVL, DeFi protocols remain vulnerable to sophisticated attacks.

Key lessons from these incidents include:

  1. Security is a continuous process: A protocol can never simply be considered "secure enough"
  2. Complexity is the enemy of security: Simpler systems are generally easier to secure
  3. Proactivity is critical: Prevention is cheaper than incident response
  4. Transparency builds trust: Open communication strengthens confidence
  5. Community collaboration: Collective efforts improve ecosystem-wide security

For the DeFi industry, these incidents represent both a challenge and an opportunity. The challenge lies in continuously improving security practices and rebuilding user confidence. The opportunity lies in accelerating development of more robust and secure solutions.

Strategic lesson: The maturity of the DeFi industry will be determined not by the complete absence of hacks, but by its ability to respond quickly, learn from incidents and continuously improve security practices.

For users, these incidents serve as a reminder of the importance of due diligence and risk management. DeFi offers significant opportunities, but it also carries substantial risks. The most successful users will be those who understand those risks and take appropriate precautions.

For developers and projects, the hacks underscore the critical importance of a security-first approach. Investment in security is not simply an expense, but an essential investment in a project's long-term viability and success.

The future of DeFi security lies in continued innovation, collaboration and education. As technology becomes more sophisticated, security practices must evolve alongside it. An industry that learns from each incident and continuously improves will be better positioned for long-term success and mainstream adoption.

Ultimately, the DeFi revolution continues, and security remains one of its critical foundations. Every hack, however painful, provides valuable lessons and moves the ecosystem closer to becoming safer and more robust. The question is not whether future attacks will occur — they are inevitable. The question is how well prepared the industry will be and how quickly it can respond.

“In the world of DeFi, security is not an option but the foundation. A protocol without reliable security is a castle built on sand.”

— Andreas Antonopoulos, blockchain technology expert

01.09.2026, 01:05