PeckShield Counts 50 August Hacks, CertiK Puts Losses $79M Higher

Fifty crypto hacks were recorded in August, the highest monthly count of 2026, and the money taken fell by about half. The count comes from PeckShield, a blockchain security firm, in a tally published on 1 September. It puts August losses at $136.3 million against roughly $270 million in July, when 30 incidents were logged. CertiK closed its own August book a day earlier and put the month at $215 million. The two totals sit about $79 million apart, and neither firm addresses the other.
One exploit carried the month
Most of August's money went in a single event. PeckShield puts the Tectonic exploit on Cronos at about $74 million, more than half the month's total and the fourth-largest theft of the year on its count. Coin Edition writes it as $74 million to $75 million. CertiK gives a different figure again, a $120.4 million impact, of which roughly $74 million to $75 million escaped before the chain was stopped. This desk's own report on the day carried an estimate of $75 million. Four numbers, one event, and no account reconciles them. Cronos validators later restarted the chain with the exploit rolled back, by which point about $6 million had been bridged to Ethereum.
The count rose while the losses fell
Set Tectonic aside and August reads as a quiet month. The average loss per incident was about $2.7 million, against roughly $9 million in July. PeckShield's top ten accounted for $123.34 million, about 90.5% of the total, which leaves the other 40 incidents sharing something near $13 million. Two of the ten have been covered here already. Moonwell lost $8.7 million to a manipulated collateral price on Base, and Term Labs lost $8.5 million to an attacker who won a governance vote. Coinsbuy at $7.9 million and TAC at $7.5 million fill out the visible end of the list. April is still the costliest month of the year, at about $646.9 million.
Two firms, two books
The gap between the totals is a difference in method. PeckShield counts what it calls major hacks and names them. CertiK's month includes categories that PeckShield's named list does not: phishing at $41.5 million, wallet compromise at $11.8 million, code vulnerabilities at $20.6 million, DeFi at $144.6 million and governance at $8.5 million. Those five add to $227 million against a stated total of $215 million, so the buckets overlap somewhere, and CertiK does not say where. Its price-manipulation line, $131.6 million, cuts across the others. Timing separates the two books as well. CertiK published on 31 August, before the month had finished; PeckShield published on 1 September, after it had. We could not establish whether the two cover the same days.
Numbers that may yet be revised
CertiK says $110.7 million of August's losses were returned or frozen, a figure PeckShield's report does not carry. That matters most for Tectonic. If the Cronos rollback holds, the bulk of the money never left, and the month's headline number describes an attempt as much as a loss. Neither firm has published a restatement. Coin Edition, alone among the accounts reviewed, reports that TRM Labs counted 32 price-manipulation exploits during 2026, its highest annual count, and puts first-half incidents at 207; CertiK's own half-year book gives 344 incidents and $1.32 billion. Different providers, different definitions, and nothing published lets the two be compared. The test in the next few weeks is whether either firm goes back and rewrites August once the recovered funds are settled.
Read also: Cosmos Labs Says It Misgraded the Bug Behind a $5.7M Six-Chain Hack