Crypto security losses top $37 million for August 9-15 week

Crypto security incidents caused more than $37 million in confirmed weekly damage between August 9 and August 15, led by a $25.6 million repeat phishing-style drain from an unidentified whale wallet and a $7.9 million coordinated breach at B2B payment processor Coinsbuy. The week also included a suspected unauthorized mint of roughly 4 billion ONE on Harmony Protocol, the theft of about 199,916 XRP from the Coreum-XRPL bridge, an unauthorized ORAI mint on Oraichain and a $136,000 pricing-logic exploit at Ethereum stablecoin protocol USM. The latest losses add to an August already hit by the Coldcard firmware exploit, whose stolen bitcoin cache had climbed above $130 million by mid-month. They also reinforce a broader pattern flagged in CertiK’s H1 2026 report, which said Web3 lost more than $1.31 billion across 344 incidents in the first half, with wallet compromises and infrastructure breaches now producing the biggest losses. The largest single victim this week was a whale address hit on August 12, marking the second major compromise of the same wallet after a $24.2 million loss in September 2023. Researchers have not confirmed whether the latest theft came from signature phishing (tricking users into approving malicious transactions) or a private-key compromise, but the stolen assets were quickly swapped and consolidated, with no funds returned as of mid-week. Elsewhere, Coinsbuy’s losses spanned Ethereum and TRON in what investigators believe was more consistent with a hot-wallet or administrative compromise than a smart-contract exploit. Harmony and Oraichain highlighted the risk of unauthorized minting paths, while the Coreum-XRPL bridge breach showed how weak deposit verification in relayer software can trigger real withdrawals from fake deposits. USM’s exploit, by contrast, came from protocol math that rewarded splitting one redemption into many smaller calls. Taken together, the week’s major incidents pointed to a common theme: the most damaging failures are increasingly happening in keys, permissions, bridge logic, mint controls and pricing design rather than in conventional smart-contract bugs alone.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.