CertiK said confirmed security incidents in August 2026 caused approximately $215 million in losses, including roughly $41.5 million from phishing and $144.6 million in DeFi (decentralized finance). About $110.7 million was later classified as returned or frozen. Price manipulation was the largest category at $131.6 million, driven mainly by the Tectonic lending protocol on Cronos, where an attacker inflated the thinly traded TONIC token and borrowed against the higher collateral value. CertiK’s August total followed $1.32 billion in losses across 344 incidents during the first half of 2026. The firm said the adjusted H1 comparison with 2025 was worse in 2026 after excluding the $1.45 billion Bybit theft from the earlier period. The incidents highlight the continuing risks of using illiquid tokens as collateral, even when protocols do not contain a conventional smart-contract (self-executing blockchain code) bug.