Daily Observation on Crypto Security: In August, over $188 million was lost on Web3 chains, and Tectonic was severely impacted, reflecting the oracle crisis

Loss Overview: $188 Million Evaporated, Exploit Attacks Dominate
The Web3 on-chain security situation in August remains severe, characterized by "high frequency and large single amounts."
According to statistics from GoPlus, a total of 33 major security incidents were recorded in August, resulting in a cumulative loss of approximately $188.1 million. Although this figure represents a 41% decrease from the shocking losses in July (approximately $319 million), it is still 2.4 times the total loss in June (approximately $77.98 million). Among all types of attacks, "exploit attacks" have become the primary means of profit for hackers, with 28 such attacks occurring that month, leading to direct losses as high as $162.3 million, accounting for over 86% of total losses.
Concentration of Losses Intensifies: Top Five Incidents Account for Over $140 Million
The losses from on-chain security incidents exhibit a strong "head effect," where the collapse of a few protocols often triggers systemic capital outflows.
The report indicates that the five largest security incidents in August collectively caused losses of approximately $141.5 million, accounting for 75.2% of the total losses for the month. This concentration metric is even slightly higher than July's 73.5%. Among them, the most devastating single incident was the hacker attack on the cross-chain lending protocol Tectonic. The attackers drained as much as $75 million in assets from the protocol through precise price manipulation and excessive borrowing vulnerabilities, becoming the biggest security black swan in the Web3 space in August.
Risk Sources: Price Manipulation and Private Key Leaks Become Two Major "Choke Points"
From the classification of specific attack methods, the vulnerabilities of DeFi protocols in price feed mechanisms and infrastructure operations are glaringly exposed.
GoPlus categorizes the risk sources in August into three major disaster areas, which together account for 79% of total losses:
Price manipulation and oracle attacks: Resulting in losses of approximately $83.2 million (with the Tectonic incident as a typical example), indicating that many DeFi protocols still have fatal blind spots in the depth of oracle price feeding and anti-manipulation mechanisms;
Private key leaks and wallet thefts: Resulting in losses of approximately $39.1 million, exposing serious oversights in internal permission management and multi-signature mechanisms by project teams;
Underlying chain and ecosystem vulnerabilities: Resulting in losses of approximately $25.8 million, these types of vulnerabilities that penetrate the underlying public chain often have a broader impact and are extremely difficult to capture completely through regular code audits in advance.
DeFi Infrastructure Urgently Needs "Bulletproof-Level" Upgrades
Comprehensive on-chain security data from August shows that there is still a significant gap between the growth of TVL in the DeFi ecosystem and its security protection capabilities. Hacker attack methods are evolving from simple "code logic searching" to "financial mechanism arbitrage (such as manipulating AMM and oracle price differences)." For the Web3 industry, which is extending an olive branch to traditional institutional funds, if fundamental standard upgrades cannot be achieved in oracle price aggregation, dynamic risk reserves, and physical isolation of multi-signature private keys, the large-scale entry of institutional funds will always face significant trust barriers.
Data source: https://bbx.com/ Cryptocurrency Concept Stock Information Database, compiled based on global listed company announcements and SEC/TSE disclosure documents from yesterday.












