Introduction
August 2026 saw attackers steal approximately $162 million across the 27 major incidents analysed in this report, spanning DeFi lending and liquidity protocols, cross-chain bridges, a crypto payment platform, a self-custodial wallet, and a single, large-scale phishing loss against a private individual.
The month's loss profile was reshaped on its final weekend by a single event. On 30 August, an attacker manipulated the price of TONIC, the thinly traded governance token of Cronos lending protocol Tectonic, pumping it roughly 100-fold in about 20 minutes, then posted the inflated token as collateral to borrow real assets out of Tectonic's lending pools. Cronos Network halted block production across the entire chain to contain the damage, an option available to it because Cronos runs a Tendermint-based consensus capped at 100 validators, small enough to coordinate a shutdown within minutes. The halt meant only around $6 million of the roughly $74 million taken reached Ethereum before the chain froze; the remaining approximately $68 million sits stranded on Cronos across attacker-controlled addresses, pending recovery. On its own, Tectonic accounted for close to half of August's total losses.
Even setting Tectonic aside, the remaining 26 incidents produced approximately $88.0 million in losses, broadly in line with the underlying run rate seen across recent months. The largest of these was a $25.6 million phishing attack against a private wallet, followed by Maya Protocol's $17 million smart contract exploit, a reminder that user-targeted social engineering can rival protocol-level exploits in scale even in a month otherwise defined by a single large DeFi incident.
Beyond Tectonic, a second consistent theme was the reappearance of governance and price-oracle manipulation as attack surfaces. Term Finance's $8.5 million loss, in which an attacker cheaply acquired a majority of a thinly held DAO governance token to redirect vault funds, and Moonwell's $8.75 million price manipulation attack both point to governance and collateral-pricing mechanisms as a growing risk category, distinct from both classic smart contract bugs and outright credential theft. Access control and credential compromise also featured prominently, most notably at Coinsbuy, where wallets linked to the crypto payment platform were drained across Ethereum and TRON and proceeds laundered toward Monero.
Cross-chain infrastructure remained a recurring target, with Coreum Bridge, Oraichain and Allbridge all affected, though with markedly different real-world impact; Oraichain's exploit was caught and halted before any funds were realised as loss. Tornado Cash reappeared as a laundering venue in the month's largest governance attack, while the Coinsbuy incident marked a notable shift toward Monero as a preferred off-ramp. The month's final two incidents, Tectonic and a $2.5 million exploit of Solana AMM Aquifer within 24 hours of each other, both saw the affected protocol pursue negotiated recovery of funds rather than relying solely on external investigators: Cronos halted its chain outright, while Aquifer issued a cryptographically authorised on-chain whitehat offer directly to the attacker's own addresses.
Major crypto attacks in August 2026
MOKE Token - 02/08/2026
Type: Access Control
An attacker abused an unprotected public claim() function in the MOKE token's release contract on BNB Chain, repeatedly draining tokens from the protocol's internal reserve pool with no eligibility check on the caller. The attacker then used flash loans, Venus leverage, LP removal and dividend distribution mechanics to convert the drained MOKE into wrapped BNB.
Impact: $907,000
LOOPSDAO - 02/08/2026
Type: Oracle Issue
LOOPSDAO's LpdFi protocol on BNB Smart Chain was exploited through price manipulation. The attacker reused the same manipulable PancakeSwap pair reserves for both order valuation and interest redemption, inflating a position's principal before reshaping the pool to redeem an oversized interest claim.
Impact: $573,000
RiseX - 03/08/2026
Type: Smart Contract Exploit
An unauthorised withdrawal occurred from the real-world-asset strategy linked to RISEx's XLP vault, traced to a misconfiguration present since the strategy's deployment on 13 July. The team detected the issue within minutes, patched it the same day, and fully compensated affected depositors using a portion of the platform's July fees.
Impact: $673,000
Unistreets - 06/08/2026
Type: Smart Contract Vulnerability
Unistreets' LaunchpadFactoryAuto contract on Ethereum was exploited through arbitrary calldata injection. The factory custodied the Uniswap V4 LP NFTs of every token launched through it; the attacker injected an approval and burned multiple LP positions, draining liquidity from launched projects.
Impact: $17,750
RRWallet - 06/08/2026
Type: Supply Chain Attack
Security firm Coinspect disclosed that RRWallet, an open-source, multi-currency wallet app, generated vulnerable seed phrases due to a weak random number generator in a bundled JavaScript library. The flaw made private keys predictable, and at least one user lost approximately $2 million as a result.
Impact: $2,000,000
Atomic Green - 08/08/2026
Type: Signature Replay Attack
Atomic Green, a non-custodial leveraged trading protocol on Arbitrum, was hit by a signature replay flaw. The same manager signature could be reused across 21 separate Uniswap V3 LP positions, and paired with flash-loan price manipulation, this let the attacker trigger unauthorised full LP burns, draining roughly 29,984.27 USDC.
Impact: $29,984
Coreum Bridge - 09/08/2026
Type: Bridge Logic Vulnerability
The cross-chain bridge connecting the XRP Ledger and Coreum was exploited after an attacker abused a flaw in the bridge's deposit-verification and relayer logic. By creating fake deposits, self-transfers of the bridge's own wrapped tokens carrying valid memos, the attacker tricked relayers into authorising genuine XRP withdrawals from the bridge's reserve.
Impact: $200,000
Oraichain - 09/08/2026
Type: Cross-Chain Bridge Exploit
Oraichain, an AI-focused Layer 1 blockchain, suffered a vulnerability in its EVM cross-chain transfer path that enabled unauthorised minting of ORAI tokens. The network was halted from 04:00 UTC, with bridges, cross-chain routes and public interfaces restricted while the team burned the unauthorised balances and reconciled protocol state. No realised loss has been reported.
Impact: $0
Coinsbuy - 09/08/2026
Type: Access Control
Wallets linked to Coinsbuy, a business-focused crypto payment and wallet infrastructure platform, were drained near-simultaneously across Ethereum and TRON. Security researchers assessed the pattern as consistent with hot wallet private key or administrator privilege compromise, though the exact root cause remains unconfirmed. The attacker began converting proceeds toward Monero; the exchange ChangeNOW froze a six-figure sum in transit before conversion was complete, with the remainder also routed through FixedFloat and BingX.
Impact: $7,900,000
USM - 10/08/2026
Type: Smart Contract Vulnerability
USM was exploited through a pricing flaw in defund(): its ethFromDefund() function isn't "split invariant," so redeeming FUM in many small calls extracts more value than one large redemption. Combined with per-redemption state contraction (adjShrinkFactor) and rounding, an attacker used a flash loan to manipulate pricing via fund(), then split a redemption into 64 small defund() calls, draining roughly 70.83 ETH.
Impact: $136,000
Harmony Protocol - 11/08/2026
Type: Protocol Logic Vulnerability
Harmony suffered a breach in its cross-shard receipt validation, allowing an attacker to mint unauthorised ONE tokens using forged receipts. Harmony has proposed a network rollback to a pre-exploit checkpoint, which would nullify most of the fraudulently minted supply.
Impact: $3,200,000 (provisional, pending Harmony’s post-mortem review)
Whale Wallet Drain - 13/08/2026
Type: Phishing
A single private individual lost approximately $25.6 million after being targeted in a phishing attack, the largest single loss of the month. The incident underscores that user-targeted social engineering can now rival or exceed protocol-level exploits in scale.
Impact: $25,600,000
FoxMarket - 15/08/2026
Type: Flash Loan Attack
A flash loan attack was reported against a project referenced as "FoxMarket," describing itself as a triple-token DeFi ecosystem spanning prediction markets and on-chain trading. The vulnerability sat in FoxLpBondsPool.stake(), which calculated its stake amount from a manipulable PancakeSwap spot price before executing its own large USDT-to-FOX swap, an action that itself skewed the pool's reserves. Because the stake amount was never recalculated against the actual post-swap deposit or the fair value of the resulting LP tokens, Treasury.lpBonds() went on to mint FOX against that stale, unsupported figure and sent a referral reward straight to an attacker-controlled address. The attacker then sold the newly minted FOX back into the pool within the same transaction, using flash-loan liquidity to scale up the exploit. At its core, the incident came down to three missing safeguards: manipulation-resistant pricing, a check between accounted value and actual backing, and a delay on reward settlement.
Impact: $118,700
Maya Protocol - 18/08/2026
Type: Smart Contract Vulnerability
Maya Protocol, a cross-chain liquidity protocol forked from THORChain, suffered one of the month's largest losses after a single transaction chained together six separate software bugs spanning trade account handling, outbound transaction processing and liquidity pool calculations. MAYAChain halted its network in response.
Impact: $17,000,000
Allbridge - 19/08/2026
Type: Bridge Logic Flaw
Allbridge, a cross-chain bridge supporting stablecoin transfers across more than twenty networks, suffered a bridge logic exploit. Allbridge's architecture has previously been flagged for a separate, standing centralisation risk: a privileged owner account with the ability to alter most system contracts and drain pooled liquidity, independent of this specific incident.
Impact: $190,000
The Sandbox - 21/08/2026
Type: Smart Contract Vulnerability
An attacker hijacked LayerZero delegate permissions through an approveAndCall function on The Sandbox's Base and BNB Smart Chain bridges, minting SAND tokens with no real backing. Security researchers put the nominal face value of the minted tokens at close to $49 billion across more than four hundred transactions, though the real, realisable impact was far smaller. The Sandbox disabled bridging on both affected networks; SAND on Ethereum and Polygon, along with the assets backing it, were unaffected. The Sandbox has said it will repay affected liquidity providers on a one-to-one basis.
Impact: $675,000
TAC - 22/08/2026
Type: Contract Vulnerability
TAC, a sovereign Layer 1 blockchain providing EVM compatibility bridged into the TON and Telegram ecosystem, suffered a contract vulnerability. An exploited a flaw in the shared Cosmos EVM precompile layer (not TAC-specific code) to drain a single account on TAC. The chain was halted at block 24,671,475. It was a drain, not a mint: total supply is unchanged, with 2,985,651,403 TAC moved between accounts and no other assets affected. Several other chains on the same Cosmos EVM module were hit by similar attacks within a day. TAC is finalising a postmortem and relaunch plan, working with SEAL 911 and exchanges on the moved funds.
Impact: $7,500,000
warp.green - 23/08/2026
Type: Smart Contract Vulnerability
warp.green, a cross-chain messaging protocol connecting Chia to Ethereum and Base, suffered a smart contract vulnerability affecting its ERC-20 bridge, which wraps assets moving between the two ecosystems.
Impact: $93,000
Arrakis V1 - 23/08/2026
Type: Flashloan Price Manipulation
An Arrakis V1 liquidity-manager vault pairing ENS and WETH was drained through Uniswap V3 spot price manipulation. The attacker flash-loaned 1,800 WETH from Morpho Blue, skewed the pool's instantaneous spot price, minted vault shares at the distorted valuation, restored the price, and burned the shares for a richer mix of underlying tokens. The root cause was that the vault's mint and burn functions valued the underlying Uniswap V3 position directly off the pool's spot price with no time-weighted average price or deviation guard, a protection that only covered the vault's separate rebalancing function.
Impact: $7,018
Term Finance Vaults - 23/08/2026
Type: Governance Attack
Term Finance's Strategy Vaults, ERC-4626 tokenised vaults built on Yearn V3 infrastructure, were drained after an attacker bootstrapped the exploit with roughly 2 ETH withdrawn from Tornado Cash, then cheaply acquired a majority of a thinly held DAO governance token controlling the vaults. With that voting majority secured, the attacker passed proposals that redirected vault funds, draining ether and USDC that was later swapped into DAI. Term's underlying lending and borrowing markets were unaffected. The protocol suffered a smaller, unrelated incident in April 2025 involving an oracle misconfiguration, which was later substantially recovered and reimbursed.
Impact: $8,500,000
Enjin - 25/08/2026
Type: Smart Contract Vulnerability
Enjin, an end-to-end NFT and gaming product ecosystem, suffered a smart contract vulnerability. The protocol allows adapters with different storage layouts to execute within the Managed Delegate Proxy's storage context via DELEGATECALL, and this created a storage slot collision: a registered adapter's public initialize(uint256) function writes to slot 1, while the proxy also uses slot 1 to store pendingManager. An attacker exploited this collision by invoking the adapter's initialize(uint256) through DELEGATECALL, writing their own address into the proxy's pendingManager slot, then simply called acceptManager() to complete the takeover and gain managerial control of the protocol. Once in control, the attacker registered a malicious adapter to steal victims' assets, routing them through the melt(0xf6089e12) path for liquidation.
Impact: $162,000
CometDEX - 25/08/2026
Type: Smart Contract Vulnerability
CometDEX, an open-source, Balancer-style weighted automated market maker built on Stellar's Soroban smart contract layer, suffered a smart contract vulnerability.
Impact: $717,518
FH Token - 26/08/2026
Type: Smart Contract Vulnerability
TenArmor's monitoring system flagged a suspicious attack against the FH token on BSC, resulting in an estimated loss of approximately $20,000.
Impact: $20,000
Moonwell - 27/08/2026
Type: Price Manipulation
Moonwell, a non-custodial lending and borrowing protocol operating across Base, Optimism, Moonbeam and Moonriver, was targeted in a price manipulation attack. The protocol maintains an active bug bounty programme and undergoes regular third-party audits, underscoring that established security practices do not eliminate exposure to this attack class.
Impact: $8,750,000
Avici - 28/08/2026
Type: Smart Contract Vulnerability
Avici, a Solana-based self-custodial neobank combining a smart-contract wallet, a Visa card and fiat on/off-ramp partners, suffered a security breach that drained user funds. Reported estimates of the loss vary by source; Avici had not confirmed an official figure at time of writing.
Impact: $500,859 (estimated; unconfirmed by Avici)
Tectonic (TectonicFi) - 30/08/2026
Type: Price Manipulation (Governance Token Collateral)
The month closed with its largest and most disruptive incident. An attacker manipulated the price of TONIC, the thinly traded governance token of Tectonic, the largest lending protocol on the Cronos blockchain, pushing its price up roughly 100-fold within about 20 minutes. The attacker then posted the artificially inflated TONIC as collateral, exploiting a 20% collateral factor built into Tectonic's lending parameters, and borrowed genuine assets out of the protocol's lending pools against that fabricated value. Tectonic held approximately $121.7 million in total value locked and around $82.7 million in active loans immediately before the attack, representing close to half of all capital deposited across Cronos DeFi.
Cronos Network responded by halting block production across the entire chain, a step made possible by its Tendermint-based consensus, which caps the validator set at 100, small enough to coordinate an emergency shutdown within minutes. The halt came in time to trap most of the stolen funds: only around $6 million reached Ethereum, where it was swapped into approximately 2,592 ETH, before the chain froze. The remaining approximately $68 million sits stranded on Cronos across attacker-controlled addresses. Crypto.com's exchange and app, which operate independently of the Cronos DeFi ecosystem, were unaffected, according to CEO Kris Marszalek. No recovery or reimbursement plan for Tectonic depositors had been confirmed at time of writing.
Impact: ~$74,000,000
Aquifer - 31/08/2026
Type: Access Control
The month closed with a second large incident inside 24 hours. Aquifer, a Solana proprietary automated market maker, was exploited for approximately $2.5 million in an incident involving linked attacker addresses on both Solana and Ethereum. It is reported that the attack was specifically a wallet credential compromise.
Rather than a conventional bounty announcement, the Aquifer’s Solana upgrade authority published and cryptographically authorised an on-chain whitehat offer directly to the attacker's addresses: return at least 80% of the exploited assets to designated recovery addresses on Solana and Ethereum by 3 September 2026, 14:00 UTC, in exchange for retaining up to 20% as a bounty and Aquifer agreeing not to pursue civil claims, subject to applicable law and full compliance with the offer's terms. The offer explicitly does not bind law enforcement, regulators or sanctions authorities.
Impact: ~$2,500,000
Key Findings and Trends
The Tectonic exploit reshaped the month's loss profile
A single incident defined the final weekend of August. The Tectonic exploit accounted for approximately $74 million of the month's roughly $159.5 million in losses, close to half the total, and did so through a mechanism distinct from most of the rest of the dataset: rather than a code bug, a governance hijack or stolen credentials, the attacker manipulated the market price of a thinly traded governance token and used the inflated value as collateral to borrow real assets out of a lending protocol. It is a reminder that illiquid governance and reward tokens, when accepted as loan collateral, can turn a modest amount of capital into a large exploit, and that a chain's ability to halt itself, as Cronos did, can be the difference between a $74 million loss and one many times larger.
Price and collateral manipulation was the costliest attack type of the month by a wide margin
Measured by frequency, smart contract and protocol logic exploits remained the most common category in August, accounting for 11 of the month's 27 incidents (41%), including RiseX, Unistreets, USM, Maya Protocol, The Sandbox, TAC, warp.green, Enjin, CometDEX, FH Token and Avici. Price and oracle manipulation, by contrast, accounted for 5 incidents (19%): LOOPSDAO, FoxMarket, Arrakis V1, Moonwell and Tectonic. Aquifer's $2.5 million loss sits outside both categories for now, as public reporting has not established whether it involved a code exploit or credential compromise.
Measured by value, the picture inverts sharply. Price and collateral manipulation, driven almost entirely by Tectonic, accounted for approximately $83.4 million, or around 52% of the month's total, comfortably the largest category by value despite being only the third-most frequent by count. Smart contract and logic exploits, the most frequent category, accounted for just $27.5 million (17%), most of it concentrated in two incidents (Maya Protocol at $17 million and TAC at $7.5 million); strip those two out and the remaining nine smart contract exploits totalled under $3 million between them. Phishing against a single private wallet accounted for a further $25.6 million (16%), governance attacks (Term Finance) $8.5 million (5%), and access control or credential compromise (MOKE, RRWallet, Coinsbuy) a combined $10.8 million (7%).

A single phishing loss again outweighed most protocol-level exploits
Even in a month reshaped by Tectonic, the $25.6 million loss suffered by a single private wallet to phishing remained the second-largest incident of August, larger than every smart contract exploit recorded during the month bar Maya Protocol. Nominis assesses that this reinforces a theme that has recurred throughout 2026: user-targeted social engineering against high-value individual wallets continues to rival, and sometimes exceed, the scale of protocol-level DeFi exploits.
Governance and collateral concentration emerged as a connected risk theme
Term Finance's $8.5 million loss and Tectonic's $74 million loss, while mechanically distinct, share a common root cause: both exploited a governance or reward token that was thinly traded or thinly distributed enough for an attacker to cheaply gain outsized influence, either direct voting control at Term Finance, or artificially inflated collateral value at Tectonic. Formal safeguards existed in both cases, delay and veto mechanisms at Term Finance, a fixed collateral factor at Tectonic, but neither prevented the attack in time. Nominis assesses that protocols accepting their own governance or reward tokens as collateral, or concentrating voting power in thinly held tokens, represent a growing and connected risk surface worth tracking as a distinct category going into future months.

Access control and credential compromise remained costly
Coinsbuy's $7.9 million loss, MOKE Token's $907,000 loss and RRWallet's $2 million loss together illustrate that privileged access and credential compromise, rather than code-level bugs, continue to produce meaningful losses even in a month dominated by a single large price-manipulation incident. The Coinsbuy incident is particularly notable for the profile of the victim: a regulated-adjacent crypto payment platform rather than a DeFi protocol, echoing a pattern seen with Triple-A in July, where operational wallet security proved as consequential for payment institutions as for decentralised platforms.
Cross-chain bridges were targeted again, with mixed real-world impact
Continuing a trend observed throughout 2026, cross-chain bridges and interoperability infrastructure remained frequent targets, including Coreum Bridge, Oraichain and Allbridge. The outcomes varied considerably: Oraichain's exploit was identified and halted before any loss was realised, while Coreum Bridge and Allbridge both resulted in confirmed, if comparatively modest, losses. This spread illustrates that bridge exploitability does not automatically translate into proportional financial loss, detection speed and response capability remain decisive factors.

Mixers, privacy coins and chain-level intervention all featured in fund movement
Tornado Cash reappeared as a laundering venue in the month's largest governance attack (Term Finance), continuing its role as the default obfuscation tool for stolen funds throughout 2026. The Coinsbuy incident marked a notable variation on this pattern, with the attacker converting proceeds toward Monero rather than routing through Ethereum-based mixers. Tectonic added a third and less common pattern: rather than the attacker successfully obscuring funds, the underlying chain itself intervened, with Cronos validators halting block production to physically prevent roughly $68 million from ever leaving the network. Nominis assesses that this kind of validator-coordinated freeze, while effective, is only available to chains with a small enough validator set to coordinate quickly, and carries its own trade-off in that it also stops all legitimate activity on the chain for the duration of the halt.
Negotiated recovery emerged as a direct, on-chain alternative to pure enforcement
The month's final two incidents both saw the victimised protocol attempt to recover funds by negotiating with the attacker directly, rather than relying solely on law enforcement or blockchain analytics firms after the fact. Cronos's chain-wide halt following the Tectonic exploit was a blunt, network-level intervention. Aquifer's response to its $2.5 million exploit the following day was more targeted: its Solana upgrade authority published and cryptographically authorised an on-chain whitehat offer addressed directly to the attacker's own Solana and Ethereum wallets, offering to let the attacker keep 20% of the funds as a bounty in exchange for returning the remaining 80% by a set deadline, with an explicit acknowledgement that the offer does not bind law enforcement, regulators or sanctions authorities. Nominis assesses that on-chain whitehat offers of this kind are becoming a standard first response for protocols following an exploit, offering a faster path to partial recovery than an investigation, though they depend entirely on the attacker's willingness to comply and carry no guarantee against later regulatory or law-enforcement action against the same funds.
Regulatory and Compliance Developments
August 2026 was a dense month for regulatory developments, spanning a second anti-money-laundering penalty against a European crypto-ATM operator, two new EU and Swiss sanctions measures aimed directly at Russian crypto activity, Austria's first published sanction under MiCA, a commercial partnership formalising a major stablecoin remittance corridor, and a wave of exchange-level enforcement against traditional derivatives brokers. Taken together, they point in the same direction: compliance expectations are tightening simultaneously on core anti-money-laundering controls, sanctions exposure, disclosure obligations, and the infrastructure carrying both crypto and traditional financial flows.
Yellow Card and Tranzmit formalise a major US-Nigeria stablecoin corridor
On 25 August, licensed stablecoin infrastructure provider Yellow Card announced that Tranzmit Payment Services, a subsidiary of Tranzmit Corporation, had integrated Yellow Card's Payments API to power its USA-to-Nigeria payment corridor, one of its largest and fastest-growing. The integration gives Tranzmit's US operations a direct, stablecoin-based settlement route into Nigeria, converting between US dollar-pegged stablecoins and local currency rather than relying on correspondent banking channels.
Nominis assesses that this reflects a broader pattern in the Nigeria remittance corridor, where regulated stablecoin infrastructure is increasingly being adopted by established payment companies rather than solely by crypto-native platforms. As transaction volume on this corridor shifts from legacy correspondent banking, with its long-established AML and sanctions-screening infrastructure, onto stablecoin settlement rails, the compliance burden for monitoring these flows moves with it. A licensed stablecoin provider handling remittance volume for a mainstream payments company is a materially different risk profile to a peer-to-peer or unhosted-wallet flow, but it still requires transaction-level monitoring capable of tracing funds once they convert between fiat, stablecoins and local currency.
ICE Futures Europe enforcement exposes weak systems and controls across major brokers
Trading venue ICE Futures Europe has issued seven disciplinary actions so far this year citing control and conduct failings, with HSBC and BNP Paribas both sanctioned in the past month alone. Marex Group was fined on three separate occasions, paying a combined £747,200, the only firm sanctioned more than once.
Four of the actions centred on weak or absent systems and controls, a breach of Rule A.11. Marex Spectron International was found to lack adequate monitoring, supervision and training controls for its brokers and failed to keep complete broker communication and onboarding records; TFS Derivatives was cited for similar monitoring and training failings alongside deficiencies in obtaining client consent; Marex Financial was penalised for failing to detect circular, non-commercial trades; and HSBC was cited for inadequate pre-trade risk controls and an incorrectly configured trading algorithm. Conduct failings featured separately: a trader at Logista Fund LP engaged in spoofing, while HSBC's algorithm misconfiguration led to disorderly trading, a breach of Rule E.4. BNP Paribas was sanctioned for inaccurate position reporting after recording a client's position as gross instead of net.
Marc Cornelius, co-founder of regulatory consultancy Orienta Advisory, said exchange-issued information requests and investigations are now more frequent than those from regulators directly, and urged firms to give exchange enforcement greater visibility at board and senior management level. Under REC 3.20, UK exchanges must notify the Financial Conduct Authority of all disciplinary actions taken against member firms, though the FCA has confirmed there is no automatic threshold for further supervisory action based on the number of notices a firm receives.
Kraken faces a "dust attack" stress test of its sanctions controls
Between 17 and 24 August, a wallet linked to sanctioned exchange HTX flooded Kraken-linked addresses with roughly 12,000 near-worthless micro-transfers, according to Arkham Intelligence. Kraken's automated screening flagged the incoming funds as tied to UK- and EU-sanctioned wallets and froze the affected customer accounts; access has since been restored, though the transferred funds themselves remain held. Kraken said it does not know who sent the transfers, and HTX has denied involvement, suggesting the activity may have come from independent actors amid disputes over frozen funds.
Nominis assesses that this incident exposes a structural gap in standard sanctions screening: conventional models assume a link between an incoming transaction and the recipient's own behaviour, an assumption that a permissionless blockchain breaks outright, since anyone can send crypto to a public address without the recipient's consent, and the transfer still shows up in that customer's history. For compliance teams, the case reframes the problem from simply detecting exposure to sanctioned wallets toward distinguishing unsolicited, attacker-initiated exposure from genuine customer activity, a distinction most transaction-monitoring tools were not built to make quickly at scale.
Austria fines crypto-ATM operator Kurant for the second time in ten months
On 18 August, the FMA published a second final penalty against Kurant, one of Europe's larger Bitcoin ATM operators: EUR 45,000 for deficiencies in the policies and procedures governing customer due diligence on occasional transactions, and in the handling of circumstances suggesting possible money laundering or terrorist financing. It follows a final EUR 70,000 order published in October 2025 concerning the absence of written procedures for the ongoing monitoring of business relationships.
Where the Bitpanda fine sat on disclosure paperwork, the Kurant pair sits on the anti-money-laundering statute itself, and on some of the hardest operational terrain in crypto retail: walk-up customers, occasional transactions, and the point at which a pattern becomes suspicious enough to escalate. Two final orders against the same operator inside ten months reads as a supervisory message to the wider crypto-ATM segment, not just to Kurant. Nominis notes that the orders establish procedural failings in due diligence and escalation, they do not state that Kurant lacked blockchain analytics tools, and that distinction should be preserved in any further coverage.
Switzerland bans the use of Russian crypto platforms
Switzerland adopted the EU's 20th Russia sanctions package on 19 August, in force from 20 August. Alongside 115 new listings, bringing the Swiss total to roughly 2,790, it introduces two measures aimed squarely at crypto: financial intermediaries must prohibit the use of Russian platforms for transmitting and exchanging crypto assets, and support for the development of specific Russian cryptocurrencies, including the digital rouble, is now forbidden.
FINMA's accompanying notice adds a point worth repeating to any compliance team: reporting a frozen relationship to the State Secretariat for Economic Affairs (SECO) does not discharge the separate obligation to carry out anti-money-laundering clarifications and, where warranted, to file a suspicious activity report. A sanctions hit is the beginning of an investigation, not the end of one, and establishing whether a counterparty platform is genuinely Russian-operated is an attribution question rather than a simple list-checking exercise.
Russian nationals barred from owning EU crypto businesses
A further provision, this time from the EU's 21st sanctions package, took effect on 25 August: Russian nationals and people resident in Russia may no longer own or control, directly or indirectly, a crypto-asset business established in an EU member state. The same package extended transaction bans to 14 crypto platforms in Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan and Belarus, and created a framework allowing the EU to ban dealings with providers in any country judged to be undermining Russian sanctions.
For German and Austrian crypto-asset service providers in particular, "directly or indirectly" is the operative phrase. Establishing who ultimately controls a licensed entity, through whatever chain of holding companies sits above it, is now a sanctions compliance question with a fixed date attached, and beneficial-ownership tracing through indirect ownership chains is exactly the capability this requirement puts to the test.
Austria publishes its first MiCA penalty against Bitpanda
On 14 August, Austria's Financial Market Authority published a EUR 70,000 penal order against Bitpanda, the country's first legally binding MiCA sanction to be made public. The breaches were disclosure-related rather than financial-crime related: a crypto-asset white paper was not filed at least 20 working days before publication, marketing went out before the white paper was published, and required disclosures were missing from the marketing material. The conduct dates back to a 2025 token launch and was corrected once the regulator raised it.
Coming up: Switzerland's revised AML Act and beneficial-ownership register
On 1 October, Switzerland's revised Anti-Money Laundering Act and its new federal transparency register enter into force. Most Swiss entities, plus foreign entities with Swiss branches, Swiss-based management or Swiss real estate, and foreign trusts with a Swiss trustee, will have to identify and register their ultimate beneficial owners at the 25% threshold, including control exercised through indirect chains, veto rights and fiduciary arrangements. AML obligations also extend to advisers on an activity basis, covering lawyers structuring acquisitions, notaries, fiduciaries and domiciliation providers.
Therefore, Switzerland will now have a queryable beneficial ownership register, a new corroboration source for exactly the kind of ownership question that recurs this month’s sanctions developments.
Why this matters for compliance, KYT and the intelligence layer
Several of this month's developments converge on a single capability: knowing who actually controls a counterparty, not just who it claims to be. The EU's new ownership rule for Russian nationals, Switzerland's forthcoming beneficial-ownership register, and FINMA's reminder that a sanctions hit only opens an investigation rather than closing one, all turn on the same underlying question of establishing genuine control through indirect chains. Kurant's back-to-back AML fines sit on the adjacent problem of translating that kind of exposure into a defensible, escalated decision at the point of a walk-up transaction, exactly the terrain where transaction intelligence and a documented escalation trail matter most.
Meanwhile, volume continues to migrate onto new rails faster than oversight can necessarily follow it. In the Yellow Card and Tranzmit case, remittance flows are moving onto stablecoin settlement infrastructure that promises to outperform the legacy banking channels the ICE Futures enforcement wave shows can already struggle with basic controls, even inside mature, heavily supervised markets. If systems and controls failings of the kind seen at Marex, HSBC, TFS Derivatives and BNP Paribas can persist for years inside long-established, tightly regulated derivatives brokers, the same discipline cannot be assumed by default as volume shifts onto newer, faster-moving stablecoin infrastructure serving corridors like US-Nigeria.
The throughline connecting this month's regulatory developments, and the exploits detailed earlier in this report, is that speed and growth in payment or settlement volume are not substitutes for monitoring capability, and neither is a clean sanctions list check a substitute for genuine ownership and attribution analysis. A licensed stablecoin provider onboarding a major payments partner needs the same transaction-level visibility that a well-run exchange member firm should already have in place: the ability to detect anomalous patterns and establish genuine control, before a regulator or an exchange has to ask why it was missed.
Conclusion
August 2026 delivered approximately $162.0 million in losses across 27 major incidents. Unlike July, where a single hardware-wallet firmware flaw drove the month's total, August's concentration arrived in its final days: the Tectonic exploit on Cronos, close to half the month's total, showed how a thinly traded governance token accepted as loan collateral can be manipulated into an outsized loss, and how a chain's ability to halt itself can be the difference between containment and catastrophe. A day later, Aquifer's $2.5 million exploit added a second data point on how protocols are now responding in real time, offering the attacker a direct, on-chain path to partial recovery rather than waiting on investigators. Beyond these two, losses were distributed across a long tail of smart contract exploits, a large individual phishing loss, and the emergence of governance and collateral concentration as a connected and effective attack method, visible at both Term Finance and Tectonic despite their different mechanics.
The through-line from July continues to hold, with a new dimension added in August. Where code-level vulnerabilities remain the most frequent category of incident, they are rarely the most expensive; that was true again this month, even before Tectonic is accounted for. The month's largest losses instead traced back to price and collateral manipulation, a user-targeted phishing attack, and a governance token whose voting power was cheap enough to acquire outright. For compliance teams, custodians and protocol operators, August reinforces that monitoring needs to extend beyond contract audits to cover privileged access, governance and reward token distribution, the collateral parameters attached to illiquid tokens, and the behavioural signals that precede fund movement, particularly once stolen assets begin crossing chains or entering mixers and privacy coins.
This month's regulatory picture reinforces the same message from the other direction. A major stablecoin remittance corridor is formalising just as exchange-level enforcement reveals that systems and controls failings can persist for years inside mature, heavily supervised derivatives brokers. Whether the venue is a DeFi protocol, a regulated payment platform or a traditional exchange member firm, the firms that stay ahead of both attackers and regulators will be those that treat monitoring as a continuous, intelligence-driven capability rather than a one-time control built and then left unchecked.
All research content and accompanying reports are provided for informational purposes only and should not be relied upon as professional advice. Accessing these materials does not create any professional relationship or duty of care. Readers are encouraged to consult appropriately qualified professionals for guidance. We uphold the highest standards of accuracy in all the information we provide. For any questions or feedback, please contact us at contact@nominis.io.