CertiK’s August Ledger: $215M and the Audit Paradox
CertiK closed the books on crypto's busiest exploit month of 2026: $215 million lost, led by DeFi price manipulation. The scorekeeper's own data exposes a paradox at the heart of the audit business.
On the last day of August, the Cronos blockchain did something blockchains are built not to do: it stopped. Validators halted block production after an attacker gutted Tectonic, the largest lending market on the Crypto.com-linked network, in a fast and clinical sequence: inflate a thinly traded token by roughly a hundredfold, borrow real assets against the fake collateral, and try to run before anyone reacts. Most of the loot never made it out, because the network operators pulled the emergency brake on the entire chain.
Hours later, CertiK closed its books on the month. The New York security firm audits smart contracts, runs a continuous-monitoring product called Skynet, and every month publishes a tally of what crypto lost and how it happened. August 2026 came to about $215 million across the highest number of incidents CertiK had logged in any month this year, with decentralized finance accounting for $144.6 million of the damage. Tectonic was the single largest line on the page.
That ledger is worth reading closely, because CertiK sits at an awkward intersection. It is the company that grades crypto’s code, and it is also the company documenting, month after month, a world in which broken code is less and less often the reason money disappears. August put that contradiction on full display. Layer on CertiK’s stated ambition to become the first publicly listed Web3 cybersecurity firm, and the result is one of the more revealing stories in crypto security right now: a scorekeeper preparing to go public in a game its own numbers say the industry keeps losing.
The August Ledger: $215 Million in a Single Month
CertiK’s August figures, published on 31 August, put total confirmed losses at roughly $215 million, with DeFi responsible for $144.6 million and about $110.7 million later classified as returned or frozen. The unusually high recovery rate is mostly an accident of the Tectonic attack: a chain halt stranded most of the stolen value on-chain before the attacker could move it, so the money is frozen rather than gone. In a normal month that recovery line would be a fraction of the size.
The vector breakdown is where the report earns its keep. Price manipulation, the category that covers oracle games and illiquid-collateral attacks, accounted for the overwhelming share of the month’s damage. Old-fashioned smart-contract bugs, the thing a code audit is designed to catch, made up a small slice.
| Attack vector (August 2026) | Reported losses |
|---|---|
| Price manipulation | $131.6 million |
| Phishing | $41.5 million |
| Code vulnerabilities | $20.6 million |
| Wallet compromise | $11.8 million |
| Governance | $8.5 million |
| Total confirmed | about $215 million |
Notice how small the code-vulnerabilities line is against the total. In a month defined by two large DeFi attacks, the classic picture of a hacker discovering a flaw buried in a smart contract accounted for under a tenth of the losses. Everything else came from manipulating markets, deceiving users, or stealing keys. That distribution is not a one-month quirk; it is the shape of 2026, and CertiK’s own half-year data tells the same story at larger scale.
Tectonic and the Day Cronos Stopped
Tectonic is the biggest lending protocol on Cronos, the Layer 1 tied to exchange Crypto.com. On 30 August, an attacker turned its own risk parameters against it. The target was TONIC, Tectonic’s thinly traded governance token, which the protocol accepted as collateral. By buying into a shallow market, the attacker pushed TONIC up by roughly one hundred times in about twenty minutes, then used the artificially valuable tokens as collateral to borrow far more valuable assets from the pool. It is the same pump-and-borrow shape as the 2022 Mango Markets attack, executed against a market too shallow to defend itself.
The dollar figure depends on which number you use. CertiK’s monthly tally listed the incident’s impact at $120.4 million, a measure closer to the value at risk in the protocol. On-chain researcher Weilin Li put the amount the attacker actually extracted closer to $75 million, and Tectonic’s total value locked collapsed from about $122 million to near $3 million. The gap between those numbers matters, and it exists because of what happened next.
Cronos validators halted the entire blockchain. Only about $6 million had been bridged to Ethereum before the network froze, which left the bulk of the proceeds stranded on a chain that had simply stopped producing blocks. It is a blunt instrument, and it works only on a network centralized enough to coordinate a halt, a fact critics were quick to note. Crypto.com chief executive Kris Marszalek said the exchange’s app and centralized platform ran normally and that customer funds there were unaffected, with a post-mortem to follow. For a lending market, the episode is a reminder that a protocol can be drained without a single contract being rewritten; the attacker simply fed it a price it was willing to believe. It is the collateral-and-liquidation machinery, explored in our guide to how DeFi liquidations work in 2026, run in reverse.
Moonwell: $8.7 Million and Not a Line of Broken Code
Three days earlier, on 27 August, the lending protocol Moonwell lost about $8.7 million on Base through the same playbook. The collateral this time was MAMO, another illiquid token, and the attacker inflated its price in a thin market before borrowing real assets, including cbBTC and USDC, against the inflated value. PeckShield and CertiK both sized the loss at roughly $8.7 million the same day, and the security firm Blockaid flagged 50.6 cbBTC worth more than $4 million leaving a single market.
What makes Moonwell the cleaner illustration is that nothing in its code was broken. The contracts executed exactly as written; they priced collateral from a spot market too thin to trust, and the attacker supplied the price. The team responded by cutting borrow caps across its Base core markets to a single wei, effectively freezing new borrowing, and it was the protocol’s third security incident of the year. When the failure lives in the economic design rather than the code, an audit that certifies the code can pass with flying colors and change nothing about the outcome. That is the whole problem in one sentence, and the rest of this piece is really about that sentence.
August’s Third Act: Governance Capture at Term Finance
Lost in the noise of two price-manipulation attacks was a third kind of failure. On 23 August, Term Finance lost about $8.5 million when an attacker accumulated enough of a sparsely held governance token to push through malicious proposals and drain a set of vaults. It is the governance-capture pattern: not a code bug, not a stolen key, but the deliberate purchase of enough voting power to make a protocol rob itself. CertiK logged it under the governance line in the same August tally. Three headline incidents, three different attack surfaces, and only one of them, the smallest, was the sort of thing a contract audit is built to find.
Put the month together and a theme emerges. The attacker who wants a large payday in 2026 does not look for a reentrancy bug in a well-reviewed contract. They look for a thin market, a captured vote, or a poorly guarded key. Each of those lives outside the four corners of a standard audit, and each of them cost more in August than the code bugs did.
Who CertiK Actually Is
CertiK grew out of academic work on formal verification in 2016 and was founded the following year by Ronghui Gu, an associate professor of computer science at Columbia University, and Zhong Shao, who chairs the computer science department at Yale. Their calling card was CertiKOS, described as the first fully formally verified concurrent operating-system kernel; the name is shorthand for the phrase certified kernel. The pitch was to take the mathematical, prove-the-code-correct discipline of formal verification and point it at blockchains, where a single bug can be worth nine figures. Our explainer on formal verification as an audit that proves your code covers the method CertiK helped popularize.
The company scaled quickly. It has raised roughly $296 million and last carried a valuation near $2 billion, with Binance as its first and largest backer alongside Coinbase, SoftBank, Insight Partners, Tiger Global and Advent International. It says it has worked with more than 5,000 clients and audited code securing on the order of $600 billion in assets. Its product line now spans manual and formal-verification audits, penetration testing, bug bounties, a compliance arm called SkyInsights for KYC and AML screening, and the monitoring engine that feeds those monthly reports.
Skynet, the Scoreboard Nobody Voted For
The monthly loss tallies come from Skynet, CertiK’s continuous-monitoring platform. Where an audit is a snapshot taken once before launch, Skynet is meant to watch a project after deployment, tracking on-chain activity, governance, market behavior and code changes, and rolling the result into a single public Skynet Score. CertiK says the system tracks close to $500 billion in combined market value across the projects it monitors, which is what lets it publish an industry-wide ledger every month.
That scale is also why CertiK’s numbers get quoted everywhere, from exchange listing pages to newsroom copy, and why the firm functions as a de facto scoreboard for a market that never agreed to appoint one. A high Skynet Score has become a marketing asset for projects, which introduces its own tension: the entity measuring the risk is often paid by the projects being measured. It is a conflict CertiK shares with credit-rating agencies in traditional finance, and it colors how much weight any single score should carry. The monthly reports, which grade the whole industry rather than a paying client, are in some ways the cleaner product.
The Half-Year Picture: Where the Money Really Goes
August fits a pattern CertiK had already documented in its half-year Hack3d report. The firm counted more than $1.31 billion lost across 344 incidents in the first half of 2026. Headlines called that a decline from a year earlier, but the comparison is almost entirely an artifact of the single $1.45 billion Bybit theft that defined early 2025; strip that outlier out, and losses were up roughly 28 percent on a like-for-like basis. The report’s own conclusion was that the underlying security environment had not improved, and in several meaningful respects had gotten worse.
The vector table is the part that should worry builders.
| Attack vector (H1 2026) | Losses | Incidents | Average per event |
|---|---|---|---|
| Wallet compromise | about $444 million | 33 | over $13 million |
| Phishing | about $366 million | 63 | about $5.8 million |
| Code vulnerabilities | over $151 million | 204 | about $0.7 million |
Wallet compromise, the theft of private keys and signing authority, was the most financially destructive category of the half, and by a wide margin the most expensive per incident. Code vulnerabilities were the most frequent by count but the cheapest on average, around $0.7 million per event. The two largest incidents of the half, the Kelp DAO and Drift Protocol breaches, together about 44 percent of all losses, both landed in April and both were failures of operational and infrastructure security rather than contract bugs.
Ronghui Gu drew the obvious conclusion in an interview with Forbes: “Attackers are getting more return by going after key management, multisig governance, and operational infrastructure than by hunting for bugs in code.” The takeaway for anyone deploying capital is that key management, not contract review, is now the first-order risk, which is one reason the mechanics of key custody and account abstraction and smart-account design have moved to the center of the security conversation.
The uncomfortable part for the audit industry is that none of the biggest 2026 attack surfaces show up in a code review at all. A stolen signing key, a phishing email that fools a treasury manager, a fake job interview that plants malware on a developer’s laptop: these are human and operational failures, and a contract can be mathematically perfect while every one of them plays out around it. CertiK can audit the code and monitor the chain, but it cannot audit an employee’s password hygiene or a multisig quorum that turned out to be one person holding every key. That is why the loss curve has bent away from the very thing the industry spent years learning to review.
Why Price Manipulation Came Roaring Back
Tectonic and Moonwell are two instances of one idea, and that idea drove August’s numbers. A lending market has to price the collateral it holds. If it prices a token from a deep, liquid market, moving that price enough to matter costs more than the attack can earn. If it prices a token from a thin market, the cost of moving the price collapses, and the protocol becomes a machine for converting a cheap pump into an expensive loan. Attackers spent August finding tokens sitting on the wrong side of that line.
The defense is unglamorous: conservative collateral factors for illiquid assets, price feeds that resist manipulation, borrow caps, and circuit breakers that trip before a single trade can distort a market. None of it is exotic, and all of it is the sort of parameter choice a point-in-time code audit does not typically own. An auditor can confirm that the oracle contract reads a feed correctly; it is a separate, harder judgment call whether that feed should be trusted for that token at that size, and that call usually belongs to the protocol’s risk team, not its reviewers.
Price manipulation also rhymes with the broader world of on-chain value extraction. The same thin order books and predictable liquidations that let a bot profit from reordering trades are the conditions an oracle attacker exploits at a larger scale. The difference is one of degree, not kind: an MEV searcher skims a few basis points from a large trade, while an oracle attacker moves the price outright and borrows against the distortion. When liquidity is shallow, price is cheap to move, and cheap-to-move price is the raw material of both games.
The Audit Paradox
Here is the paradox CertiK lives inside. Its core business is auditing code, yet its own data shows that in 2026 the code is increasingly not where the money leaks. An audit is a photograph of a contract at one moment; the risk it certifies keeps changing after the shutter clicks. Gu has said as much: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key,” and, on the habit of auditing once and never again, “The danger window doesn’t close after launch.”
CertiK has felt this from the wrong end more than once. It has audited or rated projects that were later drained or rugged, from the roughly $3 million Swaprum rug pull to the Merlin decentralized exchange, which lost about $1.8 million to an insider drain in 2023 shortly after receiving a strong CertiK security score, and an older run of incidents at PancakeBunny, Uranium Finance and Meerkat Finance. None of these means the audits were worthless, but each underlines the gap between a clean report and a safe protocol. When a project is rugged by its own developers or bled through an operational failure, the audit was answering a question nobody was attacking. Recovering funds afterward is its own ordeal, as our guide to getting your crypto back after a rug pull lays out.
Independent voices have been sharper. Suhail Kakar, developer relations lead at TAC Blockchain, put it bluntly after a separate 2026 exploit at Balancer: “audited by X means almost nothing. Code is hard, DeFi is harder.” His point was not that audits are useless, but that treating a badge as a guarantee is how users get hurt. The badge answers the narrow question, was this code reviewed. It does not answer the one users actually care about, is my money safe here today.
CertiK’s own answer to this critique is that it never claimed an audit was the whole story, which is precisely why it built Skynet and sells continuous monitoring on top of the one-time review. That is a fair defense, and it is also a quiet admission: if the pre-launch audit were sufficient, the monitoring product would not need to exist. The firm is, in effect, selling the cure for the limitations of its own flagship service, and the monthly loss reports are both a public good and the marketing for it.
The Kraken Affair and the Trust Problem
The hardest test of CertiK’s credibility was self-inflicted. In June 2024, CertiK researchers found a bug in the exchange Kraken that let them credit assets to an account without a real deposit. Instead of reporting it and stopping, they used it to withdraw about $3 million of real funds over several days. Kraken chief security officer Nick Percoco said the exchange treated the matter as criminal and accused the firm of crossing a bright line: “This is not white-hat hacking, it is extortion,” he wrote, describing a standoff over the return of the money.
It got worse for CertiK’s optics when on-chain sleuths noticed that some of the funds had been routed through Tornado Cash, the sanctioned mixer, an odd move for a US-headquartered firm claiming a white-hat motive; CertiK later attributed those transactions to a rogue employee. The funds were ultimately returned, aside from network fees. CertiK’s defense was that it was conducting legitimate research and that Kraken had been heavy-handed. Reasonable people still disagree about who was more at fault, but the episode left a mark on a company whose entire product is trust, and it is the sort of thing that resurfaces the moment a listed CertiK files a risk-factors section.
The AI Bet
CertiK’s answer to the widening gap between audits and losses is, in part, automation. In April 2026 it released AI Auditor, which it says hit an 88.6 percent cumulative exact hit rate against 35 real-world 2026 incidents while keeping false positives low. Built internally over more than six months, it is pitched as a complement to human reviewers, handling baseline detection and pre-audit triage so that senior auditors can spend their time on protocol-level design risk, exactly the sort of economic-design flaw that felled Tectonic and Moonwell.
CertiK has also moved into securing AI agents themselves, with tools that scan the third-party skills and integrations an autonomous agent might use. Gu frames the risk in memorable terms: an AI agent with wallet access is “a new kind of privileged key holder,” except its decisions can be steered through malicious inputs in ways a human might catch and a poorly guardrailed agent will not. That is the same trust question our piece on verifiable compute as the trust layer for AI agents examines from the infrastructure side.
Not everyone is sold on pointing more models at the problem. Skeptics counter that a model is not a methodology, and that an AI pass mostly lowers the cost of a first look without closing the danger window Gu keeps describing. The optimistic read is that automation lets human reviewers concentrate on the design-level risks that machines still miss; the pessimistic read is that cheaper, faster audits produce more badges without changing the loss numbers on CertiK’s own dashboard. August did not settle the argument.
Going Public in a Losing Year
All of this is happening while CertiK openly courts the public markets. Speaking at Davos in January 2026, Gu said the firm wants to become the first publicly listed Web3 cybersecurity company, adding, “We still do not have a very concrete IPO plan. But this is definitely the goal we are pursuing.” A listing would test the market’s appetite for a pure-play crypto-security business, and it would put CertiK’s own numbers, the ones that show losses climbing, into a public filing.
The bull case is that a deteriorating threat environment is good for a security vendor the way a crime wave is good for a locksmith. Recurring revenue from Skynet monitoring and SkyInsights compliance, rather than one-off audit fees, is the kind of story public investors reward, and a Securities and Exchange Commission that has softened its posture toward crypto in 2026 makes a US listing more plausible than it looked two years ago. The bear case is the paradox again: if audits increasingly fail to prevent the losses that dominate the headlines, a public CertiK will have to explain, every quarter, why the product works even as the industry it guards keeps bleeding. Its backers, Binance and Coinbase among them, would be selling into that narrative.
A public listing would also force a level of disclosure the crypto-security business has never had to provide. Traditional cybersecurity firms trade on predictable subscription revenue and retention metrics; CertiK would have to show how much of its income is durable monitoring and compliance versus lumpy, deal-by-deal audit fees, and how it keeps growing when its most newsworthy product is a report about other people’s losses. Investors comfortable with a locksmith may be less comfortable with a locksmith whose own numbers show more break-ins every quarter. Whether that story clears an exchange listing is, for now, an open question.
What It Means for Regulators and Users
No US regulator accredits smart-contract auditors, and none requires a protocol to be audited before it launches. The Securities and Exchange Commission under chair Paul Atkins has spent 2026 pulling back from the view that most tokens are securities, which leaves the practical work of security largely to private firms like CertiK rather than to a government stamp. An audit, in other words, is a commercial product, not a safety certification, and it carries no legal warranty that funds are safe. When a protocol on a MiCA-regulated or SEC-registered venue fails, the compliance regime reaches the intermediary, not the smart contract that was drained.
For users, the lesson from August is to read a Skynet Score or an audit badge as one input, not a verdict. Ask when the audit was performed, what was in scope, whether the protocol prices illiquid collateral from thin markets, who controls the admin keys, and whether anyone is watching the contract after launch. Those questions, not the presence of a logo, separate the projects that survive a bad month from the ones that become a line in next month’s report.
What August Tells Us About 2026
Strip away the branding and CertiK’s August report is a status update on a losing position. The most expensive attacks are aimed at keys and market design, not at the contract code that audits were built to inspect. Price manipulation is back because too many lending markets still trust prices they should not. Recovery rates flatter the month only because one chain was centralized enough to hit an emergency stop. And the firm best placed to see all of this is preparing to sell shares in the business of watching it happen.
None of that makes audits pointless. A code review still catches the bug that would otherwise cost a protocol everything, and formal verification still proves properties no test can reach. But August is a reminder that the audit is necessary and not sufficient, that the danger window stays open long after launch, and that the most valuable thing CertiK produces may not be the badge on a project’s website. It may be the monthly ledger that keeps insisting, in the firm’s own words, that things have not gotten better.
Frequently Asked Questions
Is a CertiK audit a guarantee that a crypto project is safe?
No. A CertiK audit is a point-in-time review of a project’s code, and it does not cover private-key management, admin controls, oracle and collateral design, or anything that changes after launch. CertiK’s own 2026 data shows most losses now come from key compromise, phishing and price manipulation rather than the code bugs an audit is built to catch, so a clean report should be read as one input, not a promise of safety.
How much did crypto lose to exploits in August 2026?
CertiK put confirmed losses at about $215 million across the month, the highest incident count it had recorded in 2026, with DeFi accounting for $144.6 million. Price manipulation was the largest vector at $131.6 million, followed by phishing at $41.5 million, and roughly $110.7 million was later returned or frozen, most of it stranded by the Cronos chain halt.
What happened to Tectonic and why did Cronos halt its blockchain?
On 30 August, an attacker inflated Tectonic’s thinly traded TONIC token by roughly a hundredfold in about twenty minutes, then borrowed far more valuable assets against the inflated collateral. On-chain researchers estimated the attacker extracted close to $75 million, but Cronos validators halted the entire network before most of it could be moved, so only about $6 million was bridged out and the rest was frozen on-chain.
What is CertiK’s Skynet?
Skynet is CertiK’s continuous-monitoring product. Unlike a one-time audit, it tracks a project after deployment across on-chain activity, governance, market behavior and code changes, and rolls that into a public Skynet Score. CertiK says Skynet tracks close to $500 billion in combined market value, which is the data behind its monthly loss reports.
Is CertiK planning to go public?
CertiK has said it wants to become the first publicly listed Web3 cybersecurity firm. Speaking at Davos in January 2026, co-founder Ronghui Gu said an IPO is the goal the company is pursuing while cautioning that there is no concrete plan yet. The firm was last valued near $2 billion and counts Binance, Coinbase and SoftBank among its backers.
By Anneke de Vries, HOGE Wire security desk editor.