August Set the Year's Record for Crypto Hacks. What Actually Puts Card Users at Risk

ST
SolCard Team
crypto hacks 2026

August 2026 had the most crypto hacks of any month this year -- 50 incidents -- but total losses fell 49.5% to about $136.3 million, and the tally is dominated by protocol and platform exploits rather than individual wallets. The tally comes from blockchain security firm PeckShield, as reported by BeInCrypto via Yahoo Finance and crypto.news. One lending-protocol exploit accounted for more than half of the month.

The distinction between money stolen from protocols and money stolen from individuals is the most useful thing to understand about crypto security, and the headlines usually skip it. This guide covers the August numbers, where retail holders actually lose money according to the FBI, the habits that close off most of it, and what changes once you spend through a prepaid card.

What happened in August 2026

PeckShield counted 50 major incidents in August, up 67% from 30 in July, while estimated losses dropped from roughly $270 million to $136.3 million, per crypto.news; the average loss per incident fell to about $2.7 million from roughly $9 million, according to BeInCrypto.

One event dominated. On August 30, an attacker pushed the thinly traded TONIC token up roughly 100-fold in about 20 minutes, deposited it into Tectonic, the largest lending protocol on the Cronos chain, and borrowed real assets against it, per CoinDesk. PeckShield put the figure at about $74 million; CoinDesk reported an estimate near $75 million. Cronos validators halted the whole chain, only about $6 million reached Ethereum before blocks stopped, and the network later restarted from a state before the attack, per BleepingComputer. The next-largest incidents on PeckShield's list were each under $10 million.

The incidents at the top of the tally are protocols and platforms. If you had no funds deposited in Tectonic, the Tectonic exploit did not touch you.

The bigger picture: 2025 and 2026 so far

TRM Labs recorded about $972 million stolen across 207 incidents in the first half of 2026, less than half the $2.3 billion taken in the first half of 2025, per TRM Labs. About 66% was attributed to North Korea-linked groups, and infrastructure compromises -- stolen keys, hijacked systems -- made up roughly 76% of funds lost while being only about 15% of incidents.

For context, Chainalysis counted more than $3.4 billion stolen in 2025, with the February 2025 Bybit exchange hack alone at about $1.5 billion, per Chainalysis. The same report puts personal wallet compromises at about $713 million, or 20% of the year's stolen value, across an estimated 158,000 incidents and at least 80,000 victims.

Where individuals actually lose money

Hacks make headlines; fraud takes the money. Two different problems: one is rare and enormous per event, the other constant and almost always a person being tricked. The FBI's Internet Crime Complaint Center (IC3) logged 181,565 cryptocurrency-related complaints in 2025 totaling $11.366 billion in losses -- more than half of the $20.877 billion in all reported cybercrime losses that year -- per the 2025 IC3 Annual Report.

Investment fraud is the largest category at $8.65 billion, and the report names cryptocurrency investment fraud -- the long-con scams run from Southeast Asian scam compounds -- as the single highest source of financial loss to Americans, at $7.2 billion. Americans aged 60 and over reported $4.43 billion of the crypto total; SIM-swap complaints, by comparison, totaled 971 with $17.4 million in losses.

Wallet-drainer phishing, by contrast, took $83.85 million worldwide in 2025, per Scam Sniffer. The dominant way a retail holder loses crypto is by sending it to someone who lied to them.

Threat by threat: how it works and the habit that defeats it

ThreatHow it worksThe habit that defeats it
Investment or romance scamA contact from social media or a dating app coaches you into a "platform" that shows fake profits, then blocks withdrawalsNever send crypto to anyone promising returns. The FTC: only scammers guarantee profits
Seed-phrase phishingA fake wallet site or "support agent" asks for your recovery phraseNever type a seed phrase into a website or share it with anyone
Wallet drainer / malicious approvalA site asks you to sign an approve or Permit that lets it move your tokensRead what you sign; review and revoke old approvals with Revoke.cash
Address poisoningDust arrives from an address matching the first and last characters of one you use, hoping you copy it from historyVerify the full address, not the first and last four; use an address book
SIM swapYour carrier moves your number to an attacker's SIM, who then receives your SMS codesAuthenticator app or hardware key for two-factor authentication, never SMS
Fake supportA "support agent" DMs you after you post about a problemReal support never DMs first. Go to the official site yourself
Exchange or protocol hackA venue you deposited into is compromisedKeep only spending money on hot wallets and exchanges

The poisoning row is not hypothetical: in December 2025 a trader lost $49,999,950 in USDT to an address that shared the first five and last four characters of the intended recipient, copied from transaction history, per The Block.

Practical hygiene, in order of impact

  1. Split cold from hot. Long-term holdings go on a hardware wallet whose seed has never touched an internet-connected device; spending money goes in a separate hot wallet or on a card.
  2. Treat the seed phrase as radioactive. No website, form, screenshot, cloud note, or support chat ever sees it.
  3. Refuse every investment pitch that arrives by message. The FBI's numbers say this single habit avoids the largest loss category in the ecosystem.
  4. Audit and revoke approvals. Old approvals stay live until revoked. Check them quarterly and after any session on a site you do not fully trust.
  5. Verify the whole address. Read it end to end, or send a small test and copy the address from the confirmed test transaction, not from history.
  6. Move two-factor authentication off SMS. An authenticator app or hardware key cannot be SIM-swapped.
  7. Unique passwords, passkeys where offered. Visa's card advice is the same: unique credentials per site plus multi-factor authentication, per Visa.
  8. Ignore inbound "support" and check the domain, not the design. Phishing sites copy layouts pixel for pixel; the address bar is the one thing they cannot copy.
  9. Keep exchange balances to spending money. Exchanges are the bigger target; cold storage is far harder to reach.

Card-specific hygiene

Once crypto has become a card balance, you are defending a card number and an app login rather than private keys.

  • Load what you plan to spend. What sits on the card is what is exposed if the number is compromised.
  • Use a virtual card number online, kept separate from any other card you hold.
  • Freeze it when idle. A frozen card declines new purchases; unfreeze when you are about to pay.
  • Watch for micro-charges. Card testing often starts with a small charge from an unfamiliar merchant to confirm the number works; report suspicious charges to your issuer immediately, per Visa.
  • Turn on transaction notifications. Visa describes near real-time transaction alerts as a way to spot possible fraud as soon as it occurs, per Visa Purchase Alerts.
  • Know the dispute path before you need it. Both card networks publish unauthorized-transaction policies, and both carve out categories of card, so what applies to you depends on your issuer and your card. Read your card's terms before you need them, and report unauthorized activity to the issuer first.

That is the honest contrast with on-chain payments: as the FTC notes, cryptocurrency payments typically are not reversible and do not carry the legal protections credit and debit cards do.

What this means if you spend crypto with a card

From the product side, without overstating it: a prepaid crypto card is a useful boundary for the "spending wallet" above. With SolCard, you fund the card by sending SOL, USDC, or USDT over Solana, or USDC or USDT over Ethereum, BSC, Arbitrum, Base, Polygon, or Avalanche, and once loaded the balance is held in fiat.

Two security consequences follow. The balance is not on-chain, so a protocol exploit, a bridge hack, or a malicious approval is out of reach of it -- there is no token to drain. It does sit with the card program instead, which is its own kind of counterparty. And the loaded balance is what is exposed: fund the week's spending and the rest stays in a wallet you control.

The card side then relies on ordinary card habits: the virtual card is a Mastercard with its own number for online use, the card can be frozen instantly from the app, and the virtual card's $5,000 per month load limit keeps balances in the spending-money range. None of this protects you from being talked into sending crypto to a fraudster, the biggest threat in the FBI's data, and we would not claim otherwise. It draws a hard line between the money you spend and the money you hold. Our how to pay with crypto guide covers loading and paying; is SolCard legit covers the company.

Frequently asked questions

Were crypto hacks in August 2026 the worst ever?

No. August had the highest incident count of 2026 at 50, but losses of about $136.3 million were down 49.5% from July, per crypto.news. The Bybit hack alone, in February 2025, was about $1.5 billion, per Chainalysis.

Does a DeFi protocol hack affect me if I just hold crypto in a wallet?

Only if your funds were deposited in the exploited protocol. DeFi (decentralized finance) exploits like Tectonic drain the protocol's own pools; tokens in a self-custody wallet that never interacted with it are untouched. Revoke any approval you once granted it anyway.

What is the single most common way people lose crypto?

Being persuaded to send it. The FBI's 2025 IC3 report names cryptocurrency investment fraud the largest source of financial loss to Americans at $7.2 billion, versus $17.4 million in reported SIM-swap losses, per the 2025 IC3 Annual Report.

How do I check whether I have risky token approvals?

Use an approval dashboard such as Revoke.cash, which lists every approval your address has granted and lets you revoke the ones you no longer need. Check each chain you have used.

The bottom line

August 2026 was a record month for the number of crypto hacks, not their size, and the losses fell overwhelmingly on protocols, not individuals. Where retail holders lose the most, by an order of magnitude, is fraud, and fraud is defeated by habits: keep long-term holdings cold, never type a seed phrase anywhere, refuse every pitch that arrives by message, verify full addresses, and move two-factor authentication off SMS. Then treat the card as a fiat spending wallet with a hard ceiling, protected by ordinary card habits. Our best crypto debit cards comparison lays out the options, and our crypto payments August 2026 roundup covers the rest of the month.

Sources

More in Guides
Globe
SolCard

150M+ places.
One card.

Instantly create and top-up your SolCard with SOL and enjoy hassle-free shopping IRL and online.