Crypto security incidents increased sharply in August 2026, even as the total value lost moved lower from the previous month. Blockchain security firm Peckshield said the industry recorded 50 major hacks in August, up 67% from July.
At the same time, estimated losses fell to $136.3 million, down 49.5% from roughly $270 million in July. One exploit, affecting decentralized lending protocol Tectonicfi, accounted for the majority of the damage by value and shaped the month’s overall totals.
Tectonicfi dominated August losses
Peckshield said the Tectonicfi exploit resulted in about $74 million in losses, representing more than 54% of all funds stolen during the month. That made it by far the largest single incident in August.
According to the report, the attacker had difficulty moving the assets. Only around $6 million was bridged out before the Cronos network paused its chain, which left most of the funds trapped. Excluding Tectonicfi, the remaining losses totaled $62.3 million and were spread across dozens of smaller attacks.
Attack patterns shift toward smaller targets
Peckshield’s analysis suggests attackers are relying less on the kind of outsized mega-exploits seen in July and are instead hitting a broader set of mid-tier protocols and decentralized finance components.
Among the projects named in the smaller incidents were Termlabs, Moonwell, Coinsbuy, and TAC. While the methods differed across cases, Peckshield said many DeFi breaches still point back to the same underlying weakness: privileged keys being compromised on vulnerable endpoints.
AEREDIUM pitches threshold signing as an alternative
That single-key risk is the problem AEREDIUM says it is trying to address with AERSeal, a newly announced product built on the company’s threshold key infrastructure. The system is designed to replace the private key that normally controls privileged smart contract functions with threshold signing that requires multiple authorized approvers.
Under AEREDIUM’s design, the key shares are not recombined into one complete private key. Instead, signatures are produced through the CGGMP24 threshold signing protocol. The company said the smart contract itself does not need to be moved, and AERSeal currently supports Ethereum Virtual Machine chains and EVM-compatible networks.
How the system is meant to work
Before custody is activated, AERSeal identifies the privileged powers attached to a contract and requires those permissions to be transferred to the threshold key. The system then checks on-chain that the transfer has been completed.
AEREDIUM said customers can also independently verify the threshold key assigned to them. Using address derivation and a signed fresh challenge, they can confirm both derivation and possession of the key, including offline, rather than depending only on the company’s word.
The onboarding process includes Know-Your-Customer verification, contract registration, cryptographic key verification, transfer of privileged powers, on-chain verification, and activation of the customer’s approval policy.
Next focus remains key management
Albert Dadon, AEREDIUM’s founder and chief executive, said AERSeal is the first complete product to put the company’s AERKey system into operation from end to end. He said the aim is to move control of smart contracts away from a single private key and toward distributed approval policies that can be independently verified.
More broadly, the August breach data and AEREDIUM’s launch point to the same confirmed issue: security teams continue to focus on privileged key management as a central weakness in DeFi. According to the source report, reducing smart contract exploits may increasingly depend on replacing single-key control with threshold-based governance as attackers keep probing infrastructure across ecosystems.
Source: news.bitcoin.com