< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Cryptocurrency exploits and address poisoning drain millions

The cryptocurrency sector experienced significant security breaches in late August 2026, with multiple exploits targeting infrastructure and user behavior. Between August 17 and August 23, five distinct on-chain exploits resulted in losses exceeding $13 million. These incidents included a cross-chain DEX, a stablecoin bridge, and a Bitcoin restaking Layer 1. Notably, MAYAChain, a cross-chain DEX utilizing THORChain’s open-source code, suffered a $10.9 million loss after six chained software bugs were exploited, causing the CACAO token price to drop 89%.

Separately, the Tron network was targeted by an address poisoning scam that drained $9.4 million from 15 victims over a four-week period. In this tactic, attackers send tiny amounts of cryptocurrency from fake addresses that mimic legitimate transaction history. Users inadvertently copy these fraudulent addresses, sending funds to the attacker instead of the intended recipient. One major victim, Bofur Capital, lost approximately $2 million to this method. While some wallets have implemented protections against such attacks, these features are primarily focused on EVM-compatible chains.

Entities

Bofur Capital · MAYAChain · SlowMist · THORChain · TRON