Key Takeaways
Peckshield reported 50 crypto hacks in August 2026, a 67% bounce from July, whereas whole losses fell to $136.3M.A $74M breach at Tectonicfi led month-to-month damages, however Cronos chain intervention trapped most stolen belongings.Albert Dadon sees threshold-based enclave governance, like AERSeal, changing single-key threat.
Crypto Exploits Surge in August as Monetary Losses Drop
The cryptocurrency sector noticed a pointy rise in safety breaches in August 2026, recording 50 main hacks throughout the business. In line with new information from blockchain safety agency Peckshield, the variety of exploits elevated by 67% from the 30 incidents logged in July.
Regardless of the surge in assault frequency, the entire worth of stolen belongings fell sharply. Month-to-month losses reached $136.3 million, a 49.5% drop from the roughly $270 million stolen in July. A single exploit concentrating on decentralized lending protocol Tectonicfi accounted for about $74 million, greater than 54% of the month’s whole losses.
Though the Tectonicfi assault was giant in scale, the exploiter struggled to dump the belongings. Solely about $6 million was bridged out earlier than the Cronos community paused its chain, leaving most funds trapped. The remaining $62.3 million in losses got here from dozens of smaller assaults on protocols together with Termlabs ($8.5 million), Moonwell ($8.7 million), Coinsbuy ($7.9 million), and TAC ($7.5 million).
Peckshield’s evaluation factors to a shift in attacker technique. Whereas headline-grabbing mega-exploits declined in contrast with July, risk actors more and more focused mid-tier protocols and decentralized finance elements. Business consultants notice that regardless of diversified assault vectors, many decentralized finance (DeFi) breaches nonetheless hint again to a single level of failure: compromised privileged keys saved on weak endpoints.
New Product Launched to Deal with Single-Key Vulnerabilities
That single-key vulnerability is identical architectural flaw AEREDIUM goals to eradicate with its newly introduced product constructed on its threshold key infrastructure. Generally known as AERSeal, the product is designed to take away the non-public key that sometimes controls privileged sensible contract features and exchange it with threshold signing ruled by a number of approved approvers.
Sensible contracts usually carry highly effective administrative permissions, together with minting, upgrading, or executing different privileged actions. Nevertheless, when these permissions depend upon a single non-public key, shedding that key can imply completely shedding entry, whereas theft or compromise can provide an attacker full management. AERSeal addresses this by transferring these privileged powers to a threshold key, with key shares held individually inside hardware-attested enclaves.
The shares are by no means reconstructed into an entire non-public key; as an alternative, signatures are produced by means of the CGGMP24 threshold signing protocol. The sensible contract itself doesn’t transfer, and AERSeal at the moment helps Ethereum Digital Machine (EVM) and EVM-compatible chains.
Earlier than custody is activated, the product identifies the privileged powers related to the contract and requires them to be transferred to the edge key. The system then verifies on-chain that these powers have been totally transferred. It additionally permits clients to independently confirm the edge key assigned to them.
Shift Towards {Hardware}-Attested Enclave Governance
Utilizing tackle derivation and a signed recent problem, clients can confirm each derivation and possession of the important thing—together with offline—slightly than relying solely on AEREDIUM’s assertion. Onboarding contains know-your-customer (KYC) verification, contract registration, cryptographic key verification, switch of privileged powers, on-chain verification, and activation of the client’s approval coverage.
“AERSeal is the primary full product to place AERKey into operation from finish to finish,” stated Albert Dadon, founder and CEO of AEREDIUM. “The objective is to take away the concept management over a complete sensible contract ought to depend upon one non-public key. With threshold signing and outlined approval insurance policies, management could be distributed and independently verified slightly than concentrated in a single level.”
In the meantime, Dadon instructed Bitcoin.com Information that this structure instantly addresses the basis explanation for many exploits highlighted in reviews like Peckshield’s: privileged keys that exist entire on machines that may be phished. Underneath AERSeal’s hardware-attested enclave mannequin, governance depends on human consensus and {hardware} verification slightly than a weak developer workstation.
A compromised laptop computer yields at most one signatory seat whereas API tokens can suggest actions however by no means approve them. Enclaves be a part of the signing group solely after recent attestations verified towards a distributed belief checklist, defending towards unauthorized {hardware} configurations and replay assaults.
As attackers proceed testing infrastructure throughout rising and established ecosystems, safety leaders argue that shifting away from single-key administration towards threshold-based, enclave-enforced governance might be important to lowering sensible contract exploits.








