Web3 Security Weekly News Review — August 17–23, 2026
A ~$23.5M DEX aggregator router exploit via a flawed token-approval path, followed by a ~$18.5M custody hot-wallet key leak. With MEV, phishing and sanctions freezes added in, tracked losses reached ~$96M, up ~12% week-over-week.
- Tracked losses$96M
- Events18
- Largest event$23.5M
- Phishing share14%
Overview
Week of August 17–23 saw tracked Web3 security losses rise to ~$96M, the fourth straight weekly increase. The story is breadth, not one blowup: the top three events carry ~57% of the total (down from ~80% last week), while phishing climbed to its highest share in a month. Contract exploits still lead at 46%, but custody (28%) and phishing (14%) keep gaining share — the same rotation my weekly data report measures. Two TRON-linked items carry explicit on-chain footprints.
The 18 Stories
DEX aggregator router drained ~$23.5M via approval-path abuse
On August 19, an attacker drained approximately $23.5M in stablecoins and wrapped ETH from the router contract of a DEX aggregator. The attacker registered a malicious token, routed a small swap through the aggregator, and used the approval created in that path to call transferFrom on user funds the router held authorization for. The sweep completed inside a three-block window, and roughly $6.5M has since been frozen via exchange cooperation.
Source: CertiK, PeckShield analyses; Etherscan trail
Custody hot-wallet key leak (~$18.5M)
A custody provider reported that a hot-wallet signing key was exposed through a compromised internal dashboard session, allowing unauthorized withdrawals of roughly $18.5M. The provider has paused affected services and engaged two forensics firms. The company statement is corroborated by Chainalysis transaction analysis, though the full fund flow is still being mapped.
Source: Official statement; Chainalysis
MEV sandwich on lending pair (~$12.9M)
A flash-borrowed sandwich attack extracted approximately $12.9M from a lending pair on Ethereum across consecutive blocks. The attacker manipulated the pair's price window between user transactions, profiting from slippage at the expense of liquidity providers. The transaction trail is fully public on Etherscan and has been reconstructed by SlowMist.
Source: SlowMist analysis; Etherscan
Exchange key-rotation flag (~$6.5M)
An exchange paused ERC-20 withdrawals for several hours after an anomalous internal flow of approximately $6.5M. The exchange attributes the flow to a routine key-rotation procedure, but it has not published a post-mortem. Until it does, I keep this event unconfirmed and exclude it from firm recovery expectations.
Source: Exchange official X
Sanctions-linked asset freezes (~$6.4M)
OFAC added a mixer operator to the Specially Designated Nationals list, and several exchanges subsequently froze approximately $6.4M in assets linked to the designation. The funds are recoverable in principle through compliance processes, which is why I track them separately from unrecovered exploit losses in the category tables.
Source: OFAC designation; CoinDesk
Fake bridge-frontend phishing wave (~$5.2M)
A phishing campaign cloned the frontend of a popular cross-chain bridge and swapped the RPC endpoint, so users who signed through the fake interface handed approvals and seed phrases to the attackers. Roughly $5.2M in losses is linked to the campaign, spread across several hundred small victims, and takedown requests are in progress.
Source: SlowMist; rekt.news
Lending oracle manipulation (~$4.6M)
A lending pool was exploited through a price-input manipulation path: the attacker moved a thinly-traded collateral asset's price, borrowed against the inflated value, and defaulted on roughly $4.6M. PeckShield and the project's own blog confirm the path, and the affected market has been paused while the oracle is re-anchored.
Source: PeckShield; project blog
Support-impersonation + fake seed tool (~$3.1M)
A wave of verified-looking support accounts on X distributed a fake seed-recovery tool; users who entered their seed phrase lost their wallets, with roughly $3.1M in tracked losses. Chainalysis traced the pattern and several projects have published warnings. The fake tool domains are being taken down, but new ones keep appearing.
Source: Chainalysis; official X
Bridge slippage-window abuse (~$3.0M)
A cross-chain liquidity bridge saw an anomalous slippage window exploited across three consecutive blocks, draining approximately $3.0M. The bridge paused deposits and forensics are ongoing; the project has not yet confirmed the full attack path. The figure may revise as the investigation closes.
Source: Project notice; block explorers
Cloned Tron-energy airdrop site (~$2.8M)
A cloned Tron-energy airdrop interface asked Tron wallet users to sign setApprovalForAll before showing any balance; linked losses are estimated at ~$2.8M. The approvals are visible on TRONSCAN, confirming the TRON footprint, and takedown requests have been filed against the impersonating domains.
Source: SlowMist; TRONSCAN (TRON footprint)
Malicious wallet extension campaign (~$2.3M)
A browser wallet-extension campaign is under review after roughly $2.3M in linked losses emerged. The extensions impersonate popular wallets and route signing through a malicious backend; Hacken has published an advisory and major stores are removing the listings.
Source: Hacken advisory
Tether freeze on ransomware-linked address (~$2.2M)
Tether blacklisted a ransomware-linked address, freezing approximately $2.2M in USDT within hours of the address being flagged. The blacklist was applied on-chain and the TRON-basis address is publicly labeled, which makes this one of the fastest and most recoverable items of the week.
Source: Tether official; TRONSCAN (TRON footprint)
Staking-helper approve reuse (~$2.0M)
A staking helper contract reused a standing approval to drain user balances, costing approximately $2.0M. The vulnerability let the helper's operator withdraw funds users had approved for staking purposes. The bug was confirmed by CertiK and a fix has been deployed, with affected users advised to revoke approvals.
Source: CertiK; GitHub advisory
Corporate wallet seed seizure (~$2.0M)
A corporate wallet lost approximately $2.0M in a seed-seizure incident, according to an official disclosure corroborated by Elliptic. The funds were held in a single-signature setup, which allowed a single point of failure to take control of the wallet.
Source: Official disclosure; Elliptic
NFT marketplace listing bug (~$1.0M)
A listing-pricing bug reportedly drained approximately $1.0M from an NFT marketplace, disclosed through a bug-bounty program rather than the marketplace itself. The marketplace has not yet published a statement, so I keep the event unconfirmed.
Source: Immunefi disclosure
Uninitialized-proxy upgrade study
A security firm published a study mapping uninitialized-proxy upgrade risks across major chains, identifying upgrade paths that can silently brick or take over contracts. No loss figure is attached — the report is a detection and hardening signal for developers.
Source: TRM Labs report
MEV-exploit taxonomy released
An audit shop released a taxonomy of MEV-based exploit patterns — sandwich attacks, arbitrage extraction and liquidation gaming — with detection criteria for each. The taxonomy is aimed at auditors and monitoring teams.
Source: Solidus Labs
Forensics platform raises $12M
An on-chain forensics platform closed a $12M round, per The Block. The funding is a confidence signal for the security-services market, which my monthly report tracks alongside loss data.
Source: The Block
Key Signals
| Signal | Reading |
|---|---|
| Loss trend | ↑ +12% w/w; 4th straight up week |
| Top vector | Contract 46%, custody 28%, phishing 14% |
| Concentration | Top-3 ≈ 57% of losses (down from 80%) |
| Verification | 12 confirmed / 6 open |
| TRON activity | 1 clone + 1 freeze, both with on-chain footprints |
| Biggest watch item | Exchange key-rotation flag (unconfirmed) |
TRON Footprint
Two TRON-linked items this week, both verified on-chain:
| Item | On-chain footprint | Status |
|---|---|---|
| Cloned Tron-energy airdrop site (~$2.8M) | setApprovalForAll approvals signed on Tron wallets; addresses visible on TRONSCAN | Confirmed pattern |
| Tether freeze (~$2.2M) | USDT blacklist applied on-chain; TRON-basis address labeled | Confirmed |
For Tron energy users: legitimate energy and bandwidth services never ask you to sign arbitrary approvals. If a page asks for setApprovalForAll before showing a balance, treat it as hostile — check the request on TRONSCAN before confirming any signature.
What I'm Watching Next Week
- Root-cause disclosure on the router exploit and any approval-swept contagion.
- Whether the exchange key-rotation flag is confirmed or withdrawn.
- Takedown progress on the cloned Tron-energy phishing domains.
- Whether the bridge slippage case closes with a revised figure.
- Recovery progress on the two largest events and new freeze activity.
Frequently Asked Questions
How do you source these events?
Every item traces to a whitelist source: security firms (Chainalysis, SlowMist, CertiK, PeckShield, Immunefi, Hacken, TRM Labs, Elliptic, Solidus Labs, rekt.news), block explorers, project official channels, regulators and industry media. Nothing is reported from rumor.
Why are some events marked unconfirmed?
If I cannot independently verify the source of truth yet, I label it unconfirmed or under investigation rather than guessing. Figures may be revised as investigations conclude.
Why do regulatory freezes appear in loss totals?
They are recoverable in principle but still represent funds removed from circulation. I track them separately from unrecovered exploit losses so the mix stays transparent.
Is this financial advice?
No. It is a security research digest for informational purposes only, not investment or security guidance.
Strengthening your defenses? See how transaction fees and energy costs scale on Tron at Tronsell.io.