BlockThreat - Week 34, 2026

$19.9M stolen across 10 incidents. 5 blockchains exploited.

BlockThreat - Week 34, 2026

This week I'm tracking 10 incidents, ranging from governance attacks and reward manipulation exploits to the usual signature verification and access control failures. But the real story is five blockchains compromised in a single week. A staggering number that I have never seen in the history of tracking onchain events.

Three of the five trace back to a silent patch from Cosmos Labs fixing a critical bug in a Cosmos-EVM staking precompile. The patch went out without prior notification to some of the major downstream chains which triggered the mass compromise days later:

2026-08-19 - Cosmos Labs releases the critical patch
2026-08-21 - Mantra Chain
2026-08-22 - TAC
2026-08-22 - KiiChain

GalaChain and BounceBit each lost millions to separate issues. You can find detailed post-mortems in the Hacks section below.

The takeaway for chain operators is to watch your upstream codebases. The window between a vulnerability becoming public and a fully weaponized exploit is now measured in hours, not weeks. Move too slowly and you join the list.

Also this week, we cover the governance exploit of Term Finance, arbitrary code injection in The Sandbox, a familiar signature verification bug in Allbridge, and other major incidents, plus the latest supply chain attacks to check your environment against, new phishing techniques, and all the bug hunting and defensive research and tooling that crossed my feeds.

Let’s dive into the news!