Price manipulation was behind roughly one in every eight crypto hacks this year, and the count keeps climbing. Security researchers logged 32 price-manipulation exploits across DeFi lending protocols through August 2026, a record, and nearly triple the 12 recorded in all of 2025. The attack itself is old. What changed is how cheap and repeatable it has become, and how few lending markets have closed the door it walks through.
The clearest example landed at the end of August on Cronos, the chain operated by Crypto.com.
A token worth $0.00000103 unlocked $75 million
An attacker pushed the price of TONIC, a thinly traded token, up around 100 times in about 20 minutes. On-chain researcher Weilin Li put the manipulated value near $0.00000103 per token. That inflated figure was enough to borrow an estimated $75 million from Tectonic, a lending app on the network, against collateral that had been worth almost nothing an hour earlier.
The protocol's code did what it was written to do. It read a price, accepted the collateral, and released the loan. The contract behaved exactly as designed, and the manipulated price feeding it is where the money walked out. That is the signature of price manipulation, and it is the same class of weakness that let an attacker reach into Injective's core modules while auditors kept flagging the pattern and protocols kept shipping around it.
The dollar losses barely moved
The count is only half the picture. Across all 207 hacks tracked this year, total losses came to about $972 million, with a median near $219,000 per incident. Thirty-two price-manipulation attacks, yet the aggregate stolen did not climb anywhere near as fast as the count. One analyst put it plainly: these attacks are cheap and repeatable, which is why the incident tally runs well ahead of the dollar figure.
| Metric | 2026 figure |
|---|---|
| Price-manipulation exploits | 32 (record) |
| Same attacks in 2025 | 12 |
| Share of all crypto hacks | about 1 in 8 |
| Total hacks tracked | 207 |
| Median loss per hack | around $219,000 |
That pattern flips the picture most people carry. The costliest incidents this year came from stolen keys, with a single crew responsible for close to half the total, not from clever math. Code bugs still make up most incidents but only a sliver of the money lost, and price manipulation sits in an odd middle: frequent, cheap to run, rarely catastrophic on its own.
Every price manipulation attack needs the same open door
Each one relies on a single ingredient. A lending market that trusts the spot price of a token it accepts as collateral, plus a token illiquid enough that a few hundred thousand dollars can move its price a hundredfold. Kalshi bumped into the same design question when its copper perpetual leaned on a crypto oracle rather than the COMEX feed. The defenses are well known: time-weighted averages, prices pulled from deep markets, caps on how far one feed can swing a loan. Plenty of protocols still skip them.
What clawed back most of the Tectonic money was centralization. Only about $6 million reached Ethereum before the drain stopped; the other $68.7 million stayed frozen on Cronos, because the network halted block production within minutes. Cronos runs a Tendermint consensus capped at 100 validators, a set small enough for its operators to coordinate a stop fast, and small enough to override you. Other lending platforms have reached for the same lever this year, freezing markets to buy time after a drain. Lending markets now hold close to $50 billion in deposits, with about $29 billion in active loans across 570 protocols, so the surface for the next cheap price manipulation attack is only widening.