0x560236575602…56023654

ConfirmedSecurity—117 sat/vB

TRM Labs Counts 32 Price-Manipulation Exploits in 2026, Up From 12

TRM Labs counted 32 price-manipulation exploits in 2026 through early September, up from 12 in all of 2025. The category now covers roughly one in eight crypto hacks, hitting Sui, Cronos and Optimism protocols.

Outputs

  1. TRM Labs counted 32 price-manipulation attacks in 2026 through early September, up from 12 in all of 2025.

  2. Price manipulation accounts for roughly one in eight crypto hacks in 2026, versus one in 17 in 2022.

  3. Tectonic on Cronos saw roughly $75 million borrowed against a token pumped ~100x in 20 minutes, forcing a chain halt.

  4. Full Sail lost ~$91,000 via a Switchboard oracle key compromise on Sui and shut down entirely on August 29.

  5. Cozy Finance lost ~$170,000 (163,326 USDC.e) on Optimism on September 7, its second exploit of the year.

TRM Labs recorded 32 price-manipulation attacks across DeFi lending in 2026 through early September, nearly triple the 12 incidents counted across all of 2025, according to the blockchain intelligence firm's data reported by Odaily Planet Daily on September 2 and republished by KuCoin the same week. Price manipulation now accounts for roughly one in eight crypto hacks, up from about one in 17 in 2022.

The figure marks the highest annual count TRM Labs has recorded for this exploit category. Independent coverage from Cryptonomist corroborated the same numbers days later, describing the surge as concentrated in DeFi lending rather than spread across the wider crypto market.

The story is one of frequency rather than a single blockbuster loss. Neither outlet published a full dollar-loss total for the category, and individual incidents run small relative to nine-figure bridge hacks. But the mechanism keeps recurring across chains, oracle providers and protocol designs.

What does a price-manipulation exploit actually look like?

TRM Labs defines the category narrowly: incidents where an attacker deliberately distorts a collateral price or oracle feed to over-borrow, drain a lending pool, or mis-price a position. That excludes private-key thefts, access-control bugs and governance takeovers, which still produce larger aggregate dollar losses in 2026.

Three sub-patterns dominate this year's incidents:

  • Oracle-key compromise. Full Sail, a yield protocol on Sui, disclosed on August 29 that an attacker added a signing key to a live Switchboard oracle feed and pushed vault prices roughly 100x below market value, draining about $91,000 across three vaults.
  • Market-based manipulation. An attacker drove a thinly traded token up roughly 100x in 20 minutes and borrowed an estimated $75 million against it on Cronos lending protocol Tectonic, an incident severe enough that validators halted the chain.
  • Protocol-logic manipulation. Cozy Finance lost roughly 163,326 USDC.e, about $170,000, on Optimism on September 7, with the exploit transaction landing at 05:43 UTC. The attacker bridged the funds out within 13 minutes.

Why did Full Sail shut down over a $91,000 loss?

The size of the loss understated the damage. Full Sail said its own admin keys were not compromised and pinned the root cause on Switchboard's oracle infrastructure, then announced it would wind down operations on Sui entirely rather than keep running a third-party dependency it no longer trusted.

Switchboard paused operations across Aptos, Sui, IOTA and Movement while investigating how the signing-key vulnerability reached production, according to Cryptobriefing.

Cozy Finance's second exploit in months raises a separate question: a protocol that had already been attacked once should, in theory, have hardened its surface. That a second incident landed within the same year suggests patching one vulnerability does not close off the broader class of exploit behind it. Blockaid flagged the incident in near real time, but detection did not translate into containment before the bridge transaction cleared.

Why does illiquid collateral keep getting exploited?

Nearly every 2026 incident shares one ingredient: collateral that trades too thinly to resist a determined buyer. Blue-chip assets like ETH and BTC require capital most attackers lack to move meaningfully. A token trading a few thousand dollars a day on one venue can be pushed to a wide multiple within minutes.

Protocols keep listing these assets because collateral breadth drives growth. KuCoin's write-up frames the tension directly: risk teams face pressure to list assets faster than their oracle infrastructure can safely support. Tokenized real-world assets compound the problem, arriving with even less on-chain price history and thinner secondary markets.

Flash loans appear in a large share of these exploits but are an accelerant, not the root cause. They remove the need for upfront capital; the underlying vulnerability remains a price feed that can be moved or corrupted. The durable fixes sit on the oracle side — time-weighted average pricing, multiple independent data sources, and circuit breakers that reject out-of-range updates.

How does the category fit 2026's broader loss picture?

Price manipulation leads on incident count but not on dollars. Stolen private keys and access-control failures still produce the largest single losses as part of the more than $1.3 billion in aggregate DeFi hack losses tracked this year. Q2 2026 alone saw 99 incidents and $746 million in losses across all categories.

Other documented manipulation cases this year include Moonwell on Base ($8.7 million via price oracle manipulation), More Markets on Flow EVM (about $410,000 via an E-mode collateral flaw), and Term Finance ($8.5 million in a governance-linked hack).

Aave and Morpho, the two largest lending protocols by total value locked, have not appeared in TRM Labs' 2026 count. Aave relies on governance-driven collateral approvals and Chainlink's decentralized oracle network; Morpho isolates individual markets so a manipulated price cannot cascade. Security researchers describe both as harder targets, not impossible ones — their absence may reflect attacker preference for softer venues as much as structural advantage.

There is also a second-order risk: Cozy Finance operates in risk coverage, meaning the protocols meant to backstop DeFi risk are themselves exposed to the same manipulation patterns as the markets they insure.

What happens next?

The industry response so far has been operational rather than regulatory. No dedicated enforcement action targeting price-manipulation exploits has emerged as of this writing, though the pattern feeds broader DeFi risk-disclosure conversations underway in the US and EU.

Expect collateral listing standards to tighten, with more protocols requiring minimum trading volume or liquidity-depth thresholds. Oracle providers will face pressure to publish audits and incident-response track records the way contract auditors already do. And on the current trajectory — 12 incidents in 2025, 32 in under nine months of 2026 — next year's TRM Labs tally plausibly clears 40 unless oracle design standards shift meaningfully across the sector.

via kucoin.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles