Blockchain intelligence firm TRM Labs has recorded 32 price-manipulation exploits so far in 2026, already more than in any previous year. The attacks pump the price of illiquid tokens, then use them as collateral to drain crypto lending protocols — and the growing size of that lending market gives attackers a bigger target to hit.
Attacks accelerate for a third year running
TRM Labs has registered 32 price-manipulation exploits in 2026, more than in any previous year. The tally has grown for three years straight, up from just 12 cases last year. According to the researchers, price manipulation now accounts for about one in eight hacks, up from one in 17 in 2022. Yet the share of stolen value has stayed relatively flat, suggesting the attacks have possibly become cheaper and more repeatable as flash loan capital makes them easier to fund.
The mechanics are simple. An attacker artificially inflates the price of a thinly traded token, then borrows other assets against it as collateral from a lending protocol. Because the collateral's price crashes immediately after, the attacker walks away with the borrowed asset and abandons the now-worthless collateral without repaying the debt.
Two weak links: illiquid tokens and oracles
According to TRM Labs: "an attacker who can convince a protocol that a near-worthless asset is valuable" never has to touch its code. All it takes is a token with a thin market and an oracle that prices it off that same market. Oracles, the programs that feed collateral values to lending protocols, are the second weak link — a token with little trading volume is relatively easy to pump.
A growing market gives attackers a bigger target
This rise in attacks tracks the expansion of crypto asset-backed lending. Per DefiLlama data covering more than 570 lending protocols, total value locked across these platforms has risen around 56% over the past two years to almost $50 billion, while the value of active loans has nearly doubled to close to $29 billion. Yet the attacks have accelerated even though, in dollar terms, this market fell sharply from its October 2025 highs before recovering since August alongside the broader crypto rally.
As reported by Bitcoin.com News, the most recent major attack came just days ago when money market protocol Tectonic lost over $70 million after an attacker inflated the price of its TONIC token 100x in about 20 minutes. However, the Cronos network, the layer one blockchain underlying Tectonic, rolled back the chain, limiting the attacker's haul to roughly $6 million. Three days earlier, attackers manipulated MAMO oracle prices to drain about $8.7 million from lending protocol Moonwell.
Bad debt hits lenders who never held the token
A user does not need to hold the manipulated token to get hurt. Anyone using the attacked protocol can be exposed once it is left holding bad debt, and their ability to withdraw funds then depends on what assets the affected lending pool has left, and on whether the protocol's operators can freeze the attacker's addresses, reverse transactions, or negotiate a return.
Recovering losses through law enforcement can also prove difficult. In a similar case involving Mango Markets, a U.S. judge ruled in May last year that the platform had no rules and no one testified that users understood borrowing to reflect an intent to repay, while the platform was permissionless and automatic with no prohibition against manipulation. The judge vacated Avram Eisenberg's fraud and manipulation charges because prosecutors had failed to prove the case belonged in New York, and prosecutors have since appealed.
A governance conflict compounds the risk: TONIC is Tectonic's own governance token and is accepted as collateral by the same protocol, while the people who set its risk parameters also benefit when its price rises — but are also affected by the price crash if they are not quick enough to liquidate their positions.
Source: TRM Labs
Trading involves risk.