Risk Radar

Daily Risk Brief / 5 developments

Crypto Risk Monitor — August 30, 2026

CEXVia’s August 30 crypto risk brief tracks the Cosmos EVM six-chain exploit, MANTRA’s $3.6M incident, Kraken sanctions dusting, the Avici/Rain exploit and Luno’s withdrawal deadline.

August 30, 2026Last updated 10:30 UTC6 min read

Security and operational risk remains elevated across several parts of the crypto market going into the final day of August.

The highest-priority issue is the disclosure around a critical Cosmos EVM balance-underflow vulnerability that was exploited across six networks. The same underlying software flaw appears to have been monetized repeatedly between August 20 and August 25, making this more than a single-chain incident. It is a shared-infrastructure failure with implications for any network that depended on affected Cosmos EVM versions.

MANTRA has also published a post-mortem for the unauthorized movement of approximately 720.9 million MANTRA tokens from a burn address and a dormant genesis-era multisig. The project valued the affected tokens at roughly $3.6 million immediately before the incident. MANTRA says validator, administrator, governance and multisig keys were not compromised, and the chain resumed using patched software without a rollback.

A different type of security event is affecting Kraken users. Nearly 12,000 tiny transfers linked by chain-intelligence labels to sanctioned HTX-associated wallets were reportedly sent in a pattern capable of triggering sanctions controls. Some users temporarily lost account access while the exchange reviewed the transactions. Kraken restored access while isolating suspect funds. The attribution question remains disputed: HTX has denied official involvement, so claims that HTX intentionally organized the campaign should not be treated as confirmed.

Elsewhere, Avici disclosed confirmed customer losses tied to an older Rain Solana card-balance contract. The incident affected 1,685 users and $500,859.22 in confirmed Avici card balances. Avici says self-custody wallets were not affected and has committed to full refunds.

Finally, Luno customers facing account closures reach a key operational deadline on August 31: the final normal bank-withdrawal day before affected accounts close on September 1. Users with balances remaining after closure may need to rely on a manual support process.

Today’s Highest-Priority Alerts

RiskEntityEventStatus
CriticalCosmos EVM ecosystemBalance-underflow exploit across six networksDeveloping
CriticalMANTRA ChainUnauthorized movement of ~720.9M MANTRAPost-mortem published
HighKrakenSanctions-triggering dust transfers and temporary account locksAccess restored; attribution disputed
HighAvici / RainSolana card-balance contract exploitRefund process pending
HighLunoAugust 31 final normal withdrawal deadlineDeadline imminent

1. Exchange Exit, Shutdown and Withdrawal Risk

Luno — final normal withdrawal deadline

Affected Luno users have until August 31 to complete normal bank withdrawals before account closure on September 1.

The crypto-send deadline had already ended on June 29. After closure, customers with remaining balances above the applicable threshold may need to use a manual support route rather than the ordinary withdrawal interface.

Read the full update: Luno Account Closure and Withdrawal Deadline

Existing high-risk exchange watchlist

No new verified disclosure today materially changes the standing risk assessment for:

  • BitMart — Critical: restructuring roadmap target remains September 9.
  • AscendEX — Critical: withdrawals remain suspended; Claims Portal target remains September 5.
  • BitMEX — High: exchange trading is scheduled to end September 23.
  • WOO X — High: no new public response materially changes the Seychelles FSA warning.

2. Regulation and Licensing

The Kraken incident is primarily an operational compliance-security event rather than a new enforcement action, but it shows how sanctions screening can itself become an attack surface.

An adversary does not necessarily need to steal funds to disrupt users. If small incoming transfers from sanctioned addresses cause automated account restrictions, attackers may be able to impose compliance costs and temporary denial of service on innocent recipients.

Read the full analysis: Kraken Sanctions Dust Attack and Account Locks

3. Hacks, Vulnerabilities and Asset Loss

Cosmos EVM — Critical

A critical balance-underflow flaw in shared Cosmos EVM software was exploited across six networks between August 20 and August 25.

The disclosed monetized impact was approximately $5.7 million: about $2.87 million converted through decentralized exchanges and about $2.85 million moved through centralized exchanges.

The vulnerability had reportedly been disclosed months earlier and patched, but its production exploitability was initially underestimated.

Read the full analysis: Cosmos EVM Six-Chain Underflow Exploit

MANTRA Chain — Critical

MANTRA’s post-mortem says 720,923,967.99 MANTRA moved without authorization from a burn address and a dormant genesis-era multisig. The tokens were valued at approximately $3.6 million immediately before the incident.

MANTRA says core validator, administrator, governance and multisig keys were not compromised. The chain resumed on patched software without a rollback.

Read the full analysis: MANTRA Chain Exploit Post-Mortem

Avici / Rain — High

Avici says an older Rain Solana card-balance contract was exploited, affecting 1,685 users and $500,859.22 in confirmed Avici card balances.

Self-custody wallets were not affected. Avici has promised full reimbursement.

Read the full analysis: Avici / Rain Solana Card Contract Exploit

4. User Complaints and Operational Anomalies

The Kraken event is unusual because users can be affected without initiating the suspicious transfer themselves.

Reports of temporary account restrictions are consistent with a sanctions-review workflow, but individual complaints should not be generalized into a broader Kraken solvency or withdrawal crisis. At present, this is a targeted compliance-disruption issue, not evidence of platform-wide financial distress.

5. On-Chain and Market Anomalies

The Cosmos EVM and MANTRA incidents remain the most important on-chain security events in today’s brief.

For both, the next risk question is no longer only how the exploit happened. Recovery, exchange tracing, affected-chain patch coverage and the possibility of additional downstream deployments now matter.

6. Watchlist

Key dates to monitor:

  • August 31: Luno final normal bank-withdrawal deadline.
  • September 1: affected Luno accounts close.
  • September 1–5: Kraken liquidates 21 previously delisted assets.
  • September 5: AscendEX Claims Portal target.
  • September 9: BitMart restructuring roadmap target.
  • Mid-September: Core Lightning security details may become public.
  • September 23: BitMEX exchange trading ends.

7. No New Development, Still High Risk

BitMart — Critical

No new verified restructuring disclosure materially changes the current risk view. September 9 remains the next major roadmap date.

AscendEX — Critical

Withdrawals remain suspended. The Claims Portal target date remains September 5.

Moonwell — Critical

No final bad-debt or compensation figure has been confirmed.

Core Lightning — High

Version 26.06.7 remains an urgent security update. Full technical details remain temporarily restricted.

WOO X — High

No material new public response has changed the Seychelles FSA warning status.

Coldcard — Critical

No major new movement has been confirmed from the large dormant attacker-controlled BTC balance.

FAQ

What is the biggest crypto risk event on August 30, 2026?

The Cosmos EVM vulnerability is the highest-priority technical event because one shared software flaw was exploited across six networks.

Is Kraken experiencing a withdrawal crisis?

There is no evidence in this monitoring cycle of a platform-wide Kraken withdrawal or solvency crisis. The incident involves sanctions-linked dust transfers that reportedly triggered compliance restrictions for some users.

What should Luno users do before August 31?

Affected users should complete normal bank withdrawals before the August 31 deadline if possible and keep records of balances, withdrawal requests and support correspondence.

MANTRA is part of the broader Cosmos EVM security story, but its project-specific incident and post-mortem deserve separate tracking because the affected assets, response and recovery questions are distinct.