Risk Radar

Daily Risk Brief / 6 developments

Crypto Risk Monitor — August 31, 2026

CEXVia tracks the Tectonic exploit and Cronos halt, Rain card-contract reimbursements, Luno and Bitfinex withdrawal deadlines, Revolut’s USDT cutoff, Polygon security fixes and high-risk exchange wind-downs.

August 31, 2026Last updated 10:30 UTC13 min read

August 31 closes with a materially higher crypto-risk profile than the previous day. The main drivers are not broad token-price moves. They are a new Critical lending-protocol exploit that forced a blockchain halt, a shared card-infrastructure vulnerability affecting multiple consumer products, and several hard platform deadlines that directly change how users can withdraw, hold or recover assets.

The highest-priority event is the exploit affecting Tectonic, the largest lending protocol on Cronos. Cronos confirmed that it identified an exploit and halted the network. Tectonic acknowledged the incident and told users not to interact with the protocol while the investigation continues. As of this update, neither Tectonic nor Cronos has published a final post-mortem, a final economic-loss figure or a confirmed network restart timetable.

That distinction is important because the most widely circulated loss number — roughly $75 million — comes from on-chain analysis, not a Tectonic final accounting. The leading reconstruction says an attacker pushed the thinly traded TONIC token roughly 100 times higher within about 20 minutes, used the inflated collateral value to borrow other assets and managed to bridge about $6 million to Ethereum before Cronos halted. A separate archive-node analysis has produced a larger gross affected-pool figure. CEXVia therefore rates the incident Critical, but treats all current dollar amounts as Developing / On-chain estimates until Tectonic publishes its reconciliation.

The second material development is the Rain Solana card-contract incident. This is now clearly a shared-infrastructure event rather than an Avici-only issue. Rain said a small number of programs were still using an outdated version of its Solana contracts. It upgraded all programs on that version, said no further unauthorized activity had been observed, engaged third-party forensic specialists and said it would work with law enforcement and relevant regulators.

Avici reconciled 1,685 affected users and $500,859.22 in affected card balances. It later said refunds were processed in full and added an extra 10% cashback. Tria disclosed 636 affected users and $431,945, then said every affected user received a full refund plus an additional 10%. The two named programs therefore account for 2,321 users and $932,804.22 in confirmed affected balances. Broader on-chain reporting has traced roughly $1.0–$1.1 million across Rain-powered programs, so the provider-wide total remains incompletely reconciled.

Several asset-access deadlines also fall today. For Luno, August 31 is the final day affected customers in the regional exit can sell crypto and withdraw fiat through the normal bank-withdrawal process. Accounts close September 1. Luno says qualifying balances can still be handled manually after closure, but fees begin accruing. This is a scheduled exit and asset-access event, not evidence of insolvency.

For Bitfinex, standard withdrawals for 13 delisted tokens and NEOGAS remain open until 10:00 UTC on August 31. Current Bitfinex token-specific help pages for affected assets such as ATOM, B2M and LDO state that trading ceased on July 3 at 10:00 UTC. Today’s relevant risk is the final standard-withdrawal cutoff: after it, users must rely on Bitfinex’s Delisted Token Recovery Policy, which may involve fees and is limited in time.

For affected European Revolut users, August 31 is the final stage of the USDT wind-down described in customer notices. Revolut’s current help material says USDT was removed because it does not meet the stablecoin regulatory requirements applying to its crypto service in the affected region, including MiCA-related requirements. This should be classified as a regulatory distribution and forced-exit risk, not as evidence of a Tether reserve failure.

Finally, Polygon PoS has publicly documented security and liveness bugs that were fixed privately before disclosure through the Austin and Kyoto hard forks. Polygon says none of the disclosed issues was observed disrupting mainnet. Bor v2.10.0 and Heimdall v0.11.0 are already active and mandatory.

1. Today’s Highest-Priority Alerts

RiskEntityEventTimeLatest statusEvidenceContinue monitoring?New vs. Aug. 30
CriticalCronos / TectonicLending exploit followed by Cronos network haltAug. 30–31Halt confirmed; no restart time or final post-mortem; ~$75M remains an on-chain estimateOfficial + on-chain + major mediaYesNew Critical incident
HighRain / Avici / TriaOutdated Solana card-contract vulnerabilityAug. 28–31Rain says affected-version programs upgraded; Avici and Tria say reimbursements completed with extra 10%; forensics ongoingCompany statements + on-chain + mediaYesScope expanded; refund status improved
HighLunoRegional service exit and final normal bank-withdrawal dayAug. 31Final normal bank-withdrawal day; affected accounts close Sept. 1OfficialYesDeadline reached
HighBitfinexWithdrawal cutoff for 13 delisted tokens + NEOGASAug. 31, 10:00 UTCStandard withdrawals remain open until cutoff; recovery afterward is limited and fee-bearingExchange announcementYesFinal withdrawal day
MediumRevolut / USDTEuropean USDT removal under regional stablecoin rulesAug. 31Final wind-down stage for notified affected customersOfficial help + customer notices/mediaYesFinal cutoff day
MediumPolygon PoSAustin/Kyoto security fixes disclosed after deploymentAug. 27 onwardPatched; mandatory versions live; no observed mainnet exploitationOfficialYesNewly public technical detail
HighBitMEXExchange wind-down in reduce-only phaseAug. 26–Sept. 23New/increased positions restricted; forced closure possible before Sept. 23OfficialYesNo material change today
CriticalAscendEXWithdrawals suspended; claims/insolvency processOngoingClaims portal targeted for Sept. 5; portal will not initially restore withdrawalsOfficialYesNo verified milestone today

2. Exchange Exit, Shutdown and Withdrawal Risk

Luno — High: the final normal bank-withdrawal day

Luno’s regional exit is now at the last stage where affected customers retain normal self-service withdrawal control. Deposits, buying and receiving crypto stopped on June 1. Normal outbound crypto sends ended June 29. August 31 is the final day users can sell crypto and withdraw fiat to a bank through the ordinary interface. On September 1, the relevant accounts close and normal wallet access ends.

Luno says users with more than the equivalent of $10 remaining can contact support after closure for a manual withdrawal. The company says it normally processes those withdrawals within three to five business days after all required information is verified. But the process is slower and more conditional than ordinary withdrawal. Balances also begin to incur a $2 monthly inactivity fee in September, with an additional $50 monthly dormancy fee from December.

Update the existing page: Luno Withdrawal Deadline: What Happens After August 31

Bitfinex — High: the last standard-withdrawal window

Bitfinex’s 13-token delisting did not begin today. Current Bitfinex help pages for affected assets including ATOM, B2M and LDO state that trading ceased on July 3 at 10:00 UTC.

What remains today is the final normal withdrawal route. Withdrawals for the delisted assets, including NEOGAS, remain open until August 31 at 10:00 UTC. After the cutoff, users must rely on the Delisted Token Recovery Policy. Bitfinex says a recovery fee may apply and recovery can only be attempted for up to two months after withdrawal closure.

Read the detail: Bitfinex 13-Token Withdrawal Deadline

BitMEX — High: already in reduce-only wind-down

BitMEX remains an active asset-access risk even though there is no new material development today. Since August 26, users have been unable to increase positions and can only reduce them. BitMEX says it may force-close positions during the wind-down, and any remaining position at the September 23, 04:00 UTC closure will be force-closed.

The exchange describes the closure as the result of a strategic review rather than financial distress, a hack or immediate regulatory pressure. That fact boundary matters. CEXVia should continue to track position closures, withdrawal operations and post-closure fee/withdrawal changes without describing the event as insolvency.

AscendEX — Critical: claims process, not normal exchange access

AscendEX remains one of the most serious centralized-exchange watchlist cases. Official notices say normal operations and withdrawals remain suspended while the company explores rescue, recapitalization and restructuring options in parallel with preparations for a possible formal insolvency process.

The company targets September 5 for the initial launch of a customer claims portal, but warns that the date can change. The portal is designed to show recorded balances, accept claims and collect documents; it will not initially restore trading, deposits or withdrawals. A displayed balance does not mean a claim has been admitted or establish the timing or amount of recovery.

3. Regulation and Licensing

Revolut / USDT — Medium: MiCA changes distribution, not the token’s existence

Revolut’s USDT removal is a clear example of how regulation can change the practical availability of an asset without the asset itself failing.

Revolut’s help center says USDT was removed because it does not currently meet the stablecoin regulatory requirements applying to the company’s crypto services in the affected region, specifically referring to requirements under MiCA around authorization, reserves, disclosure and supervision.

Revolut is also migrating EEA crypto users to Revolut Digital Assets Europe Ltd, which the company says is licensed by CySEC as a MiCA Crypto-Asset Service Provider under licence 001/2025. A regulated CASP has strong incentives to standardize its product list around the assets it can support within its regulatory perimeter.

For users, the risk is therefore distribution and execution: USDT may remain live and liquid on-chain, but a specific regulated platform can stop supporting it and may convert remaining balances after the final exit window.

Read the detail: Revolut Ends USDT Support for Affected European Customers

WOO X / Seychelles — High, no material new development

The Seychelles FSA warning remains active. The regulator said WOOTECH Limited Corp, operator of WOO X, has no current legal or operational nexus to Seychelles and has not been authorized under the Virtual Asset Service Providers Act 2024.

No verified development today changes that regulatory finding.

4. Hacks, Vulnerabilities and Asset Loss

Cronos / Tectonic — Critical

This is the largest live security event in today’s monitoring cycle.

The confirmed layer is narrow but severe: Tectonic acknowledged an incident, Cronos halted, and users were told not to interact with the protocol. The current TONIC price-manipulation path and roughly $75 million affected-assets estimate come from on-chain research, not the project’s final report.

That evidence should be written as: “On-chain analysis estimates roughly $75 million affected”, not “Tectonic confirmed a $75 million loss.”

Read the full detail: Cronos Halts After Tectonic Exploit

Rain / Avici / Tria — High, with customer loss materially remediated

Rain says the vulnerability affected a small number of programs still using an outdated Solana contract version. All programs on that version were upgraded, Rain says no further unauthorized activity was observed, and third-party forensics plus law-enforcement/regulatory engagement are underway.

Avici says the incident affected the separate Solana card-balance layer, not users’ ordinary self-custodial Solana/EVM wallets. It reconciled 1,685 users and $500,859.22 and later said refunds were processed in full with an additional 10% cashback.

Tria disclosed the same custody boundary, reconciled 636 users and $431,945 and later said every affected customer received a full refund plus 10%.

Update the existing page: Rain Solana Card Exploit: Avici and Tria

Polygon PoS — Medium: patched disclosure, not an active exploit

Polygon’s Austin hard fork addresses two Bor denial-of-service paths. Kyoto addresses a larger set of Heimdall consensus and input-validation issues, including deeply nested protobuf messages that could force expensive validator work, unbounded fee-coin lists and several checkpoint/milestone/replay edge cases.

Polygon says the fixes were deployed before public disclosure and the issues were not observed disrupting mainnet.

Read the detail: Polygon Austin and Kyoto Security Fixes

5. User Complaints and Operational Anomalies

No new community complaint cluster found in this monitoring window is sufficiently corroborated to justify calling another major exchange insolvent or subject to a platform-wide withdrawal freeze.

CEXVia should keep three evidence levels explicit:

  • Confirmed: official service status, formal withdrawal suspension, closure schedule or other verified platform-wide condition.
  • Developing: strong on-chain or multi-source evidence where the entity has not yet published final accounting.
  • Community / Unverified: Reddit, X or other user reports that have not been independently corroborated.

For today, Luno, AscendEX, BitMEX and Bitfinex are confirmed operational/access events. Tectonic’s final loss and Rain’s provider-wide final reconciliation remain developing. Isolated KYC or withdrawal complaints at other venues remain community signals unless they develop into a broader cluster.

6. On-Chain and Market Anomalies

The most important on-chain anomaly is the Tectonic attack.

If the current reconstruction is confirmed, the incident demonstrates why collateral risk cannot be assessed from market capitalization or a displayed token price alone. A lending protocol must evaluate executable liquidity, oracle construction, collateral factor, liquidation capacity and the amount of capital required to move the reference price.

A low-liquidity asset can become dangerous when the cost to manipulate its reference price is far smaller than the borrowing power the protocol grants against the manipulated value.

The Rain event also has a material on-chain trail. Independent transaction analysis describes repeated authorization/admin-addition/withdrawal patterns, followed by conversion of stolen stablecoins into SOL, bridging to Ethereum and movement through Tornado Cash. Rain has not yet published a complete technical post-mortem confirming every step, so CEXVia treats that reconstruction as independent analysis rather than the definitive code-level root cause.

7. Watchlist

Date / WindowEventWhat CEXVia is watching
Aug. 31Luno regional exitWhether users complete normal bank withdrawals before closure
Aug. 31, 10:00 UTCBitfinex 13-token withdrawal cutoffWhether deadline changes; later recovery success, fees and timing
Aug. 31Revolut USDT wind-downResidual-balance treatment and user complaints about conversion
ImmediateCronos / TectonicRestart block, rollback/no-rollback decision, official loss and bad debt, attacker-address treatment
ImmediateRain / Avici / TriaProvider-wide loss reconciliation, technical root cause and any additional programs
Sept. 1LunoPermanent account closure for affected users
Sept. 2, 12:00 UTCBitMEXEarly settlement of 11 perpetual swaps
Sept. 5AscendEXTarget date for initial claims-portal launch
Sept. 5–6KrakenScheduled delisting of 21 assets
Sept. 9BitMartRestructuring / business-resumption roadmap target
Sept. 23, 04:00 UTCBitMEXExchange trading closure and forced closure of remaining positions
Sept. 28BitMEX post-closure operationsAPI withdrawal and multi-network withdrawal changes

8. No New Development Today, but Still High Risk

BitMart — Critical

BitMart is developing a potential restructuring plan as an alternative to a full wind-down. The company says the plan may combine phased resumption of some operations with creditor distributions and has appointed White & Case as restructuring counsel. The next stated update target is no later than September 9. No verified development today changes that status.

AscendEX — Critical

Withdrawals remain suspended. September 5 is a target for the claims portal, not a guaranteed launch date, and the portal will not initially restore withdrawals. The unresolved variable is ultimate customer recovery.

BitMEX — High

The exchange is already in reduce-only/risk-limit mode. No new event today changes the September 23 closure timetable, but customers with open positions remain exposed to forced closure during the wind-down.

WOO X — High

The Seychelles FSA warning remains unresolved. No material public development found today changes the regulator’s statement that WOOTECH Limited Corp is not authorized under Seychelles’ VASP law.

Core Lightning — High

The urgent 26.06.7 security-update watch remains open. The main risk is exposure for operators that have not upgraded before more complete vulnerability details become widely available.

Why Today Matters

Three distinct types of crypto risk are visible at the same time.

Tectonic is protocol and market-structure risk. A thinly traded collateral asset can become a lever against a much larger lending pool if oracle design and collateral factors do not reflect real executable liquidity.

Rain is shared-provider and custody-boundary risk. A consumer product can have a self-custody wallet while relying on a separate third-party smart-contract layer for card spending. When users move funds into that layer, the risk perimeter changes.

Luno, Bitfinex and Revolut are asset-access risks. Users may not lose economic value immediately, but deadlines, delistings, forced conversion and manual recovery procedures can materially change when and how assets can be moved.

Those states should never be collapsed into one generic “exchange risk” label. Hacked, insolvent, delisted, closed, reduce-only and temporarily inaccessible are different risk conditions.

FAQ

What is the highest-risk crypto event on August 31, 2026?

The Tectonic exploit and Cronos network halt. The exploit and halt are confirmed; the roughly $75 million affected figure remains an on-chain estimate pending Tectonic’s final accounting.

Has Cronos restarted?

As of this update, CEXVia has not identified a verified official restart timetable or final post-mortem.

Were Avici and Tria users reimbursed?

Yes. Both companies subsequently said affected users were fully reimbursed and received an additional 10% benefit/cashback. Rain says affected programs were upgraded.

Is Luno insolvent?

The current official exit guidance does not establish insolvency. The tracked event is a scheduled regional exit with withdrawal and account-closure deadlines.

When is the Bitfinex withdrawal cutoff?

August 31, 2026 at 10:00 UTC for the affected delisted tokens and NEOGAS. After that, users must rely on the Delisted Token Recovery Policy.

Does Revolut removing USDT mean Tether has failed?

No. Revolut describes the change as a regulatory/product-support decision tied to stablecoin requirements in the affected region, including MiCA.