profile

QuillAudits Web3 Security πŸ₯·πŸ›‘️

Your official QuillAudits update stream, covering product launches, security insights, event announcements, reports, and key developments from across the organization.

Sep 04Β β€’Β 4 min read

The Quill Sentinel August 2026


πŸ‘‹ Welcome to the August Edition

We joined Sherlock's new Audit Engine, putting QuillShield's multi-agent review inside one of the industry's most-used audit platforms. And we went live on multisig security, breaking down how $1.7B has left secure wallets through hidden delegatecalls and drifting thresholds.

$144.1M stolen in August. One Cronos lending market lost more to a manipulated spot price than the other 21 incidents of the month combined. Full story in Hack Watch below.

On research, we mapped the freeze authority hiding inside neobank stablecoins, the habits that actually keep a multisig safe, and audit checklists for three RWA standards.

Here's the full August roundup.

From the Quill Research Desk

August's research kept landing on the same conclusion. The risk in every one of these systems sits in the privileged control surface, not the happy path, whether that's a Safe's module list, a stablecoin's freeze key, a token's admin role, or a vault's share price.

​How to Check Your Safe Wallet's Security in 60 Seconds A hands-on walkthrough of Safe Inspector on a live Safe: 7 owners, a 4-of-7 threshold, and one module absent from the known registry. The scan scored 78 out of 100, an unrecognized module flagged for review, not assumed malicious.

​Someone Else Controls the Neobank Dollars Over 11,000 USDT freeze actions across Ethereum and Tron have locked roughly $5.85 billion, with more than $1.4 billion permanently destroyed. Freeze, mint, and upgrade authority sit outside a neobank's control plane entirely, a risk no reserve attestation ever surfaces.

​Multisig Security Habits That Actually Matter Most multisig failures trace back to a habit nobody wrote down, not the code. Dedicated signing devices, thresholds that can't collapse to one compromise, out-of-band confirmation, and scheduled Safe reviews matter more than any dashboard number suggests.

​ERC-3643 (T-REX) Security Audit Checklist A structural checklist for T-REX tokens, where every transfer clears an identity check and a compliance check before it settles, and privileged roles can freeze, force, mint, burn, and recover holdings entirely.

​ERC-7518 (DyCIST) Security Audit Checklist A checklist for DyCIST's partitioned tokens, where each tokenId carries its own lockups and compliance rules, and eligibility often rests on a signed EIP-712 voucher. Get the voucher validation wrong and the entire compliance gate falls open.

​ERC-4626 Vault Security Audit Checklist A checklist built around one number, the vault's share price, and every way an attacker can bend it. Inflation attacks and donation-based price spikes remain the standard's signature failure mode, preventable with virtual shares or dead-share seeding.

Hack Watch

August totals 22 incidents, $144.1M stolen, across 16 chains. The first three weeks stayed quiet at roughly $42.6M combined, then one contract call in the final week turned August into the third-worst month of the year.

​Tectonic $75M Cronos, Aug 30, Oracle Manipulation. The attacker moved the spot price a Tectonic market trusted, then borrowed against the inflated collateral. No key leaked, no bridge failed, no access control broke. The feed alone moved $75 million in one call, more than the rest combined.

​Moonwell Lending $8.7M Base, Aug 27, Oracle Manipulation. An attacker donated MAMO tokens directly into the mMAMO contract, inflating the exchange rate 3.68 times without minting a share, then pushed MAMO's thin-liquidity price higher. A small deposit became $23 million of paper collateral, worth $11 million in borrows.

​Term Labs $8.5M Ethereum, Aug 23, Governance Takeover. Almost nobody had wrapped their shares into Term's governance token, so half an ETH became the majority. A proposal disguised as a routine parameter veto disabled the vault's transaction delay, then drained six vaults for $8.5 million once voting closed.

​Harmony Bridge $3.2M Harmony, Aug 11, Cross-Shard Receipt Replay. A legacy check validated spent receipts using two unauthenticated fields, not the signed header, letting a used receipt replay as new with no debit on the source shard. Forged ONE ballooned to 3.01 trillion before a rollback, losses near $3.2M.

​MayaChain $1.7M Mayachain, Aug 18, Slash Subsidy Pool Inflation. A batched deposit's final message overwrote a shared voter record, tricking theft detection into slashing an uncapped subsidy into a pool with almost no liquidity. That credited 49 million CACAO the pool never had, withdrawn before the funding transfer failed.

Oracle manipulation was the month's real story. Lending markets alone absorbed $84.5M across three hits, and Cronos absorbed more in losses than every other chain combined, entirely on the back of one incident. Track the live incident log on QuillMonitor.

If a market reads a spot price, assume someone will eventually move it. If a foundation key is hot, assume it is already gone. If quorum is cheap to buy, the treasury is the prize. This month's lesson is to audit the feed, not just the contract.

QuillAudits Stats

A quick look at our August audit activity and how we helped secure the Web3 ecosystem.

Community Highlights

QuillShield joins Sherlock Audit Engine, putting multi-agent AI review inside one of the industry's most trusted audit platforms.

$1.7B has walked out of secure multisigs in 18 months, not from broken code but from what signers didn't see, and we went live to break down exactly how.

twitter profile avatar
QuillAudits πŸ₯·
Twitter Logo
Twitter Logo
@QuillAudits_AI
The Most Expensive Click in Crypto Was a Multisig Approval https://x.com/i/broadcasts/1dKrPrdEnEOJX
link visual
x.com
QuillAudits πŸ₯·
The Most Expensive Click in Crypto Was a Multisig Approval
1:30 PM β€’ Aug 21, 2026
6
Retweets
22
Likes
​

August's losses didn't require sophistication. They required a spot price nobody defended. $1.32B already lost this year. The baseline isn't improving.

We'll see you in September. Stay paranoid. Audit everything.


Wanna partner up w/ us or want to get your project audited?

Have a great day,

Team QuillAudits

HOME
OUR AUDITS
BLOGS
SECURITY REPORTS
EVENTS

​Unsubscribe​

​Update your profile​

QuillAudits Inc

8 The Green, Ste A, in the city of Dover, County of Kent, Delaware 19901, United States


Copyright (C) 2026 QuillAudits. All rights reserved.


Your official QuillAudits update stream, covering product launches, security insights, event announcements, reports, and key developments from across the organization.


Read next ...