Back to Blog

Defi Security

10 articles on this topic.

DeFi & Web3 Security12 September 2026

Cozy Finance Drained Again: $170K Lost to a UMA Oracle Manipulation

A false, unchallenged assertion to Cozy Finance's UMA Optimistic Oracle integration triggered a payout an attacker then drained in minutes — the DeFi insurer's second Optimism loss in just over a year.

defi-securityoracle-manipulationuma-protocol
4 min readRead
DeFi & Blockchain Security6 September 2026

Blockstream Halts Liquid Network After $320M Exits via a 'Whitehat' Claim

A withdrawal equal to roughly 95% of Liquid Network's bitcoin reserves moved through a peg-out authorization key that Blockstream says was never compromised — a gap that matters more than the on-chain "whitehat" message left behind.

defi-securitybitcoin-sidechainliquid-network
4 min readRead
DeFi & Smart-Contract Security2 September 2026

Cronos Halts Its Own Chain After $75M Tectonic Oracle Exploit

An attacker pumped a thinly-traded governance token 100x in 20 minutes and used it as inflated collateral to drain Cronos's largest lending market — forcing validators to freeze the entire chain.

defi-securityoracle-manipulationsmart-contracts
4 min readRead
Web3 & DeFi Security29 August 2026

Moonwell's Fourth Exploit in a Year: $8.7M Lost to a MAMO Price Manipulation

An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.

defi-securityweb3price-manipulation
4 min readRead
DeFi & Smart Contract Security26 August 2026

Term Finance's $8.5M Governance Takeover: When a Timelock Doesn't Trigger

An attacker bought up Term Finance's thinly-held governance token and voted itself control of the protocol's vaults, draining roughly 68% of assets — with the on-paper timelock and veto safeguards never firing.

defi-securitygovernance-attacksmart-contracts
4 min readRead
DeFi & Smart Contract Security21 July 2026

Allbridge Core Loses $1.65M to a Flash Loan Pricing Bug It Fixed in 2023

A flash loan against Allbridge Core's Solana stablecoin pools distorted internal pricing and let an attacker drain roughly $1.65 million — the same class of bug the protocol says it patched on BNB Chain three years ago.

defi-securityflash-loanweb3
3 min readRead
DeFi & Smart-Contract Security19 July 2026

Summer Finance's $6M Vault Accounting Bug Ends in Full Shutdown

A flash-loan attacker exploited how Summer Finance's Fleet Commander vault priced its underlying strategies, extracting $6 million in a single transaction — and the protocol has now wound down entirely.

defi-securityflash-loan-attacksmart-contract-security
4 min readRead
Web3 & DeFi Security11 July 2026

Summer.fi's $6M Vault Exploit Is a Playbook for Donation-Based Share Manipulation

A three-month-old attacker wallet used a $65M flash loan and a donation to a strategy adapter pending removal to skew vault share pricing, draining $6.04M from two Lazy Summer USDC vaults before guardians could react.

defi-securityflash-loan-attacksmart-contract-exploit
5 min readRead
Web3 / Smart Contract Security1 July 2026

Aztec Connect: $2.1M Stolen From a Bridge With No One Left to Fix It

A proof-verification flaw let an attacker drain a DeFi privacy bridge that Aztec Labs deprecated three years ago and can no longer patch, pause, or upgrade — a case study in what "immutable" really costs.

defi-securitysmart-contractsweb3
4 min readRead
Web3 & DeFi Security29 June 2026

Secret Network–Axelar Bridge Drained $4.67 M via Infinite-Mint Bug Hidden for Seven Days

An attacker exploited a removed source-validation check to mint unbacked wrapped tokens on Secret Network, redeeming them through Axelar's legitimate channel — and nobody noticed for a week.

secret-networkaxelarbridge-exploit
4 min readRead