Back to Blog

Smart Contracts

9 articles on this topic.

Web3 Security28 September 2026

Payy Network's Ethereum bridge drained of $1.83M USDC: what is confirmed

Payy says its Ethereum bridge contract was drained of its full balance and that the cause was not a compromised key, social engineering or its off-chain infrastructure. The root cause is still undisclosed, so here is what the public record supports and what bridge teams should check.

web3bridge-securitysmart-contracts
3 min readRead
DeFi & Smart-Contract Security2 September 2026

Cronos Halts Its Own Chain After $75M Tectonic Oracle Exploit

An attacker pumped a thinly-traded governance token 100x in 20 minutes and used it as inflated collateral to drain Cronos's largest lending market — forcing validators to freeze the entire chain.

defi-securityoracle-manipulationsmart-contracts
4 min readRead
Web3 & DeFi Security1 September 2026

Cronos Halts Its Entire Chain to Reverse a $75M Tectonic Exploit

An attacker pumped Tectonic's governance token 100x in 20 minutes to borrow against phantom collateral. Cronos validators froze the whole chain and rolled it back to claw the funds back — trading decentralization for recovery.

defiweb3-securitysmart-contracts
4 min readRead
Web3 & Smart Contract Security30 August 2026

Rain Contract Bug Drains $1.1M From 'Self-Custodial' Crypto Cards

An outdated Solana smart contract at payments processor Rain let an attacker seize admin control of card-collateral accounts, draining funds from Avici and Tria customers who believed their crypto stayed under their own control.

web3-securitysmart-contractssolana
4 min readRead
Web3 & DeFi Security29 August 2026

Moonwell's Fourth Exploit in a Year: $8.7M Lost to a MAMO Price Manipulation

An attacker pumped an illiquid collateral token and borrowed against the inflated price — no smart contract bug required. It's Moonwell's fourth loss event in under a year.

defi-securityweb3price-manipulation
4 min readRead
DeFi & Smart Contract Security26 August 2026

Term Finance's $8.5M Governance Takeover: When a Timelock Doesn't Trigger

An attacker bought up Term Finance's thinly-held governance token and voted itself control of the protocol's vaults, draining roughly 68% of assets — with the on-paper timelock and veto safeguards never firing.

defi-securitygovernance-attacksmart-contracts
4 min readRead
Web3 & Smart Contract Security22 July 2026

Wanchain Bridge Exploit Drains $9M in NIGHT Tokens: A Signature-Reuse Lesson

A flawed message-encoding scheme in Wanchain's Cardano–BNB bridge let an attacker reuse a legitimate signature to drain 515 million NIGHT tokens — a reminder that bridge validators, not the chains they connect, remain the weakest link.

bridge securityweb3cardano
4 min readRead
Web3 & Bridge Security20 July 2026

Across Protocol's Solana Bridge Hit for $3.35M — Relayer, Not Users, Took the Loss

A July 17 attack on Across Protocol's Solana deployment drained roughly $3.35 million from the project's own relayer, not from bridge users — a result that says as much about bridge architecture as it does about the exploit itself.

web3bridge-securitysolana
4 min readRead
Web3 / Smart Contract Security1 July 2026

Aztec Connect: $2.1M Stolen From a Bridge With No One Left to Fix It

A proof-verification flaw let an attacker drain a DeFi privacy bridge that Aztec Labs deprecated three years ago and can no longer patch, pause, or upgrade — a case study in what "immutable" really costs.

defi-securitysmart-contractsweb3
4 min readRead