DeFi Risk & Exploits

41 stories
Incident Analysis reconstructs failures across the industry; this category is specific to DeFi attack paths, smart-contract flaws, oracle manipulation, governance exploits, economic attacks, and protocol loss exposure. Articles in DeFi Risk & Exploits examine smart contract exploit risk, DeFi oracle manipulation, and flash loan attacks. Relevant work examines protocol insolvency risk, liquidity pool exploits, and admin key exposure; DeFi bridge vulnerabilities and economic attack vectors help establish the outcome. The account reconstructs sequence, cause, impact, response, and recovery through protocol incident losses, exploit response measures, and oracle manipulation attacks.

Blockstream Rejects $50 Million Bounty After Liquid Network Exploit

Blockstream has refused a $50 million bounty demand from the Liquid attacker, recovering most of the stolen Bitcoin but leaving nearly 600 BTC missing and the network's peg suspended.

Read more

Gate Trenches and DEXs Force Users to Choose Between Control and Convenience

Gate Trenches lets exchange users trade onchain with fewer wallet steps, while DEXs offer self-custody and direct liquidity access. Both options carry slippage, contract, and network risks that users must weigh before moving assets.

Read more

Arbitrum Watchdog Targets Three DeFi Projects With Potential DAO Ban

Good Entry, Limitless, and APX Finance face possible exclusion from Arbitrum DAO programs after failing to address high-severity misuse findings. The watchdog committee has set a tentative September 10 deadline for responses and fund recovery.

Read more

Moonwell Bad Debt Plan Cuts Interest but USDC Withdrawals Still Frozen

Moonwell's new proposal could sharply reduce interest on bad debt, but users with USDC deposits remain unable to withdraw funds as the protocol weighs further risk and recovery steps

Read more

Aave V4 Proposal Arms Risk Stewards With One Way Emergency Freeze

Aave DAO is voting on a plan to let Risk Stewards freeze markets instantly in emergencies but not unfreeze them without further approval, raising new questions about protocol control and accountability for users and developers

Read more

Firo Hard Fork Forces Urgent Node Upgrade After Inflation Flaw

Firo node operators and service providers have only hours to upgrade before a critical hard fork disables older software and patches a flaw that could allow unlimited token creation through Spark transactions

Read more

Stolen Coldcard Bitcoin Moves to Ethereum in $1.6M Cross-Chain Shift

A stash of 20.5 BTC linked to the 2026 Coldcard hardware wallet theft has been swapped into Ethereum using THORChain, turning a dormant case into an active cross-chain investigation with new on-chain evidence and security implications

Read more

TAC Blockchain Standoff: $1B Token Rescue Faces Unresolved Exploit Fallout

The TAC network remains halted after a critical exploit drained nearly 30% of its token supply. A $1.26 billion TAC treasury bailout is planned, but over 1.6 billion attacker-held tokens on BNB Chain remain in limbo.

Read more

Switchboard Oracle Incident Freezes DeFi Vaults on Multiple Networks

A suspected compromise of Switchboard's Move-based oracles led to halted deployments on Aptos, Sui, IOTA, and Movement, triggering liquidations, vault freezes, and user fund restrictions across several DeFi protocols

Read more

Cronos Blockchain Paused After $75M Tectonic Lending Exploit

Cronos halted its blockchain after a major exploit drained $75 million from the Tectonic lending protocol, leaving most stolen funds stranded on-chain and raising urgent questions about protocol risk and user recovery

Read more

DeFi Lenders Tectonic and Moonwell Hit by $83M Price Manipulation Attacks

Two decentralized lending protocols, Tectonic and Moonwell, suffered over $83 million in losses after attackers exploited thinly traded tokens to inflate collateral values and drain liquid assets

Read more

MANTRA Chain Restarts After Halt, But Code Changes Raise Questions

MANTRA Chain resumed mainnet block production after a six-day outage, but the lack of a public postmortem and silent code changes have left developers and node operators seeking answers about the incident's root cause and mitigation.

Read more

Term Finance Hit by $8.5M Exploit After Governance Takeover

Term Finance suffered an $8.5 million loss after an attacker gained control of its Meta Vaults through a governance exploit, draining nearly all ETH deposits and forcing the protocol to shut down affected products

Read more

Moonwell Leaves $1.8M cbETH Liquidity Gap Unaddressed in New Plan

Moonwell's latest reserve allocation leaves a $1.77 million cbETH shortfall unresolved, keeping liquidity negative and preventing suppliers from withdrawing funds as the protocol faces ongoing fallout from a February oracle error

Read more

StandX DEX Launches Yield-Bearing DUSD Stablecoin With On-Chain Risks

StandX introduces a decentralized perpetual exchange and DUSD, a stablecoin that shares protocol revenue with holders. The platform promises noncustodial leveraged trading but exposes users to smart contract, liquidity, and peg risks.

Read more

BounceBit Chain Shutdown Leaves BB Token Utility in Limbo

BounceBit is shutting down its Layer 1 blockchain after a protocol flaw moved 286.5 million BB tokens, forcing a 1:1 reissue on BNB Chain and leaving the token's future utility and network roles uncertain

Read more

MANTRA Chain Mainnet Remains Offline as Patch Testing Delays Restart

MANTRA Chain's mainnet is still paused after an exploit targeting a software dependency. Transactions, transfers, and staking are halted while a patched release undergoes testnet validation before a coordinated restart.

Read more

Shade Protocol Burn Deadline Forces Holders to Choose Irreversible Loss

Shade Protocol users must decide by 18:00 UTC on Aug. 21 whether to permanently burn SHD tokens for a chance at a future Feather allocation, with no guarantee of value or terms as the project winds down its Secret Network applications

Read more

Ethereum's EIP-7702 Wallet Upgrade Exposes Millions to Attacks

A peer-reviewed study found that 63% of early EIP-7702 wallet authorizations were linked to attacker-controlled contracts, exposing millions in user assets and highlighting new risks for Ethereum and compatible chains

Read more

Ethereum Developers Weigh Encryption to Block Trading Bots

Ethereum is considering encrypting its public mempool to shield pending trades from predatory bots, aiming to curb sandwich attacks while preserving open access for users and builders.

Read more

Solana's Alpenglow Bug Bounty Requires 0.5 SOL Upfront Fee

Security researchers must pay a non-refundable 0.5 SOL fee to submit bug reports for Solana's new Alpenglow consensus protocol, with eligibility and rewards determined only after submission and review

Read more

21Shares Ethereum ETF Faces $48M Redemptions With Most ETH Still Locked

The 21Shares Ethereum ETF processed $48 million in redemptions in early 2026, but kept over 86% of its ETH staked, raising questions about liquidity and redemption timing for investors as market volatility persists

Read more

Crypto Liquidation Data Gaps Expose Risks in Solana, Binance Crash

Conflicting reports on October's crypto crash reveal major gaps in liquidation data, with billions in losses and unclear risk mechanisms across Solana, Binance, and DeFi platforms. Regulators face challenges in tracking systemic failures and user impact.

Read more

Study Links 65,000 Crypto Addresses to $574 Million in Losses

A new security study has identified tens of thousands of Ethereum and BNB Smart Chain addresses tied to risky activity, revealing how contract and key misuse have led to hundreds of millions in lost funds

Read more

Tron Inc. Faces Major Risk as 91% of Assets Locked in JustLend

Tron Inc. has staked nearly all of its TRX treasury through JustLend, leaving over 90% of its assets uninsured and exposed to protocol and smart-contract risks as its holdings continue to grow

Read more

Harmony Considers Blockchain Rollback After Billions in ONE Minted Illegally

Harmony has halted further unauthorized minting of its ONE token after a protocol flaw allowed billions to be created and sent to exchanges, but the fate of the excess supply and possible transaction rollback remains unresolved

Read more

Drift Protocol Attack Exposes Limits of Multisig Wallet Security

Multisig wallets are designed to prevent single-point failures, but the $285M Drift Protocol exploit shows that valid signatures alone can't stop social engineering or malicious transactions when thresholds are low and oversight is weak

Read more

Crypto Audit Badges Fail to Protect Investors From Major Security Risks

Crypto platforms often display 'audited' badges as a sign of safety, but recent billion-dollar losses reveal these labels can mislead users about the true scope of security protections

Read more

Wall Street's $7B Tokenized Funds See Minimal DeFi Adoption

Despite Wall Street pouring billions into tokenized funds, less than 1% of these assets are actively used in DeFi protocols, raising questions about composability, security, and the future of real-world asset integration

Read more

Bybit Hack Shows Why Stolen Crypto Is So Hard to Recover

A $1.5 billion crypto theft tied to North Korea highlights the limits of legal action and blockchain transparency, as most stolen funds vanish before courts can intervene and only a fraction is ever frozen or recovered

Read more

Page 1 of 2