From the lab

Research

For every major 2026 exploit: the root cause, the attack path, and the exact layer that would have caught it. The pattern is consistent where it counts: most incidents are contract bugs, but most of the money is lost outside the contracts — in keys, configuration, build pipelines and the frontend.

Bridge / config · Apr 2026 · $292M · rsETH omnichain bridge

Kelp DAO — $292M — the bridge was audited and clean

Kelp's rsETH omnichain bridge ran on LayerZero, and its contracts had been audited. By every account the code was clean — LayerZero itself later confirmed the contracts “operated exactly as designed.” The problem was never the code.

The bridge shipped with a single-verifier configuration — a 1-of-1 DVN, one attestation source with no redundancy. Attackers compromised the RPC nodes that single verifier relied on and DDoS'd the backups, then injected a forged cross-chain message attesting a deposit that never happened. The lone verifier signed it, and the destination contract released 116,500 rsETH from escrow. It cascaded into roughly $177–190M of bad debt downstream.

This is the defining pattern of 2026: a clean, audited contract, undone by a configuration choice a contracts-only audit doesn't treat as in-scope.

What the audit covered vs. where it broke

Vari's cross-chain layer checks the verifier / DVN threshold as a first-class item — a 1-of-1 configuration is a high-severity single-point-of-failure finding we raise before an attacker finds it. Config is in scope, not just code.

Keys / social engineering · Apr 2026 · $285M · Solana

Drift Protocol — $285M — the attackers never touched the contracts

Drift had been audited by multiple well-known firms. The attackers didn't bother with the contracts. Over roughly six months they socially engineered contributors and captured two of five multisig signers.

Using Solana durable-nonce accounts, they pre-signed admin transactions that stayed valid indefinitely, moved admin control to their own wallet, stood up a fake market with an attacker-controlled oracle, disabled the circuit breakers, and drained 15+ assets in about ten seconds.

The code was fine. The operational configuration — a 2-of-5 threshold with no timelock on admin transfers — is what made two compromised signatures fatal.

What the audit covered vs. where it broke

Vari's live on-chain verification reads the deployed multisig threshold and timelock; a 2-of-5 with no timelock is a high-severity centralization finding, and the operational scorecard mandates hardware-key signing and signer separation. We can't stop a phish — but we flag the config that turns one into a $285M loss.

Oracle / listing config · Mar 2026 · ~$3.7M · BNB Chain

Venus / THENA — correct code, exploited listing

Venus is a heavily audited, Compound-lineage lending protocol. Every unit test passed. The exploit lived in the parameters of a single listed market, not in a broken function.

The attacker donated tokens directly to the vToken to inflate its exchange rate and slip past the market's supply cap, then looped deposits and borrows to push a thin-liquidity oracle price roughly 18× — over-borrowing against collateral that was only briefly worth what the oracle claimed.

Listing a thin-liquidity token with a manipulable price feed, plus a known donation-attack vector, is a configuration and parameter failure — precisely the kind of exploit that passes every code test.

What the audit covered vs. where it broke

Vari's deployment-and-config layer reviews listing parameters as deployed — oracle source and liquidity depth, supply caps, donation-vector exposure on new vTokens — before the market is ever listed.

Frontend / dApp · Feb 2025 · $1.4B–$1.5B · Ethereum

Bybit — $1.4B–$1.5B — the contracts were never touched

Nothing was wrong with Bybit's or Safe's smart contracts. A Safe{Wallet} developer's machine was compromised, and malicious JavaScript was injected into the public Safe{Wallet} UI bundle (_app-52c9031bfa03da47.js), scoped to trigger only for Bybit's cold-wallet signers. The injected code performed a bait-and-switch: it substituted the transaction payload presented for signing, harvested valid signatures on the tampered payload, then restored the original display data.

Attackers (attributed to DPRK-linked Lazarus by the FBI and multiple forensic firms) compromised a Safe{Wallet} developer workstation and pushed tampered frontend JS to Safe's AWS S3-hosted UI. When Bybit's multisig signers approved what looked like a routine ETH transfer from the cold wallet, they in fact signed an execTransaction call with operation=1 (delegatecall) to attacker contract 0x9622...7242. That delegatecall overwrote storage slot 0 of the Gnosis Safe proxy (0x1Db9...FCF4), repointing its implementation at attacker-controlled logic, which was then used to sweep the wallet.

What the audit covered vs. where it broke

Only a frontend/dApp review — integrity of the served JS bundle, build-and-deploy pipeline controls, and signer-side blind-signing/clear-signing verification — would have caught this; a contract audit of either Safe or Bybit would have found nothing, because both contracts behaved exactly as written.

Primary source ↗
Deployment / config · Jul 2026 · $116M–$130M+ · Bitcoin

Coldcard / Coinkite — $116M–$130M+ — a build-config default, not a code bug

A build-configuration and symbol-resolution defect, not a cryptographic design flaw. In the March 2021 migration to Bitcoin Core's libsecp256k1 (via libNgU), seed generation switched from ckcc.rng_bytes() to ngu.random.bytes(); the rng_get() symbol was defined in both the board's hardware TRNG and MicroPython's software fallback, and the linker resolved to the software Yasmarang PRNG. The developer had set MICROPY_HW_ENABLE_RNG=0 to disable the software path, but the preprocessor guard used #ifndef rather than testing for a nonzero value, so the guard never fired and the fallback stayed in the binary.

Any seed generated on affected firmware had drastically reduced entropy — Coinkite puts Mk2/Mk3 on firmware 4.0.1–4.1.9 at roughly a 40-bit effective search space and Mk4/Mk5/Q at ~72 bits. Attackers brute-forced the reduced keyspace entirely offline, with no access to the devices, then swept the resulting addresses. TRM recorded a first wave of ~594 BTC (~$38M) from ~500 wallets consolidated into a single address within 25 minutes on 30 July 2026, followed by three further waves over four days. Galaxy Research assessed that at least a dozen independent attackers were involved — inferred from divergent transaction construction and unsophisticated laundering, not confirmed by any single actor.

What the audit covered vs. where it broke

A deployment/configuration and build-integrity review — checking that the shipped binary actually links the hardware RNG and that compile-time feature flags take effect — is the only layer that finds this; there is no smart contract here at all, and even a source-level review of the intended code would have looked correct.

Primary source ↗
Contracts · Nov 2025 · $120M–$128M · Multi-chain

Balancer V2 — $120M–$128M — a genuine contract bug

A genuine smart-contract math bug. The _upscale function calls FixedPoint.mulDown(amount, scalingFactor), which divides by 1e18 and always rounds down. ComposableStablePool (added September 2021) overrode _scalingFactors to fold in a token exchange rate, making scaling factors non-unitary — precisely the condition the original code comment warned about ('there's no rounding error unless _scalingFactor() is overridden'). At tiny balances the truncation swallowed the whole rate adjustment: 17 × 1,058,132,408,689,971,699 / 1e18 = 17.98, truncated to 17.

The attacker first drove pool token balances down to near-dust levels (roughly ≤100k units) by repeatedly swapping BPT for the underlying WETH and osETH. They then ran repeating triplets inside batchSwap — a prime swap to position the pool, an exploit swap using minimal amounts (often 17 units against balances of 18) to maximise the truncation loss, and a reset swap to restore balances — exploiting batchSwap's transient balance accounting to effectively borrow BPT within a batch before settlement. The cycle was repeated across ComposableStablePool and LinearPool instances on multiple chains.

What the audit covered vs. where it broke

This one a contract audit should have caught, and honestly did not — the contracts had been audited repeatedly and had run for roughly four years; catching it required fixed-point precision analysis or invariant/formal verification of the rounding behaviour under the overridden scaling factor, not infrastructure review.

Primary source ↗
Keys / social engineering · Jun 2026 · $31M–$36M · Ethereum and BNB Smart Chain

Humanity Protocol — $31M–$36M — the keys, not the code

Seven private keys — one hot wallet key plus two sets of three Safe multisig keys — were stolen from a developer's machine. The protocol attributed their presence on that device to an accidental backup left over from the mainnet launch, with malware later obtaining root access. Possession of a full Safe quorum meant the attacker inherited the protocol's upgrade authority outright.

The attacker drained 6,045,060 H from the compromised hot wallet, then used the Safe keys to push a malicious bridge contract upgrade that drained roughly 141 million H on Ethereum. On BSC they used the inherited admin control to mint 300 million unauthorised H. Around 447 million H total was stolen or minted and largely swapped to ETH on DEXs. Note the dispute: the protocol says accidental backup, while on-chain investigator ZachXBT publicly argued it was an inside job — that remains an analyst allegation, not an established finding.

Reported figures differ between sources — the range above reflects that, not a single confirmed number.

What the audit covered vs. where it broke

A key-management and operational review — where launch-time keys live, whether a single machine can reconstitute a multisig quorum, and hardware isolation of signers — is the only layer that reaches this; the bridge contract's upgrade mechanism worked exactly as designed for whoever held the keys.

Primary source ↗
Keys / social engineering · Jan 2026 · $27M–$30M · Solana

Step Finance — $27M–$30M — the keys, not the code

The team confirmed that attackers gained access to the devices of the project's executive team, giving them control of treasury signing authority. The exact mechanism — whether private keys were exfiltrated outright or malware corrupted the transaction-approval flow on those machines — was not publicly established beyond that.

With executive device access the attacker unstaked approximately 261,854 SOL from the protocol treasury and transferred it out of the compromised wallets, together with other treasury assets. STEP collapsed over 80% and, after roughly three weeks of attempted recovery, the team wound down Step Finance and its associated Solana platforms.

What the audit covered vs. where it broke

Key management and endpoint/operational security — treasury signer hygiene, hardware isolation, and spend limits or timelocks on treasury movements; a contract audit was irrelevant here because no contract misbehaved.

Primary source ↗
Backend / API · Mar 2026 · $25M · Ethereum

Resolv Labs — $25M — the pipeline signed it, the contract obeyed

A software supply-chain and cloud-IAM failure, not a contract bug. A contractor's GitHub credential — retained from unrelated prior third-party work — was compromised upstream and used to reach Resolv's repositories. Attackers planted a malicious CI/CD workflow that exfiltrated infrastructure credentials, then modified a cloud key-management access policy to grant themselves signing authority over the off-chain minting service that authorises USR issuance.

Compromise originated at a third-party project where the contractor had contributed, then moved laterally into Resolv's GitHub. A malicious workflow exfiltrated cloud API keys; reconnaissance followed; the attacker escalated by editing the KMS key policy to obtain the minting signer. Two unauthorised mints followed — 50M USR at 02:21:35 UTC and 30M USR at 03:41 UTC — and the proceeds were swapped to ETH. Resolv detected within roughly an hour, fully paused by 05:16 UTC and completed credential revocation at 05:30 UTC.

What the audit covered vs. where it broke

A backend/API and CI/CD review — third-party credential lifecycle, workflow permissions on the repo, and who can alter cloud KMS key policies — is the only layer that surfaces this; the minting contract correctly honoured a signature from an authorised signer, so a contract audit would have passed it.

Primary source ↗
Contracts · Jan 2026 · $26.4M · Ethereum

Truebit Protocol — $26.4M — a genuine contract bug

An unchecked integer overflow in legacy code. The getPurchasePrice function of Truebit's Purchase contract computes Price = (100·A²·R + 200·A·R·S) / ((100−T)·S²). The numerator addition (v12 + v9) had no SafeMath protection, and the contract was compiled with Solidity 0.6.10, which has no built-in arithmetic checks. A sufficiently large token amount wraps the numerator to a near-zero value, driving the computed price to 0.

The attacker queried getPurchasePrice with 240,442,509,453,545,333,947,284,131 TRU and received a price of 0. They called the mint function for that amount, paying zero ETH, then immediately burned the minted TRU to redeem 5,105.069 ETH from the contract's reserves. The mint-burn cycle was repeated until the reserves were drained.

What the audit covered vs. where it broke

A contract audit would straightforwardly have caught this — unchecked arithmetic on a pre-0.8 Solidity contract is a first-pass finding; the real failure was that a long-dormant legacy contract holding real reserves was never re-reviewed.

Primary source ↗
Cross-chain · May 2026 · $11.58M · Cross-chain

Verus–Ethereum Bridge — $11.58M — the bridge never reconciled

A missing conservation-of-value check across the message boundary. Verus-side notaries validated the structure and authenticity of a transfer blob, and the Ethereum-side contract validated notary signatures and blob hash integrity — but nothing on either side verified that the input amount committed on Verus matched the payout amount claimed on Ethereum. Specifically, checkCCEValues on the Ethereum side did not enforce that inputs and outputs balanced.

The attacker submitted a transfer blob carrying roughly $0.01 of inputs on the Verus side. Notaries approved it because it was well-formed and correctly signed. The attacker then called submitImports() on Ethereum; the contract verified the signatures and hash, extracted the payout instructions without reconciling them against the inputs, and released $11.58M. A structurally similar exploit recurred in July 2026 for $7.54M.

What the audit covered vs. where it broke

This sits on the cross-chain messaging layer — the defect is in the trust boundary between two independently-correct systems — but stated honestly, a thorough audit scoped to the Ethereum-side bridge contract should have flagged that submitImports/checkCCEValues never reconciles input and output value; the failure is as much an audit-scoping failure as a layer gap.

Primary source ↗
Keys / social engineering · Feb 2026 · $4.3M–$4.4M · Cross-chain

IoTeX ioTube bridge — $4.3M–$4.4M — the keys, not the code

An employee machine was compromised in what IoTeX described as a suspected social-engineering attack, handing the attacker the upgrade authority over the ioTube bridge's Ethereum-side Validator contract. The bridge's contracts were not logically flawed; their upgradeability was simply exercised by the wrong party.

After compromising the employee's machine, the attacker upgraded the ioTube Validator contract to a malicious implementation that would approve arbitrary withdrawals. They drained roughly $4.4M of bridge reserve assets, then minted 410M CIOTX to extract further value. IoTeX detected the activity at 08:01 UTC and issued a public alert at 09:39 UTC, and confirmed that the IoTeX L1 chain and IOTX total/circulating supply were never affected.

What the audit covered vs. where it broke

Key management and deployment/upgrade governance — who holds bridge upgrade authority, whether it sits behind a multisig with a timelock, and endpoint security for the humans holding it; a contract audit would note the contract is upgradeable but would not call working upgradeability a vulnerability.

Primary source ↗
Oracle / listing config · Feb 2026 · $1.78M · Base

Moonwell — $1.78M — correct code, wrong configuration

A price-feed wiring error introduced during a governance execution. Governance proposal MIP-X43 enabled Chainlink OEV wrapper contracts, and the cbETH oracle configuration derived cbETH's USD value from the raw cbETH/ETH exchange rate alone, without multiplying by the ETH/USD feed. cbETH was consequently priced at roughly $1.12 instead of ~$2,200 — a unit-composition mistake in configuration, not in the oracle or the lending contracts.

As soon as the misconfigured feed went live, cbETH collateral in Moonwell's lending markets appeared to be worth effectively nothing. Liquidation bots — behaving exactly as designed — immediately liquidated cbETH-backed positions at the false price, taking over 1,096 cbETH within minutes. Moonwell cut cbETH supply and borrow caps to 0.01 to stop further liquidations, leaving ~$1.78M of bad debt.

What the audit covered vs. where it broke

An oracle/listing configuration review — validating each feed's units, decimals and composition against a sanity-checked reference price before the governance proposal executes; the contracts were audited and correct, and consumed the wrong number faithfully.

Primary source ↗
DNS / domain · Apr 2026 · no user-fund loss · Ethereum and CoW Protocol's suppor

CoW Swap / CoW Protocol — no user-fund loss — the domain, not the contract

DNS records for swap.cow.fi were altered so that the domain resolved to attacker infrastructure serving a phishing clone of the dApp. CoW Protocol's smart contracts were untouched and continued operating correctly throughout. The precise registrar-level entry point was not publicly established in the reporting available; comparable 2026 incidents have been traced to registrar 2FA bypass, but that has not been confirmed for CoW Swap.

Attackers redirected the swap.cow.fi domain to a malicious site designed to harvest token approvals and drain connected wallets. The CoW team paused the backend and APIs as a precaution and told users who had interacted with the frontend after 14:54 UTC to revoke approvals immediately; Aave separately disabled CoW Swap endpoints for its integrators. As of the reporting reviewed, CoW DAO had not published a full post-mortem.

What the audit covered vs. where it broke

DNS/domain layer only — registrar lock, DNSSEC, registrar account MFA and out-of-band monitoring for record changes; no amount of contract auditing touches the domain that users actually type.

Primary source ↗

More breakdowns are published as they happen.

Get a fixed quote

Want your stack reviewed?

Contracts, config, cross-chain, frontend, backend and DNS — one review, ranked by exploitability, 1–3 days. From $2,500. Fixed quote within 24 hours, free.