Chainlink2026-09-28 12:30:59Chainlink rolls out CCIP 2.0 after rival bridge hack exposed single-verifier riskChainlink on Monday released CCIP 2.0, a new version of its Cross-Chain Interoperability Protocol that lets companies add their own verification checks to cross-chain transfers on top of Chainlink’s default 16-operator network. The upgrade arrives months after the April attack on Kelp DAO’s bridge, in which about $292 million in rsETH was drained after a LayerZero-based setup that relied on a single verifier was allegedly tricked. Kelp later said it would move rsETH to Chainlink. The update expands the menu of verifier options available to users. Companies can run their own verifiers or hire outside providers including Infosys and Nethermind, while Chainlink’s own node-operator network continues to check every transfer. At the same time, the release changes how Chainlink’s Risk Management Network works. That separate set of nodes no longer acts as an independent backstop, meaning users who do not add optional verifiers appear to depend on one verification network rather than the two-layer design Chainlink previously promoted. Chainlink said existing users were automatically migrated, and added that Aave and Maple have begun adopting some of the upgrade’s other features, though it did not name any institution using the new verifier model yet.210
Symbiosis2026-09-15 13:43:50Symbiosis bridge exploit let attacker mint 46.1 billion unbacked syBTC from a 330-satoshi depositSymbiosis said two software flaws in its Bitcoin Bridge let an attacker use a 330-satoshi bitcoin deposit, worth about $0.25, to generate roughly 46.1 billion unbacked syBTC through 12 bogus deposits. According to the project’s post-mortem and blockchain data reviewed by CoinDesk, the attack unfolded across BNB Chain, Ethereum and Rootstock in about four minutes. One bug let the attacker obtain administrator privileges by exploiting how the bridge identified the sender of a bitcoin transaction. A second bug treated a negative fee as an addition, allowing the deposit amount to be inflated to essentially any number the attacker entered. Despite the huge token count, Symbiosis put preliminary losses at 9.97 BTC, or about $770,000, because unbacked bridge tokens do not create the real assets needed for redemption. The project said syBTC supply had been only 13.91 before the attack, with 11.26 syBTC in pools paired with WBTC, cbBTC, BTCB and RBTC. Symbiosis has taken the native Bitcoin Bridge offline, said it will rewrite the bitcoin-side software, commission an independent audit and compensate affected users and liquidity providers.700
Symbiosis2026-09-14 09:55:35Symbiosis says it recovered 15 BTC after bridge exploit and is offering a 20% bountyCross-chain liquidity protocol Symbiosis said it has recovered 15 BTC, worth about $1.1 million, after an exploit hit its native Bitcoin bridge on Friday. The recovered Bitcoin has been moved to a team-controlled multisig wallet, while the protocol said all routes remain operational except for the native Bitcoin bridge, which is still paused. Blockchain security firm Blockaid said the attacker minted 46.1 billion unbacked tokens through the bridge and ultimately realized net proceeds of 4.3 WBTC, or about $336,000. Symbiosis has not explained how the recovered 15 BTC relates to that figure. The protocol is now offering a 20% bounty to anyone whose information leads to asset recovery, after an earlier 20% white-hat offer to the attacker expired on Sunday. Symbiosis also said it will disclose a compensation framework for affected liquidity providers. DeFiLlama has estimated losses at roughly $336,000, though the protocol has yet to publish a final accounting. The incident adds to a recent run of bridge-related exploits, including the Secret Network and Verus-Ethereum cases earlier this year.840
Term Labs2026-09-03 09:03:13Term Labs Restores Fixed-Rate Loan Positions Affected by $8.5M Governance AttackTerm Labs has fully restored all fixed-rate loan positions affected by an August governance attack, with the final transfer completed on August 25. The attack caused approximately $8.5 million in losses. A community-approved recovery plan ensured all affected users were compensated. Meta Vaults and related strategies remain closed, as reported by Crypto.news.810
Tectonic2026-08-31 03:01:10Tectonic hit by TONIC price manipulation attack, losses estimated at about $74 millionCronos-based lending protocol Tectonic was hit by an attack on Aug. 30 in which an exploiter allegedly used thin TONIC liquidity to push the token’s price up by about 100x in roughly 20 minutes, then used the inflated collateral value to borrow more liquid assets from the protocol. Researcher Weilin Li initially traced about $66 million tied to the exploit, including roughly $6 million bridged to Ethereum and about $60 million left in three Cronos addresses, before identifying another attacker-linked address holding about $8 million. PeckShield later estimated total losses at around $74 million. Cronos halted block production after confirming a vulnerability affecting Tectonic, while the protocol told users to stop interacting with it. Crypto.com CEO Kris Marszalek said the Crypto.com app and exchange were not affected and that the company’s security team was helping with the investigation. Before the incident, Tectonic was the largest lending protocol on Cronos by total value locked. DefiLlama data cited in the report showed about $120 million in TVL and roughly $82.7 million in active loans before the attack; by Aug. 31, TVL had dropped to below $3 million. The report compares the incident with the MAMO market exploit on Moonwell on Aug. 27 and the 2022 Mango Markets case, both of which involved low-liquidity token price inflation feeding into borrowing power through protocol pricing systems.980
Cronos2026-08-31 03:00:09Cronos, Fogo and Cosmos EVM Chains Turned to Shutdowns as Last-Resort Crisis ResponseThree separate incidents across Cronos, Fogo, and chains using the Cosmos EVM module ended with the same emergency measure: stop the chain. On Aug. 30, Cronos validators froze the network after an attacker allegedly manipulated TONIC, a thinly traded governance token tied to the Tectonic lending protocol, and used inflated collateral to borrow about $75 million in assets such as cbBTC, USDC, and WETH. According to on-chain researcher Weilin Li, the attacker held about 364.6 trillion TONIC, and the math implied a post-manipulation collateral value of roughly $375 million. Validators halted the chain before most of the funds could leave; around $6 million was bridged to Ethereum, while about $60 million remained stuck on Cronos. Fogo followed a different path. The Fogo Foundation said on Aug. 29 at 9:13 PM ET that an unknown attacker had "compromised" the foundation and transferred 400 million FOGO tokens. The foundation initially said the blockchain itself was unaffected and kept running, but about 15 hours later the mainnet was paused so validators could upgrade the network to "restrict addresses associated with unauthorized activity." The stolen amount represented 4% of the 10 billion genesis supply and more than 10% of circulating supply. Cosmos EVM exposed a supply-chain problem rather than a single-chain failure. Cosmos Labs said a bug in the shared open-source module affected all chains running it, and on Aug. 24 urged validators to halt if they could not immediately coordinate a state-breaking upgrade. The incidents landed differently in the market, but together they showed how quickly decentralization debates return when validator coordination becomes the final line of defense.1070
Moonwell2026-08-27 13:09:03Moonwell probes Base MAMO Core Market exploit with estimated losses of about $8.7 millionDecentralized lending protocol Moonwell is investigating a security incident affecting the MAMO Core Market on Base after blockchain security firms flagged what they described as a multi-million-dollar exploit. CertiK and PeckShield estimated losses at roughly $8.7 million, while Moonwell said it had imposed emergency limits across Base Core Markets as a precaution. According to Moonwell’s statement on X, all borrowing caps for Core Markets on Base have been set to 1 wei. The protocol also reduced the supply caps for MAMO and WELL to 1 wei. PeckShield said the attacker consolidated the stolen funds into an address holding the DAI stablecoin. CertiK said the exploit involved manipulation of the collateral price for the low-liquidity MAMO token, after which the attacker borrowed real cbBTC from the mCBTC market. Blockaid identified the same attack pattern. Following the incident, WELL fell about 13% over 24 hours and MAMO dropped about 9%. The report also placed the case within a broader wave of DeFi exploits since April, a period in which more than $600 million has been stolen across protocols, with the largest single incident cited as Kelp DAO’s $292 million exploit.950
Term Finance2026-08-25 19:32:36Term Finance Permanently Shuts Meta Vaults After Governance Attack, Keeps Withdrawals OpenTerm Labs, the team behind fixed-rate lending protocol Term Finance, said all Term Meta Vaults have been permanently shut following a governance attack, while withdrawal access remains available. In an Aug. 23 update, the team said the shutdown is irreversible and future deposits have been blocked for good. It did not disclose how much remains in the vaults and said only that it would "explore paths" to address any shortfall, leaving the amount depositors may ultimately recover unresolved. Blockchain security firm PeckShield estimated that the attacker stole about 2,843 ETH, worth roughly $6.87 million at the time, along with 1.68 million USDC later swapped into about 1.68 million DAI, bringing total losses to about $8.5 million. On-chain records show transfers of 2,841.74 WETH and 1.68 million USDC to addresses labeled by Etherscan as "Term Finance Exploiter 1" and "Term Finance Exploiter 2." Yearn said the affected vault contract used its V3 architecture, but the exploit targeted a custom governance wrapper built by Term rather than a standard Yearn vault. Term added that its underlying protocol and direct lending markets have not been affected based on the current investigation.940