SODA

DeFi
2026-09-14 09:03:21

Study Says Most Losses in Audited DeFi Incidents Came From Attack Paths Outside Audit Scope

A new preprint paper by researchers affiliated with security firm ack3 and the Czech Technical University in Prague argues that the “audited” label in decentralized finance often says far less than users assume. The study reviewed 135 security incidents reported in the first half of 2026, representing $939.86 million in losses, and identified 68 cases with publicly traceable pre-incident audit records. Within that audited subset, 46 attack paths were classified as falling completely outside any verifiable audit scope, 20 were covered by at least one audit, and two could not be determined. Those out-of-scope incidents accounted for 67.6% of the 68 audited cases by count, but $680.97 million out of $721.24 million by losses, or 94.4%. The paper stresses that this does not measure whether audits are effective, nor does it prove that scope limitations directly caused the losses. The distribution is heavily influenced by two large incidents, Kelp DAO and Drift Protocol. Removing those two brings the out-of-scope loss share down to 72.1%. The paper also uses the August incidents involving ICON Network and aelf to show why a project being audited does not mean its deployed system, operational controls, upgrade paths, runtime environment, or emergency response procedures have all been reviewed. Its broader point is narrow but important: an audit record and actual audit coverage are different things, and users need versioned, time-stamped security records rather than a generic audit badge.

850
Study Says Most Losses in Audited DeFi Incidents Came From Attack Paths Outside Audit Scope
Policy and Re
2026-09-06 00:41:17

Cronos, Ontology and ICON halted block production in four days, exposing very different emergency powers

Three blockchain networks — Cronos, Ontology and ICON — stopped producing blocks within four days, but the powers used in each response were not the same. Cronos said validators coordinated an emergency rollback after the Tectonic exploit and restarted the chain from block 90,896,189, wiping out all state changes and transactions after the chosen restore point. Ontology took a preventive route instead, pausing block production before confirming malicious activity and later saying no user assets were lost. ICON followed a third path: it first paused the affected contract and then shut down the network, but by then much of the stolen ICX had already moved into exchange custody. The three incidents put the same set of questions under a spotlight: who can order a chain halt, who can alter confirmed state, what remains recoverable once assets move across chains or into centralized custodians, and who ultimately bears losses when onchain controls no longer apply. The comparison also shows that a network restart does not automatically mean dependent infrastructure, bridges, explorers and RPC services are fully back online.

830
Cronos, Ontology and ICON halted block production in four days, exposing very different emergency powers
Cronos
2026-09-02 07:33:39

Three chain shutdowns in four days show the hard limits of on-chain emergency powers

Three public blockchains halted block production within four days, but the emergency powers used in each case were not the same. Cronos responded to the Tectonic exploit by restoring the network to a pre-attack state and resuming from block height 90,896,189, effectively voiding all transactions and state changes after that checkpoint. Ontology took a preventive route, pausing block production before confirming malicious activity and later saying no user assets were lost. ICON suspended the affected contract first and then shut down the network, but by that point the foundation said most of the stolen ICX had already moved into exchange custody. Taken together, the three incidents show that a chain halt is only the first layer of control. The more important questions are who can trigger an emergency response, whether confirmed chain history can be rewritten, and what happens once funds move across chains or into centralized custodians. In Cronos’ case, rollback power only applied to assets that remained on-chain. In ICON’s case, on-chain controls arrived after the assets had largely left the chain’s sphere of control. Ontology, by contrast, used downtime to buy time for inspection, patching, and testing rather than to reverse settled transactions.

340
Three chain shutdowns in four days show the hard limits of on-chain emergency powers
Cronos
2026-09-02 07:17:09

Cronos, Ontology and ICON took three very different paths in emergency shutdowns

Three blockchain networks — Cronos, Ontology and ICON — halted block production within four days, but their emergency responses exposed sharply different governance powers and recovery limits. Cronos rolled its chain state back to before the Tectonic exploit and resumed production from block 90,896,189, wiping out all transactions and state changes after that checkpoint. Ontology paused block production before confirming malicious activity, kept confirmed state intact, and said no user assets were lost. ICON, by contrast, halted contracts and then the network only after most of the affected ICX had already moved into exchange custody, leaving recovery dependent on custodians, legal action and law enforcement. The three cases point to the same fault line: who can stop a network, whether confirmed state can be rewritten, and what happens once funds move across chains or into centralized custody. For users, the key distinction is not simply whether a chain stopped, but where each network drew the boundary of controllable loss.

360
Cronos, Ontology and ICON took three very different paths in emergency shutdowns
BingX
2026-08-28 06:28:54

BingX returns as title sponsor for TOKEN2049 Singapore 2026

BingX said it will again serve as title sponsor for TOKEN2049 Singapore 2026, where it plans to present its latest push beyond a crypto exchange model into a broader multi-asset trading platform. The event is scheduled for Oct. 7-8 at Marina Bay Sands in Singapore and is expected to draw more than 25,000 attendees, over 300 speakers, and more than 1,000 side events. According to the company, its on-site showcase will focus on an integrated trading experience, AI-powered tools, and 24/7 access to crypto and other asset markets. BingX also outlined a wider event program, including industry networking, community activations, partner events, a DJ SODA afterparty, and an invitation-only private meet-and-greet with Formula 1 driver Charles Leclerc. Chief Strategy Officer Kevin Lee said the future of trading depends less on the number of assets listed and more on how effectively platforms connect different markets and opportunities through a consistent user experience. BingX also highlighted its 100% Proof of Reserves, a $150 million Shield Fund, and ongoing spending on security and system resilience.

800
BingX returns as title sponsor for TOKEN2049 Singapore 2026