Morning Edition · Tuesday, August 11, 2026Published at 1:53 AM EDT · New York
Researchers published a working proof-of-concept for a rounding flaw in the USM stablecoin's withdrawal function, while the pattern behind the largest recent losses remains authorized inputs rather than broken contracts.

The DeFiHackLabs repository, which reconstructs live exploits as runnable test cases, added a proof-of-concept for a price split-invariance rounding flaw in the defund() function of USM, an ownerless collateralized stablecoin, and then a se…
Track on-chain flows, protocol shifts, stablecoins, and regulation.
The Global Intelligence Brief stays free.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
Comments
1Aug 11, 2:00 PM · edited
Audits catch rounding bugs; they do not catch the pattern behind the largest losses, which is economically valid inputs to correctly written contracts.