# A Rounding Bug and a Trusted Price Feed: This Week's Exploits Hit Code That Worked as Written

Researchers published a working proof-of-concept for a rounding flaw in the USM stablecoin's withdrawal function, while the pattern behind the largest recent losses remains authorized inputs rather than broken contracts.

- Published: 2026-08-11T05:53:59.872Z
- Canonical: https://polylog.news/crypto/2026-08-11/a-rounding-bug-and-a-trusted-price-feed-this-week-s-exploits
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/2c99b565ae24ea2006adf181da20c4419b3edc30), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/d4d26edbf1393537f6166523a21368b1a34499c8), [Rekt News](https://www.rekt.news/), [Ethereum Research](https://ethresear.ch/t/coordination-collapse-and-the-optimality-of-silence-two-result-that-break-standard-bft-and-oracle-design/25674</source-url), [Polylog editors](https://polylog.news)

The DeFiHackLabs repository, which reconstructs live exploits as runnable test cases, added a proof-of-concept for a price split-invariance rounding flaw in the defund() function of USM, an ownerless collateralized stablecoin, and then a se…

This story is for subscribers. Read it in full at https://polylog.news/crypto/2026-08-11/a-rounding-bug-and-a-trusted-price-feed-this-week-s-exploits (subscription information: https://polylog.news/pricing).