Morning Edition · Saturday, August 15, 2026Published at 1:40 AM EDT · New York
Rekt's review of the first half puts the Coldcard seed failure at about $116 million, a validator-signature bridge drain at AFX Trade at $24.15 million and a second VerusCoin bridge loss at $7.54 million, all in components that behaved as specified.

The security publication Rekt makes a single argument across its recent incident reports: the largest losses of the first half of 2026 passed their audits, because the failures were not in the contract code. They were in keys, signature set…
Track on-chain flows, protocol shifts, stablecoins, and regulation.
The Global Intelligence Brief stays free.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
Comments
0No comments yet.