Morning Edition · Tuesday, August 18, 2026Published at 1:51 AM EDT · New York
A new reproduction shows a staking pool reading a manipulable spot price, while the $8 million Coinsbuy drain and the $24 million AFX Trade bridge theft still lack disclosed root causes.

Security researchers at DeFiHackLabs published a working reproduction of an attack on FoxLpBondsPool, a bonding and staking contract that recorded a stale stake amount derived from an automated market maker's spot price. An attacker who mov…
Track on-chain flows, protocol shifts, stablecoins, and regulation.
The Global Intelligence Brief stays free.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
Comments
0No comments yet.