Morning Edition · Thursday, August 20, 2026Published at 1:47 AM EDT · New York
The AFX Trade attacker did not break a contract, but produced five valid validator signatures, while the payment processor Coinsbuy lost $8.07 million across two chains and the funds were routed into monero.

Three incidents documented by Rekt, a site that tracks crypto security incidents, show where losses are actually occurring, and most did not involve audited contract logic. AFX Trade lost $24.15 million of USD Coin (USDC) on Arbitrum on Jul…
Track on-chain flows, protocol shifts, stablecoins, and regulation.
The Global Intelligence Brief stays free.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
Comments
0No comments yet.