Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
strengthening · confidence 100 · 0 7d · Medium term (3-9 months) · tracking since August 10, 2026 · updated August 28, 2026
Score history
Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.
Now 100
Showing the last few days. Unlock full score history.
Why the conviction moved
- Aug 28Strengthened +5
Term Labs lost about $8.5 million to an attacker who simply bought voting power and used governance as designed to move the funds, per the week's on-chain loss roundup. Governance is named in the thesis as a privileged off-contract input, and a purchased-quorum drain shows the acquisition cost of control, not code quality, is the binding safety parameter.
- Aug 28Strengthened +6
Security researchers published a reproducible proof of concept showing Moonwell's roughly $8.7 million loss on Base came from a price oracle correctly reporting a thin market for its own collateral token, not from a defect in the lending contracts. A loss with no contract bug to patch is the cleanest form of the thesis: the audited on-chain code passed, and the failure sat in a trusted external input whose correctness assumptions were never in audit scope.
- Aug 27Strengthened +6
Term Labs lost $8.5 million to an attacker who simply bought enough voting power to pass a malicious governance action, and Coinsbuy lost $7.9 million to what investigators call key or admin compromise. Both losses ran through privileged paths functioning as specified — a valid vote and valid admin keys — so no contract audit would have flagged them.
Showing the last 2 days. Unlock the full record.
Source trail
Supporting · August 27, 2026
Security Roundup: Governance Takeover, Hot-Wallet Drain and 40 Malicious Firefox Extensions
Term Labs lost $8.5 million to an attacker who simply bought enough voting power to pass a malicious governance action, and Coinsbuy lost $7.9 million to what investigators call key or admin compromise. Both losses ran through privileged paths functioning as specified — a valid vote and valid admin keys — so no contract audit would have flagged them.
Rekt NewsSupporting · August 26, 2026
Moonwell's cbETH market still shows negative liquidity six months after an oracle misconfiguration
Moonwell's cbETH market still shows utilization above 100% six months after an oracle misconfiguration, stranding suppliers who were never liquidated, and the latest recovery plan allocates nothing to the roughly $1.8 million gap. The loss came from a correctly functioning price input configured wrongly rather than from contract code, and the six-month unhealed gap shows how poorly protocols are provisioned to remediate this failure surface.
CryptoSlate
Unlock full source trail, score history, and daily updates.
18 more sources in the full trail.
Unlock TrendsAffected regions & assets
Townsquare
Argue the thesis in Townsquare.