← Trends

Losses Move to Components That Worked as Designed

A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.

strengthening · confidence 100 · 0 7d · Medium term (3-9 months) · tracking since August 10, 2026 · updated August 28, 2026

Sign in to get threshold and movement alerts for this trend.

Score history

Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.

Aug 27 · 100Aug 28 · 100

Now 100

Showing the last few days. Unlock full score history.

Why the conviction moved

  • Aug 28
    Strengthened +5

    Term Labs lost about $8.5 million to an attacker who simply bought voting power and used governance as designed to move the funds, per the week's on-chain loss roundup. Governance is named in the thesis as a privileged off-contract input, and a purchased-quorum drain shows the acquisition cost of control, not code quality, is the binding safety parameter.

  • Aug 28
    Strengthened +6

    Security researchers published a reproducible proof of concept showing Moonwell's roughly $8.7 million loss on Base came from a price oracle correctly reporting a thin market for its own collateral token, not from a defect in the lending contracts. A loss with no contract bug to patch is the cleanest form of the thesis: the audited on-chain code passed, and the failure sat in a trusted external input whose correctness assumptions were never in audit scope.

  • Aug 27
    Strengthened +6

    Term Labs lost $8.5 million to an attacker who simply bought enough voting power to pass a malicious governance action, and Coinsbuy lost $7.9 million to what investigators call key or admin compromise. Both losses ran through privileged paths functioning as specified — a valid vote and valid admin keys — so no contract audit would have flagged them.

Showing the last 2 days. Unlock the full record.

Source trail

  • Supporting · August 27, 2026

    Security Roundup: Governance Takeover, Hot-Wallet Drain and 40 Malicious Firefox Extensions

    Term Labs lost $8.5 million to an attacker who simply bought enough voting power to pass a malicious governance action, and Coinsbuy lost $7.9 million to what investigators call key or admin compromise. Both losses ran through privileged paths functioning as specified — a valid vote and valid admin keys — so no contract audit would have flagged them.

    Rekt News
  • Supporting · August 26, 2026

    Moonwell's cbETH market still shows negative liquidity six months after an oracle misconfiguration

    Moonwell's cbETH market still shows utilization above 100% six months after an oracle misconfiguration, stranding suppliers who were never liquidated, and the latest recovery plan allocates nothing to the roughly $1.8 million gap. The loss came from a correctly functioning price input configured wrongly rather than from contract code, and the six-month unhealed gap shows how poorly protocols are provisioned to remediate this failure surface.

    CryptoSlate

Unlock full source trail, score history, and daily updates.

18 more sources in the full trail.

Unlock Trends

Affected regions & assets

RegionsGlobal
Assets3 assetsUnlock Trends

Townsquare

Argue the thesis in Townsquare.