Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
strengthening · confidence 100 · 0 7d · +4 30d · Medium term (3-9 months) · tracking since June 15, 2026 · updated September 14, 2026
Score history
Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.
Now 100
Showing the last few days. Unlock full score history.
Why the conviction moved
- Sep 14Strengthened +3
A Symbiosis bridge attacker minted 46 billion fake bitcoin tokens but realized only about $336,000, with the protocol recovering roughly 15 BTC into a team multisig. Another unauthorized-mint bridge exploit, though the gap between notional mint and realized proceeds shows exit liquidity, not the mint bug, capping losses.
- Sep 14Strengthened +3
Audited DeFi protocols lost $885 million in the first half to attack paths their audits never covered, per the researchers' review of 68 incidents. Elevated loss levels persist even among protocols that paid for pre-incident review.
- Sep 14Strengthened +3
Attackers used the shared Cosmos EVM defect to inflate balances on Nesa, KiiChain, TAC and MANTRA, a four-chain unauthorized-mint event from one code path. Shared-dependency bugs multiply a single exploit into simultaneous drains rather than isolated incidents.
- Sep 13Strengthened +3
A deprecated ether.fi contract with a missing caller check drained eleven wallets of about 15.45 ether, roughly $38,000, with researchers publishing a working proof of concept a day later as the year's exploit total passed $1.3 billion. Small in size but exactly the deprecated-contract drain the thesis names, and the $1.3 billion cumulative figure marks the loss run rate staying elevated.
Showing the last 2 days. Unlock the full record.
Source trail
Supporting · September 14, 2026
Audited DeFi Protocols Lost $885 Million to Attack Paths Their Audits Never Covered
Audited DeFi protocols lost $885 million in the first half to attack paths their audits never covered, per the researchers' review of 68 incidents. Elevated loss levels persist even among protocols that paid for pre-incident review.
CryptoSlateSupporting · September 14, 2026
One Shared Cosmos Library Bug Drained Four Chains, and Bots Are Now Probing Bitcoin Payment Servers
Attackers used the shared Cosmos EVM defect to inflate balances on Nesa, KiiChain, TAC and MANTRA, a four-chain unauthorized-mint event from one code path. Shared-dependency bugs multiply a single exploit into simultaneous drains rather than isolated incidents.
Rekt News
Unlock full source trail, score history, and daily updates.
105 more sources in the full trail.
Unlock TrendsAffected regions & assets
Townsquare
Argue the thesis in Townsquare.