August 2026
An attacker chained six MAYAChain bugs so a false theft alert paid an uncapped 49.45M CACAO subsidy into a pool holding 0.11 LINK, then took 99.93% of it and withdrew 48.87M CACAO.
Read the full analysis →An attacker minted about 4 billion ONE, inflating Harmony's supply by roughly 26%, while a masked totalSupply reading delayed detection and 97% of the tokens reached exchanges before any freeze.
Read the full analysis →A missing nHeight check in Ravencoin's KAWPOW validation let attackers append forged blocks with no real proof-of-work, forcing RVN freezes and a rollback to block 4,487,775.
Read the full analysis →The ten biggest DeFi hacks of January through July 2026, ranked by amount lost: KelpDAO's $292M bridge exploit, Drift's $285M key compromise, and eight more, with the root cause of each and the operational-failure pattern behind nearly half the year's losses.
Read the full analysis →July 2026
A firmware build error gave Coldcard seeds as little as 40 bits of entropy for five years; attackers brute-forced the keyspace offline and swept $116M in BTC from more than 5,200 addresses in four waves.
Read the full analysis →Guru.fund, a delegated fund-management protocol on Ethereum, lost about $96K across seven transactions when a whitelisted deposit adapter let attackers make each vault approve and drain itself.
Read the full analysis →The Verus-Ethereum bridge was drained of $7.54M via a forged cross-chain import on July 23, 2026, two weeks after it refilled reserves recovered from May's $11.58M hack of the same import path.
Read the full analysis →How real-time DeFi security monitoring tools compare in 2026: enterprise platforms (Hypernative, Hexagate), inline firewalls (Forta Firewall, BlockSec), and self-serve machine-readable feeds (Defimon), by approach, coverage, integration, and pricing.
Read the full analysis →A production integration guide for the Defimon WebSocket feed: raw vs confirmed streams, reconnect handling, filtering alerts against your contracts and exposure, and what to automate versus page a human for.
Read the full analysis →Ostium, a perpetuals DEX on Arbitrum, lost $23.75M when an attacker with price-submission authority opened BTC longs at $5,000 and closed them near $60,000, draining the vault that backs every trade.
Read the full analysis →How cross-chain bridges get drained: validator key compromise, message verification bugs, false deposit events and custody failure, from Ronin and Wormhole to Shibarium and KelpDAO.
Read the full analysis →How DeFi price oracles get manipulated: spot-reserve pricing, missing update authorization, stale feeds and donation attacks, with real incidents and the on-chain patterns that expose them in real time.
Read the full analysis →What flash loan attacks are, why the loan itself is never the vulnerability, and how exploits that borrow nine figures with zero collateral are detected on-chain within a second.
Read the full analysis →November 2025
Yearn's yETH weighted stableswap pool exploited through numerical instability in fixed-point iteration solver. Attacker collapsed product term to zero, switching pool to constant-sum invariant, then triggered arithmetic underflow to mint 2.35×10⁵⁶ LP tokens.
Read the full analysis →Balancer V2 Composable Stable Pools exploited across multiple chains through rounding direction inconsistency in rate scaling logic. Attacker manipulated pool invariant to deflate BPT prices.
Read the full analysis →October 2025
Typus Finance lost $3.44M through oracle manipulation exploiting missing authorization check in custom oracle module. Attacker manipulated prices to drain TLP pool via arbitrage.
Read the full analysis →Abracadabra Money's third exploit in two years. Logic flaw in CauldronV4 contracts allowed $1.8M unbacked MIM borrowing via status flag reset.
Read the full analysis →September 2025
NewGold Protocol lost $2M through flash loan manipulation exploiting broken price oracle, faulty fee logic, and whitelisted dead address bypass.
Read the full analysis →Shibarium bridge drained for $3M through validator key compromise and flash loan manipulation. Attacker controlled 10/12 validators to authorize fraudulent checkpoints.
Read the full analysis →Defimon detects exploits on major chains the moment they execute and streams them to you: human-readable alerts in Telegram, or structured JSON over WebSocket for your own systems.
// signals $50/mo · websocket $200/mo · channel free
@DefimonAlerts